Bug Bounty MCP Server
Related Servers
Alternatives to Bug Bounty MCP Server
No user-submitted related servers found.
Related Servers
- AlicenseNot gradedqualityDmaintenanceEnables comprehensive security testing and penetration testing through natural language conversations with 92+ tools for reconnaissance, vulnerability assessment, web application testing, OSINT, and reporting. Designed for authorized bug bounty hunting and security assessments.43MIT
- AlicenseBqualityAmaintenanceAI-powered bug bounty hunting platform that integrates security tools (OWASP ZAP, Caido, Burp Suite) for automated reconnaissance, vulnerability testing, JavaScript analysis, and finding management with PostgreSQL storage.4743MIT
- FlicenseNot gradedqualityDmaintenanceAI-powered cybersecurity automation platform with 150+ security tools and 12+ autonomous AI agents for penetration testing, vulnerability assessment, and bug bounty hunting. Enables comprehensive security testing through intelligent tool selection and automated workflows.2-
- AlicenseNot gradedqualityCmaintenanceEnables autonomous AI agents and penetration testers to conduct authorized security audits with persistent cross-session memory, zero-trust secret scrubbing, dynamic OWASP/ASVS checklists, and hallucination-free exploit PoC generation from captured traffic.1MIT
- AlicenseNot gradedqualityCmaintenanceAutomates bug bounty hunting across Web2 and Web3 platforms, performing recon, vulnerability scanning, Solidity audits, and report generation.MIT
- FlicenseNot gradedqualityCmaintenanceEnables AI agents to perform safe, authorized penetration testing by managing engagements, enforcing scope and risk policies, and orchestrating tools like Nmap, Nuclei, and Subfinder.-
TDQS
Scored across 40 tools
The tools cover distinct security tools and workflows (e.g., amass_scan for subdomain enumeration, nuclei_scan for vulnerability scanning), but there is significant overlap in purpose. For example, dirb_scan, dirsearch_scan, feroxbuster_scan, and gobuster_scan all perform directory/file discovery, which could confuse an agent. Similarly, nmap_scan and nmap_advanced_scan are redundant, and multiple tools handle subdomain enumeration (amass_scan, dnsenum_scan, fierce_scan, subfinder_scan). Descriptions help differentiate, but the overlaps are substantial.
Most tools follow a consistent verb_noun pattern (e.g., amass_scan, dnsenum_scan, nuclei_scan), which is clear and predictable. However, there are minor deviations: some tools use underscores inconsistently (e.g., bugbounty_business_logic_workflow lacks underscores in 'bugbounty'), and a few tools have longer, more descriptive names (e.g., bugbounty_comprehensive_assessment). Overall, the naming is mostly consistent and readable, with only slight variations.
With 40 tools, the count is excessive for a bug bounty server, leading to bloat and potential confusion. Many tools are redundant (e.g., multiple directory scanners, multiple subdomain enumerators) or could be consolidated into broader workflows. A well-scoped server for this domain should typically have 10-20 tools to cover core functionalities without overwhelming the agent. The high number suggests poor scoping and unnecessary fragmentation.
The tool set is highly complete for bug bounty hunting, covering all major aspects: reconnaissance (e.g., subdomain enumeration, crawling), vulnerability scanning (e.g., XSS, SQL injection, WAF detection), workflow creation (e.g., business logic testing, OSINT), and AI-enhanced features (e.g., analyze_target, optimize_parameters). There are no obvious gaps; agents have tools for every stage from target analysis to comprehensive assessment, ensuring no dead ends in typical workflows.