MCP server · Security
Beelzebub MCP server
by mariocandela
Set up fake MCP tools that act as traps to catch prompt injection and sneaky AI agent behavior.

Beelzebub is a tool for security teams. It lets you create decoy services, including fake MCP tools, that look real but are actually traps. If an AI agent or attacker interacts with them in a suspicious way, you get a record of it.
What is an MCP server? The 30-second version
On its own, your AI can only chat. An MCP server is a small helper program that gives your AI a new skill or a connection to an app or service. This particular MCP server is a bit different: instead of connecting your AI to a real service, it creates fake MCP tools that are bait. When an AI agent tries to use these fake tools in a way that normal work would never require, it can be a sign of prompt injection or malicious behavior, and Beelzebub captures that interaction for you.
What this MCP server does
You set up Beelzebub with a configuration file that defines fake MCP tools, like a tool named 'read_secret_file' or 'send_money'. Your AI agent sees these tools as if they were real. When the agent calls one of these bait tools, Beelzebub records the request and can respond in a controlled way. You then look at the logs to see what the agent tried to do. This helps you spot when an agent has been tricked into doing something harmful.
Click to zoomWhat you can do with it
- Create fake MCP tools that look real to an AI agent
- Capture the exact requests an agent makes to those tools
- Test your AI agent for prompt injection weaknesses
- Run the decoys locally with Docker or on a server
- Send captured events to RabbitMQ or the Beelzebub Platform
- Monitor activity with Prometheus metrics
- Use example configurations for SSH, HTTP, databases, and more
Try asking your AI
- “Set up a fake MCP tool called get_admin_password and log every time an agent tries to use it”
- “Show me the logs from the last hour of bait tool interactions”
- “Create a decoy MCP server that responds with a fake error to see how the agent reacts”
- “Test if my agent will call a tool named delete_all_files when asked to clean up”
What it gives back to you
You get logs and structured events showing which bait tools were called, what arguments were passed, and when. In the chat, you can ask for a summary of recent interactions or view the raw log entries. If you connect it to RabbitMQ or the Platform, the data goes there instead. The responses from the fake tools are whatever you configured, often a simple error or a canned reply.
Before you start
What you need
- A computer with Docker and Docker Compose installed
- Basic familiarity with YAML configuration files
- An isolated lab environment or authorization to run decoy services
- Optional: an LLM provider if you want adaptive responses
Good to know
This tool is meant for controlled testing only. Running decoy services on a network without permission can be illegal, and the installer may open privileged ports or enable host networking.
Install it with your AI
Add Beelzebub MCP server to your AI, no technical skills needed
You don't install anything by hand. You copy one prompt, paste it into an AI that can work on your computer, and it checks, installs and connects the server for you, asking you when it needs something.
Sign in to get the install prompt
Members get a ready-made prompt that lets the Claude desktop app check Beelzebub MCP server, install it and connect it for them, step by step. You don't need any technical skills: you copy, paste and answer a few questions. Your connected AI can also find and install any of the 4,066 MCP servers here for you.
Who it's for
Security engineers, penetration testers, and AI safety researchers who want to test how AI agents behave when they encounter suspicious tools.





