Skip to main content
Glama

Bug Bounty Hunter MCP Server 🎯⚡

Automated recon → vuln scan → Solidity audit → report → submit. Hunt while you sleep.

Bug bounty automation toolkit exposed as a Model Context Protocol (MCP) server. Hunt Web2 and Web3 vulnerabilities across Immunefi, Code4rena, Cantina, HackerOne, and Bugcrowd.

What It Does

Tool

What It Does

bounty_recon

Subdomain enum, tech detection, port scan, screenshots, JS endpoint extraction

bounty_vuln_scan

SQLi, XSS, IDOR, SSRF, LFI, open redirect, CORS, JWT weaknesses

bounty_solidity_scan

Reentrancy, oracle manipulation, access control, delegatecall, tx.origin, timestamp

bounty_scope

Track programs, filter by platform/bounty/web3 focus

bounty_report

CVSS-scored reports with PoC and remediation

Related MCP server: Bug Bounty MCP Server

Install

pip install mcp-server-bug-bounty
# OR
git clone https://github.com/manteclaw/mcp-server-bug-bounty.git

Connect

{
  "mcpServers": {
    "bug-bounty": {
      "command": "python",
      "args": ["/path/to/server.py"]
    }
  }
}

Usage Examples

"Recon this target with deep scanning"

"Scan this URL for SQLi and XSS"

"Audit this Solidity contract for reentrancy and access control"

"List all Immunefi programs with $1M+ max bounty"

"Generate a report for these findings on Uniswap program"

Pricing

Tier

Price

Limits

Community

Free

10 calls/day

Hunter

$59/month

Unlimited scans + auto-report

Team

$399/month

Multi-target + Slack alerts

License

MIT


Built by Manteclaw | Immunefi-native hunter | Ship or die

A
license - permissive license
-
quality - not tested
C
maintenance

Maintenance

–Maintainers
–Response time
–Release cycle
–Releases (12mo)
Commit activity

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Servers

  • F
    license
    -
    quality
    D
    maintenance
    AI-powered cybersecurity automation platform with 150+ security tools and 12+ autonomous AI agents for penetration testing, vulnerability assessment, and bug bounty hunting. Enables comprehensive security testing through intelligent tool selection and automated workflows.
    Last updated
    2
  • A
    license
    C
    quality
    D
    maintenance
    Enables AI agents to generate and manage specialized bug bounty hunting workflows including reconnaissance, vulnerability testing, OSINT gathering, and file upload testing. Provides REST API endpoints for comprehensive security assessments with intelligence-driven vulnerability prioritization.
    Last updated
    40
    2
    MIT
  • A
    license
    -
    quality
    F
    maintenance
    Enables comprehensive security testing and penetration testing through natural language conversations with 92+ tools for reconnaissance, vulnerability assessment, web application testing, OSINT, and reporting. Designed for authorized bug bounty hunting and security assessments.
    Last updated
    38
    MIT
  • A
    license
    C
    quality
    D
    maintenance
    An automated penetration testing framework that enables intelligent security assessments through reconnaissance, vulnerability scanning, and controlled exploitation. Features AI-driven workflow management with comprehensive reporting for authorized security testing.
    Last updated
    27
    21
    7
    BSD 3-Clause

View all related MCP servers

Related MCP Connectors

  • AI-powered threat intelligence, smart contract auditing, and cybersecurity OSINT.

  • Offline methodology engine for authorized penetration testing, CTF, and security research.

  • Threat modeling, code/cloud/pipeline scanning, shadow-AI discovery, compliance checks and fixes.

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/manteclaw/mcp-server-bug-bounty'

If you have feedback or need assistance with the MCP directory API, please join our Discord server