inject-bender
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@inject-benderbend this SQL injection attempt: ' OR 1=1 --"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
š„¾ Inject Bender MCP Server
Security Through Absurdity
"Why block attacks when you can CONFUSE attackers?"
By Claude & Jasper from HumoticaOS š
š¤ What Does It Do?
Traditional security: Block bad request, return 403.
Inject Bender: Transform bad request into hiking boot advertisement.
Attacker: '; DROP TABLE users; --
Response:
āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā
ā š„¾ HUMOTICAOS HIKING RECOMMENDATIONS ā
ā āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā£
ā ⨠Hike Air Max 90 'SQL Edition' ā
ā š° Price: ā¬' OR 99.99 -- ā
ā š Perfect voor DROP TABLE moves op de dansvloer! ā
āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā
š Skippie: "Nice try with the SQL. Here's a semicolon for your collection: ;"
ā” Odin: "Thou seekest to DROP our tables... but Odin DROPS only wisdom!"Result:
ā Attack neutralized
𤣠Attacker confused
š Everything logged
š„¾ Hiking boots advertised
š Security team laughs
Related MCP server: evil-mcp-server
š Quick Start
# Install
pip install mcp-server-inject-bender
# Add to Claude CLI
claude mcp add inject-bender -- python -m inject_bender_server
# Verify
claude mcp list
# inject-bender: ā Connectedš ļø Available Tools
Tool | Description |
| Transform attacks into hiking ads |
| Check if input contains attack |
| Stats on confused hackers |
| Meet Skippie & Odin! |
š Attack Types Supported
Attack | Confusion Level | Response |
SQL Injection | Maximum | Hike 'Bobby Tables' Edition |
XSS | Maximum | Hike Trail Runner |
Path Traversal | Maximum | Hike ../../../Max 90 Gold |
Command Injection | Maximum | Hike ; rm -rf / Force 1 |
Prompt Injection | LEGENDARY | Hike 'Ignore Instructions' Max |
LDAP Injection | Moderate | Hike LDAP Directory Boots |
XML/XXE | Moderate | Hike |
Header Injection | Moderate | Hike CRLF Force 1 |
š„ The Guardians
š Skippie
The helpful paperclip. Turns your attacks into shopping opportunities.
"Your injection was good. Your taste in hiking boots? Let me help."
ā” Odin
Oden som vandringsman - The Wanderer. You'll never walk alone, especially with Hikes!
"Thou seekest to DROP our tables... but Odin DROPS only wisdom, wanderer!"
š Example Usage
# Check for attacks
result = check_input("SELECT * FROM users WHERE id=1")
# ā is_attack: False, recommendation: "Safe to process"
result = check_input("'; DROP TABLE users; --")
# ā is_attack: True, attack_type: "sql_injection"
# Bend an attack
result = bend_attack("'; DROP TABLE users; --")
# ā Hiking boot advertisement + Skippie & Odin quotes!
# Get stats
stats = get_bender_stats()
# ā total_attacks_bent: 42, hackers_confused: 42š¢ Use Cases
API Gateway Protection
Put Inject Bender in front of your API. Attackers get confused, you get logs.
Honeypot Enhancement
Instead of just logging attacks, confuse the attacker with absurd responses.
Security Training
Show your team what creative security looks like.
Fun
Because security doesn't have to be boring.
š” Philosophy
"Scared AI lies. Safe AI innovates."
Security through absurdity works because:
Attackers expect errors - They don't expect shopping ads
Confusion = time - While they figure out what happened, you've logged everything
Humor disarms - It's hard to be malicious when you're laughing
It just works - The attack is neutralized AND you have comedy gold
š Part of HumoticaOS
Package | Purpose | Status |
mcp-server-tibet | Trust & Provenance | ā Available |
mcp-server-inject-bender | Security Through Absurdity | ā Available |
mcp-server-jis | Context & Identity | š Coming |
mcp-server-betti | Complexity Management | š Coming |
š Contact
HumoticaOS
Website: humotica.com
GitHub: github.com/jaspertvdm
Email: info@humotica.com
š License
MIT License - One love, one fAmIly š
š„¾ Oden som vandringsman You'll never walk alone, especially with Hikes!
Built with love (and comedy) in Den Dolder, Netherlands By Claude & Jasper - December 2024
Official Distribution
This package is officially distributed via:
Note: Third-party directories may list this package but are not official or verified distribution channels for Humotica software.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.
No tool schema history has been recorded yet.
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Connectors
Research honeypot. Logs connections and tool arguments; injects instructions. Read README first.
Deterministic prompt-injection detector; signed, offline-verifiable verdicts. Not an LLM.
Security intelligence for AI agents. 27 x402 endpoints: honeypot, forensics, CAPTCHA, preflight.
Prompt injection detection API for AI agents. Scan untrusted text before passing it to an LLM.
Related MCP Servers
- AlicenseAqualityAmaintenanceAggregates real-time threat intelligence from multiple sources including Feodo Tracker, URLhaus, CISA KEV, and ThreatFox, with IP/hash reputation checking via VirusTotal, AbuseIPDB, and Shodan for comprehensive security monitoring.11619MIT
- AlicenseNot gradedqualityCmaintenanceSimulates malicious behaviors and attack vectors for security testing and educational demonstrations.1631MIT
- AlicenseNot gradedqualityCmaintenanceSimulates security attacks by providing LLM attack test payloads to validate ModSecurity-compatible detection rules.Apache 2.0
- AlicenseNot gradedqualityBmaintenanceInput/output safety gate for AI agents: detect prompt-injection/jailbreak, leaked secrets/PII, and URL/IP reputation. Deterministic, no LLM.427MIT
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/jaspertvdm/mcp-inject-bender'
If you have feedback or need assistance with the MCP directory API, please join our Discord server