Best HackerOne MCP Servers
HackerOne is the leading hacker-powered security platform, helping organizations find and fix critical vulnerabilities before they can be criminally exploited.
Why this server?
Provides tools for interacting with the HackerOne API to manage vulnerability reports, bug bounty programs, and earnings, including capabilities to submit findings, respond to triage, and analyze hunting patterns.
FlicenseAqualityCmaintenanceProvides read-only access to HackerOne reports, program scopes, and bounty earnings through the HackerOne API. It enables users to analyze hunting patterns, check asset eligibility, and retrieve report details or triage conversations via natural language.Last updated927Why this server?
Supports security testing and reconnaissance for bug bounty programs, including subdomain enumeration, vulnerability scanning, and report generation for authorized assessments.
Alicense-qualityCmaintenanceProfessional security testing server with 50+ integrated tools for web application vulnerability scanning, reconnaissance, fuzzing, and API testing. Enables comprehensive bug bounty hunting workflows including subdomain enumeration, XSS/SQLi detection, and automated security assessments.Last updatedMITWhy this server?
Enables integration with the HackerOne platform for managing bug bounty programs, validating scope, and tracking security testing activities.
Flicense-qualityCmaintenanceA comprehensive MCP server for automated bug bounty hunting and security reconnaissance, featuring over 28 specialized tools for subdomain discovery, vulnerability scanning, and traffic analysis. It integrates automated scope validation and professional reporting across multiple platforms like HackerOne and Bugcrowd to streamline security testing.Last updated3Why this server?
Allows scanning of HackerOne program scope targets using Nuclei, with automatic scope gating based on HackerOne scope snapshots.
Flicense-qualityDmaintenanceA scoped Nuclei MCP server that only scans targets from HackerOne scope snapshots, enforcing exact, wildcard, and fuzzy matches before running scans.Last updatedWhy this server?
Provides passive reconnaissance using Shodan, with scope validation against HackerOne program snapshots to ensure only in-scope targets are queried.
Flicense-qualityCmaintenancePassive reconnaissance MCP server powered by Shodan, enabling host lookups, search, and DNS queries gated against HackerOne scope snapshots.Last updated