DungeonQ - Divert suspicious sessions into persistent decoy worlds
by•
DungeonQ diverts designated suspicious sessions into persistent synthetic worlds. Human and AI clients use world-only tickets; operators observe and approve bounded adaptation. Inspect recorded runtime checks and the original Astra experiment.


Replies
DungeonQ
Hi Product Hunt — I'm the maker of DungeonQ.
DungeonQ is a defensive deception runtime. Its job is to route a designated suspicious session into a persistent synthetic world, let the participant continue useful work there, and give the operator an inspectable record of what happened. It is built for security teams and developers working with human or AI clients.
The sequence is concrete: enter through a real adapter, read or change a world record, receive a useful world-only Wrong Ticket, and return to the same state after restart. A separately approved finite policy can add follow-up records in response to observed activity. Independent artificial-origin checks measure where the session's authority stopped.
The current reference shares one core across HTTP, MCP, bounded SSH/PostgreSQL and a private Unix workload broker. Its contexts are explicitly provisioned; automatic attack classification and production host integration remain future acceptance work. Start with the six recorded checkpoints, then self-host the same runtime to operate it. The public page presents evidence, not a hosted security service.
GPT-6 Astra contributed the original bounded assistant profile: it proposes a command from minimized synthetic context, while DungeonQ validates the candidate and keeps approval separate. That experiment, its automated-reviewer limitation and all original records remain available. The new runtime checks are engineering evidence, not a new live Astra experiment or a claim that an AI was fooled. The earlier 73-second film is retained and clearly scoped.
I'd welcome feedback on the diversion itself: can you follow the participant's useful work, the operator's observations and the independent origin checks, and identify what you would need to integrate this into an authorized environment?
DungeonQ
DungeonQ's ambition is defensive deception: divert designated suspicious human or AI sessions into persistent decoy worlds. Participants can use world-only tickets and return to the same state after restart; operators observe activity and approve bounded changes.
Astra expanded the original scripted foundation with a real model proposing actions through MCP, while DungeonQ kept execution authority separate. An ambiguous routing label made an early call wait, revealing an input problem. A subsequent two-call run passed seven checks, including rejection before approval and signature/tamper/replay checks.
That model experiment is one part of the broader runtime, now spanning HTTP, MCP, bounded SSH/PostgreSQL and a Unix workload broker. The site shows six recorded checkpoints, with source to run locally. These are engineering results; general AI-deception effectiveness and production protection remain unproven.