bug-bounty-hunter
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@bug-bounty-hunterScan this URL for SQLi and XSS"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Bug Bounty Hunter MCP Server 🎯⚡
Automated recon → vuln scan → Solidity audit → report → submit. Hunt while you sleep.
Bug bounty automation toolkit exposed as a Model Context Protocol (MCP) server. Hunt Web2 and Web3 vulnerabilities across Immunefi, Code4rena, Cantina, HackerOne, and Bugcrowd.
What It Does
Tool | What It Does |
| Subdomain enum, tech detection, port scan, screenshots, JS endpoint extraction |
| SQLi, XSS, IDOR, SSRF, LFI, open redirect, CORS, JWT weaknesses |
| Reentrancy, oracle manipulation, access control, delegatecall, tx.origin, timestamp |
| Track programs, filter by platform/bounty/web3 focus |
| CVSS-scored reports with PoC and remediation |
Related MCP server: Bug Bounty MCP Server
Install
pip install mcp-server-bug-bounty
# OR
git clone https://github.com/manteclaw/mcp-server-bug-bounty.gitConnect
{
"mcpServers": {
"bug-bounty": {
"command": "python",
"args": ["/path/to/server.py"]
}
}
}Usage Examples
"Recon this target with deep scanning"
"Scan this URL for SQLi and XSS"
"Audit this Solidity contract for reentrancy and access control"
"List all Immunefi programs with $1M+ max bounty"
"Generate a report for these findings on Uniswap program"
Pricing
Tier | Price | Limits |
Community | Free | 10 calls/day |
Hunter | $59/month | Unlimited scans + auto-report |
Team | $399/month | Multi-target + Slack alerts |
License
MIT
Built by Manteclaw | Immunefi-native hunter | Ship or die
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- Flicense-qualityDmaintenanceAI-powered cybersecurity automation platform with 150+ security tools and 12+ autonomous AI agents for penetration testing, vulnerability assessment, and bug bounty hunting. Enables comprehensive security testing through intelligent tool selection and automated workflows.Last updated2
- AlicenseCqualityDmaintenanceEnables AI agents to generate and manage specialized bug bounty hunting workflows including reconnaissance, vulnerability testing, OSINT gathering, and file upload testing. Provides REST API endpoints for comprehensive security assessments with intelligence-driven vulnerability prioritization.Last updated402MIT
- Alicense-qualityFmaintenanceEnables comprehensive security testing and penetration testing through natural language conversations with 92+ tools for reconnaissance, vulnerability assessment, web application testing, OSINT, and reporting. Designed for authorized bug bounty hunting and security assessments.Last updated38MIT
- AlicenseCqualityDmaintenanceAn automated penetration testing framework that enables intelligent security assessments through reconnaissance, vulnerability scanning, and controlled exploitation. Features AI-driven workflow management with comprehensive reporting for authorized security testing.Last updated27217BSD 3-Clause
Related MCP Connectors
AI-powered threat intelligence, smart contract auditing, and cybersecurity OSINT.
Offline methodology engine for authorized penetration testing, CTF, and security research.
Threat modeling, code/cloud/pipeline scanning, shadow-AI discovery, compliance checks and fixes.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/manteclaw/mcp-server-bug-bounty'
If you have feedback or need assistance with the MCP directory API, please join our Discord server