Skip to main content
Glama

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault
H1_MCP_ENVNoPath to the shared credentials file.~/.config/h1-mcp/env
H1_MCP_HOMENoDirectory for the default file.~/.config/h1-mcp
H1_USERNAMEYesHackerOne username (wins over the file).
H1_API_TOKENYesHackerOne API token.

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Features and capabilities supported by this server

Protocol revision2025-11-25

CapabilityDetails
tools
{
  "listChanged": false
}
prompts
{
  "listChanged": false
}
resources
{
  "subscribe": false,
  "listChanged": false
}
experimental
{}

Tools

Functions exposed to the LLM to take actions

NameDescription
list_programsA

List HackerOne programs you can access. Filter by bounty eligibility, submission state or a handle/name substring. Returns handles to feed the other tools.

get_programB

Program metadata and policy (truncated). Set flags to also include structured scope and/or scope exclusions in one call.

get_structured_scopesC

In-scope assets for a program: identifier, type, bounty eligibility and max severity.

get_scope_exclusionsC

Report categories the program excludes from rewards (out-of-scope classes).

check_in_scopeA

Decide whether an asset (host, URL, IP or CIDR entry) is covered by a program's structured scope. Returns every matching scope entry plus the program's exclusions as caveats.

hacktivity_searchB

Search disclosed reports (dedup / prior art). query uses HackerOne Lucene syntax, e.g. team:security AND cwe:"CWE-79". sort defaults to newest, e.g. -disclosed_at.

search_disclosed_reportsC

Disclosed reports for one program (dedup scoped to the program you are hunting).

my_reportsB

Your own submitted reports (state, severity, bounty). Pass report_id for one report.

Prompts

Interactive templates invoked by user choice

NameDescription

No prompts

Resources

Contextual data attached and managed by the client

NameDescription

No resources

TDQS

B3/5.0

Scored across 8 tools

Disambiguation3/5

There is meaningful overlap: get_program can optionally return structured scope and exclusions, duplicating get_structured_scopes and get_scope_exclusions, and hacktivity_search vs search_disclosed_reports both search disclosed reports. Descriptions clarify scope (global Lucene vs per-program) and intent, but an agent can reasonably hesitate between the program-metadata tool with flags and the dedicated scope tools.

Naming Consistency3/5

Most tools use a readable snake_case verb_noun pattern (list_programs, get_program, get_structured_scopes, check_in_scope). However hacktivity_search reverses the order compared to search_disclosed_reports, and my_reports is a possessive noun rather than a verb, creating mixed conventions.

Tool Count4/5

Eight tools is a well-sized surface for the HackerOne domain, comfortably within the 3-15 range. There is slight redundancy because get_structured_scopes and get_scope_exclusions overlap with get_program's flags, so not every tool strictly earns an independent place.

Completeness4/5

The set covers program discovery, policy/scope lookup, scope checking, disclosed-report research, and a user's own reports—core hunting workflows. Gaps are minor for a read-oriented server: no report submission, no direct get-by-ID for disclosed reports, and program policy is noted as truncated.

Maintenance

ActivityMaintained
ResponsivenessNo issues