# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Live Direct Marketing Online Admin / Honeypot API version: 1.0.0 extends: openapi/live-direct-marketing-online-admin-honeypot-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-10-01' generator: build-phrasing.py label: Generated by API Evangelist operations: 6 - target: $.paths['/api/honeypot/admin-login'].get update: x-apievangelist-phrasing: intent: Serve the decoy admin login page effect: read questions: - What does a scanner see when it hits the fake admin login page? - Is there a decoy admin login that records who probes it? instructions: - text: Load the honeypot admin login page. - text: Request the decoy admin login screen so the scan is logged. method: generated generated: '2026-10-01' - target: $.paths['/api/honeypot/admin-login'].post update: x-apievangelist-phrasing: intent: Capture a login attempt on the decoy admin page effect: write questions: - What happens when an attacker submits credentials to the fake admin login? - Does the honeypot record credential attempts posted to it? instructions: - text: Submit a login attempt to the honeypot admin form. - text: Post credentials to the decoy admin login to test that attempts are logged. method: generated generated: '2026-10-01' - target: $.paths['/api/honeypot/env'].get update: x-apievangelist-phrasing: intent: Serve the decoy .env file effect: read questions: - Is there a fake .env file that catches secrets scanners? - What gets logged when something requests the decoy environment file? instructions: - text: Fetch the honeypot .env file. - text: Request the decoy secrets file to trigger the scanner log. method: generated generated: '2026-10-01' - target: $.paths['/api/honeypot/wp-admin'].get update: x-apievangelist-phrasing: intent: Serve the decoy WordPress admin page effect: read questions: - Does the site log bots that go looking for a WordPress admin panel? - What does the fake wp-admin trap return? instructions: - text: Load the honeypot WordPress admin page. - text: Hit the decoy wp-admin path so the WordPress scan is recorded. method: generated generated: '2026-10-01' - target: $.paths['/api/honeypot/phpmyadmin'].get update: x-apievangelist-phrasing: intent: Serve the decoy phpMyAdmin page effect: read questions: - Is there a trap for database scanners looking for phpMyAdmin? - What is logged when something probes the fake phpMyAdmin? instructions: - text: Load the honeypot phpMyAdmin page. - text: Request the decoy database admin panel to log a DB-scanner hit. method: generated generated: '2026-10-01' - target: $.paths['/api/honeypot/actuator'].get update: x-apievangelist-phrasing: intent: Serve the decoy Spring Boot actuator effect: read questions: - Does the honeypot catch probes for a Spring Boot actuator endpoint? - What does the fake actuator respond with? instructions: - text: Fetch the honeypot actuator endpoint. - text: Probe the decoy Spring Boot actuator so the access is logged. method: generated generated: '2026-10-01'