HuntX
OfficialClick on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@HuntXtest api.example.com for IDOR and SQLi, save findings"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
HuntX
Personal MCP (Model Context Protocol) server giving Claude Code (or any MCP-compatible client) direct tool-access to security-testing primitives for bug bounty hunting: recon querying/triggering, HTTP request replay, IDOR/BOLA fuzzing, SQLi/XSS/SSTI/SSRF detection, JWT/OAuth testing, secrets scanning, misconfiguration/exposure checks, and persistent hunt memory with confidence-scored findings across sessions.
Every finding gets a confidence level (confirmed/likely/
needs_review) and nothing auto-escalates without explicit human
review — see AGENTS.md for the full design principles.
Requirements
Python 3.12+
Optional external tools
Most adapters work standalone. A few shell out to external CLI tools — install these only if you need the corresponding adapter:
Adapter | Needs |
|
|
|
|
| reconFTW installed — |
Related MCP server: recon-mcp
Setup
uv sync
uv run huntxThen add HuntX as an MCP server in your Claude Code config, pointing at
this project's huntx entrypoint.
Configuration (environment variables)
Variable | Default | Purpose |
|
| SQLite database for request history and findings |
| public interactsh pool ( | Interactsh server for |
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- Flicense-qualityDmaintenanceA comprehensive MCP server for automated bug bounty hunting and security reconnaissance, featuring over 28 specialized tools for subdomain discovery, vulnerability scanning, and traffic analysis. It integrates automated scope validation and professional reporting across multiple platforms like HackerOne and Bugcrowd to streamline security testing.5
- Alicense-qualityBmaintenanceA local Python MCP server for safe, human-led bug bounty recon, providing lightweight helpers for scope checks, headers, robots.txt, sitemap.xml, JavaScript URL collection, endpoint extraction, URL deduplication, evidence notes, and manual test planning.MIT
- AlicenseAqualityBmaintenanceAn MCP server that provides passive and low-impact active reconnaissance tools for authorized bug bounty and security assessments, enabling LLMs to perform structured recon and generate reports.11Apache 2.0
- AlicenseBqualityCmaintenanceAn MCP server for authorized bug bounty work that enforces an evidence-driven workflow with session management, preflight checks, surface discovery, and verified scanning.12MIT
Related MCP Connectors
MCP server for Pentest-Tools.com: run scans, manage findings and reports via your preffered LLM.
Security scanner for MCP servers. Detect vulnerabilities, prompt injection, and tool poisoning.
Hosted MCP server for agent governance: MCP config audits, injection scans, scope-policy checks.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/IAZENT/HuntX'
If you have feedback or need assistance with the MCP directory API, please join our Discord server