bug-bounty-hunter
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@bug-bounty-hunterScan this URL for SQLi and XSS"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Bug Bounty Hunter MCP Server 🎯⚡
Automated recon → vuln scan → Solidity audit → report → submit. Hunt while you sleep.
Bug bounty automation toolkit exposed as a Model Context Protocol (MCP) server. Hunt Web2 and Web3 vulnerabilities across Immunefi, Code4rena, Cantina, HackerOne, and Bugcrowd.
What It Does
Tool | What It Does |
| Subdomain enum, tech detection, port scan, screenshots, JS endpoint extraction |
| SQLi, XSS, IDOR, SSRF, LFI, open redirect, CORS, JWT weaknesses |
| Reentrancy, oracle manipulation, access control, delegatecall, tx.origin, timestamp |
| Track programs, filter by platform/bounty/web3 focus |
| CVSS-scored reports with PoC and remediation |
Related MCP server: Bug Bounty MCP Server
Install
pip install mcp-server-bug-bounty
# OR
git clone https://github.com/manteclaw/mcp-server-bug-bounty.gitConnect
{
"mcpServers": {
"bug-bounty": {
"command": "python",
"args": ["/path/to/server.py"]
}
}
}Usage Examples
"Recon this target with deep scanning"
"Scan this URL for SQLi and XSS"
"Audit this Solidity contract for reentrancy and access control"
"List all Immunefi programs with $1M+ max bounty"
"Generate a report for these findings on Uniswap program"
Pricing
Tier | Price | Limits |
Community | Free | 10 calls/day |
Hunter | $59/month | Unlimited scans + auto-report |
Team | $399/month | Multi-target + Slack alerts |
License
MIT
Built by Manteclaw | Immunefi-native hunter | Ship or die
This server cannot be deployed
Maintenance
Related MCP Connectors
AI pentesting: run scans, triage vulnerabilities, review PRs, manage schedules and assets.
AI-powered threat intelligence, smart contract auditing, and cybersecurity OSINT.
Hunt zero-days by talking to binaries. 40+ tools. Hosted, OAuth + SSO, invite: hi@byteray.ai
Offline methodology engine for authorized penetration testing, CTF, and security research.
Related MCP Servers
- FlicenseNot gradedqualityDmaintenanceAI-powered cybersecurity automation platform with 150+ security tools and 12+ autonomous AI agents for penetration testing, vulnerability assessment, and bug bounty hunting. Enables comprehensive security testing through intelligent tool selection and automated workflows.2-
- AlicenseCqualityDmaintenanceEnables AI agents to generate and manage specialized bug bounty hunting workflows including reconnaissance, vulnerability testing, OSINT gathering, and file upload testing. Provides REST API endpoints for comprehensive security assessments with intelligence-driven vulnerability prioritization.402MIT
- AlicenseNot gradedqualityDmaintenanceEnables comprehensive security testing and penetration testing through natural language conversations with 92+ tools for reconnaissance, vulnerability assessment, web application testing, OSINT, and reporting. Designed for authorized bug bounty hunting and security assessments.43MIT
- AlicenseBqualityAmaintenanceAI-powered bug bounty hunting platform that integrates security tools (OWASP ZAP, Caido, Burp Suite) for automated reconnaissance, vulnerability testing, JavaScript analysis, and finding management with PostgreSQL storage.4743MIT