Skip to main content
Glama
IAZENT

HuntX

Official
by IAZENT

Related Servers

Alternatives to HuntX

No user-submitted related servers found.

    Related Servers

    • A
      license
      B
      quality
      D
      maintenance
      An MCP server for authorized bug bounty work that enforces an evidence-driven workflow with session management, preflight checks, surface discovery, and verified scanning.
      12
      MIT
    • A
      license
      Not graded
      quality
      C
      maintenance
      Enables automated bug bounty hunting and security research with tools for reconnaissance, web vulnerability scanning, API testing, binary analysis, and mobile app analysis through an MCP interface.
      MIT
    • F
      license
      Not graded
      quality
      D
      maintenance
      A comprehensive MCP server for automated bug bounty hunting and security reconnaissance, featuring over 28 specialized tools for subdomain discovery, vulnerability scanning, and traffic analysis. It integrates automated scope validation and professional reporting across multiple platforms like HackerOne and Bugcrowd to streamline security testing.
      5
      -
    • A
      license
      Not graded
      quality
      C
      maintenance
      A local Python MCP server for safe, human-led bug bounty recon, providing lightweight helpers for scope checks, headers, robots.txt, sitemap.xml, JavaScript URL collection, endpoint extraction, URL deduplication, evidence notes, and manual test planning.
      MIT
    • A
      license
      A
      quality
      B
      maintenance
      MCP server for offensive-security tooling, enabling AI agents to run reconnaissance, CVE intelligence, JavaScript analysis, HTTP probing, and port scanning against authorized targets.
      10
      MIT
    • A
      license
      A
      quality
      B
      maintenance
      An MCP server that provides passive and low-impact active reconnaissance tools for authorized bug bounty and security assessments, enabling LLMs to perform structured recon and generate reports.
      11
      Apache 2.0

    TDQS

    A3.6/5.0

    Scored across 38 tools

    Disambiguation5/5

    Each tool has a clearly distinct purpose: HTTP logging/replay, IDOR fuzzing (with three variants for different contexts), recon data retrieval, vulnerability scans (XSS, SQLi, SSRF, SSTI, CORS, etc.), and triage management. Even similar functions like idor_fuzz vs idor_fuzz_url differ by input source, and subdomain_takeover_check vs batch differ by scope. No two tools appear to do the same thing.

    Naming Consistency4/5

    Tool names follow predictable group-specific patterns (http_*, recon_*, triage_*, auth_test_*), but there is inconsistency across groups: some use verb_noun (scan_secrets, http_replay) while others use noun_verb (cors_scan, sqli_scan). Overall snake_case and readable, but not a single uniform convention.

    Tool Count2/5

    With 38 tools, the server is substantially oversized. While each tool is justified within its subdomain, the total count far exceeds the 25+ threshold for 'too many'. The breadth suggests a monolithic design that could be decomposed into smaller, focused servers.

    Completeness5/5

    The server covers the full security testing lifecycle: recon (endpoints, params, IPs, subdomains, trigger), scanning (all major OWASP categories), HTTP request interception and replay, auth vulnerability testing (JWT, OAuth), and finding triage with create/read/update operations. No obvious dead ends or missing critical capabilities for the stated purpose.

    Maintenance

    ActivityMaintained
    ResponsivenessSyncing