Best Bugcrowd MCP Servers
Bugcrowd is a crowdsourced cybersecurity platform that connects organizations with a global community of security researchers to identify vulnerabilities before they can be exploited.
Why this server?
Integrates the Bugcrowd Vulnerability Rating Taxonomy (VRT) to provide baseline priority and finding categorization for vulnerability research, enabling assessment of findings against Bugcrowd's standardized taxonomy.
AlicenseAqualityBmaintenanceThis local MCP server keeps vulnerability intelligence, research scope, scanner results, evidence receipts, Bugcrowd VRT assessments, and report drafts in one SQLite ledger. It is built for authorized defensive research and does not scan, exploit, or submit reports.191MITWhy this server?
Enables managing bug bounty hunt sessions, findings, leads, and reports for Bugcrowd programs through the BountyLens platform.

@bountylens/mcpofficial
AlicenseNot gradedqualityDmaintenanceConnects Claude Code to BountyLens Hunter Tracker for managing bug bounty hunt sessions, findings, leads, and programs.11 npm64MITWhy this server?
Supports security testing and reconnaissance for bug bounty programs, including subdomain enumeration, vulnerability scanning, and report generation for authorized assessments.
AlicenseNot gradedqualityDmaintenanceProfessional security testing server with 50+ integrated tools for web application vulnerability scanning, reconnaissance, fuzzing, and API testing. Enables comprehensive bug bounty hunting workflows including subdomain enumeration, XSS/SQLi detection, and automated security assessments.1MITWhy this server?
Provides bug bounty report templates and integrates with Bugcrowd for structured vulnerability reporting.
AlicenseNot gradedqualityAmaintenanceAI-agent-optimized CVE exploit discovery toolkit that provides 19 tools for finding proof-of-concept exploits, CTF labs, bug bounty reports, and vulnerability intelligence from a single interface.24 PyPI5MITWhy this server?
Integrates with Bugcrowd to manage bug bounty programs, track scope, list programs, and generate reports.
AlicenseNot gradedqualityCmaintenanceAutomates bug bounty hunting across Web2 and Web3 platforms, performing recon, vulnerability scanning, Solidity audits, and report generation.MITWhy this server?
Indexes the Bugcrowd Vulnerability Rating Taxonomy (VRT) as part of the searchable corpus, letting agents retrieve Bugcrowd's vulnerability classification and rating data alongside other sources.
AlicenseNot gradedqualityBmaintenanceA source-grounded cybersecurity knowledge & research MCP server that provides read-only search, exact citations, and a knowledge graph, designed to run alongside execution MCPs.2MITWhy this server?
Referenced as a resource for bug bounty program rules and responsible disclosure best practices
AlicenseNot gradedqualityDmaintenanceEnables AI assistants to perform authorized security testing and penetration testing operations including SSL/TLS analysis, port scanning, vulnerability scanning, and HTTP security header audits through natural language interactions.1MITWhy this server?
Generates vulnerability reports formatted for Bugcrowd, suitable for bug bounty submissions.
FlicenseNot gradedqualityCmaintenanceExposes all PHANTOM security testing capabilities as MCP tools, enabling reconnaissance, vulnerability scanning, red teaming, and report generation through natural language interactions.2-Why this server?
Provides tools for interacting with Bugcrowd's API to list programs, get program details, and retrieve scope assets for bug bounty programs.
FlicenseNot gradedqualityDmaintenanceWraps multiple bug bounty platform APIs (HackerOne, Bugcrowd, etc.) behind a uniform MCP tool surface, enabling LLM agents to query programs, scope, and briefs across platforms through a single interface.-