Skip to main content
Glama
guaidao2

Xuanmu-BugBounty-mcp

by guaidao2

Related Servers

Alternatives to Xuanmu-BugBounty-mcp

No user-submitted related servers found.

    Related Servers

    • A
      license
      Not graded
      quality
      C
      maintenance
      Enables automated bug bounty hunting and security research with tools for reconnaissance, web vulnerability scanning, API testing, binary analysis, and mobile app analysis through an MCP interface.
      MIT
    • F
      license
      Not graded
      quality
      D
      maintenance
      A comprehensive MCP server for automated bug bounty hunting and security reconnaissance, featuring over 28 specialized tools for subdomain discovery, vulnerability scanning, and traffic analysis. It integrates automated scope validation and professional reporting across multiple platforms like HackerOne and Bugcrowd to streamline security testing.
      5
      -
    • F
      license
      Not graded
      quality
      B
      maintenance
      Unified vulnerability search MCP server for penetration testing agents, integrating 5 data sources (NVD, OSV, EPSS, CISA KEV, Exploit-DB+GitHub) and 10 MCP tools for CVE query, keyword search, batch query, EPSS scoring, KEV checking, exploit search, and comprehensive assessment with Chinese output.
      2
      -
    • F
      license
      Not graded
      quality
      D
      maintenance
      基于Kali Linux的MCP服务器,为AI助手提供渗透测试和安全评估工具接口,支持网络扫描、Web扫描、密码攻击等90多个工具。
      4
      -
    • A
      license
      A
      quality
      B
      maintenance
      A scope-aware bug-bounty & reconnaissance MCP server that works out of the box on the Python standard library and augments itself with your favourite CLI tools when they're present.
      22
      MIT
    • A
      license
      A
      quality
      C
      maintenance
      14 atomic MCP tools for AppSec and AI Security engineers: source/schema/prompt audit primitives, JWT inspect, HTTP diff, pentest atoms (default creds, GraphQL introspect, phpggc, interactsh OOB), and a defensive helpers library that fixes the bugs the detectors flag. SARIF output, PyPI Trusted Publishing with Sigstore provenance.
      14
      MIT

    TDQS

    B3.3/5.0

    Scored across 32 tools

    Disambiguation5/5

    Each tool targets a distinct security testing activity—recon, specific vulnerability classes, JWT handling, or reporting—so an agent can reliably choose the right one. Even the JWT tools are cleanly split by decode/analyze/crack/attack, and the only minor overlap (bb_extract vs bb_param_discover) is clarified by their descriptions.

    Naming Consistency5/5

    All tool names follow a uniform bb_ prefix with snake_case, and most use a recognizable vulnerability-or-action pattern (e.g., bb_sqli, bb_port_scan, bb_report). No mixed conventions, camelCase, or vague generic verbs appear.

    Tool Count4/5

    32 tools is heavy, but the server's stated scope is a full bug bounty suite covering reconnaissance, scanning for many vulnerability classes, JWT attacks, GraphQL, secrets, payload generation, and reporting. Each tool earns its place and there is little redundancy, though the count is on the upper end of what an agent can comfortably navigate.

    Completeness5/5

    The tool set covers the full bug bounty workflow: target discovery (subdomain, port, fingerprint), content/path enumeration, detection of major vulnerability classes (SQLi, XSS, SSTI, SSRF, CORS, CSRF, XXE, LFI, etc.), JWT and GraphQL-specific testing, auxiliary helpers (OOB, payloads, raw request sender), and final report generation. No obvious dead-end gaps block a typical assessment.

    Maintenance

    ActivityInactive
    ResponsivenessNo issues