canarytoken-SKILL.md

Deploy and manage Canary Tokens via the Thinkst Canary API.

Updated Apr 20, 2026
One-click install
npx skills add https://github.com/DCx7C5/ai-marketplace --skill canarytoken-skill-md
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: canarytoken-SKILL.md
Source: https://github.com/DCx7C5/ai-marketplace/tree/main/skills/deception/canarytoken
Command: npx skills add https://github.com/DCx7C5/ai-marketplace --skill canarytoken-skill-md

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill requires requests, and includes scripts (resource) and references (resource) components.

What problem does it solve?

Deploy and monitor Canary Tokens via the Thinkst Canary API to detect unauthorized access and breach attempts across networks, documents, and services.

Core Features & Use Cases

  • Deploy web bug, DNS, document, and AWS token types to lure attackers and monitor token triggers.
  • Retrieve active tokens, view associated alerts, and map incidents to MITRE/kill chain stages.
  • Use deception coverage reporting to identify token gaps and strengthen threat-hunting capabilities.

Quick Start

Deploy your first Canary Token using the CLI or API by creating a token with kind http and a descriptive memo.

Frequently Asked Questions about canarytoken-SKILL.md

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I deploy deception tokens for breach detection?

To deploy deception tokens for breach detection, use the Thinkst Canary API to create token types like web bugs or DNS records. This enables monitoring for unauthorized access across networks and documents.

What is a Canary Token and how does it detect unauthorized access?

A Canary Token is a deception-based trap that alerts you when triggered by unauthorized access. It detects breaches by luring attackers into interacting with deployed web bugs, DNS records, or documents.

Can I manage the lifecycle of deception tokens via the API?

Yes, you can manage the deception token lifecycle via the Thinkst Canary API. It supports creating, listing, fetching, and deleting tokens to maintain your breach detection coverage.

How do I map deception token alerts to MITRE attack stages?

You can map deception token alerts to MITRE kill chain stages by retrieving and analyzing triggered token alerts. This correlation helps identify specific threat-hunting behaviors during incident response.

Do I need the requests library to automate Canary Token deployment?

Yes, the requests library is required as a dependency to automate Canary Token deployment. It handles the HTTP interactions needed to communicate with the Thinkst Canary Console API.

What is the best way to audit deception coverage for security gaps?

The best way to audit deception coverage is by using the coverage reporting feature to identify token gaps. This strengthens threat-hunting capabilities by revealing unprotected network areas.