Best HackerOne MCP Servers
HackerOne is the leading hacker-powered security platform, helping organizations find and fix critical vulnerabilities before they can be criminally exploited.
Why this server?
Provides tools for interacting with HackerOne's API, enabling users to list and retrieve reports, list programs, and get program scopes and details.
AlicenseBqualityCmaintenanceEnables MCP clients like Claude and Codex to interact with HackerOne's API to list and get reports, programs, and scopes.21252MITWhy this server?
Provides read-only tools to interact with a HackerOne researcher account, including listing programs, scopes, reports, earnings, searching disclosed reports, and drafting bug reports.
FlicenseAqualityBmaintenanceA local, read-only MCP server that connects your HackerOne researcher account to Claude Desktop and Claude Code, helping you find targets, analyze program scopes, review reports and earnings, and draft bug reports.175Why this server?
Provides tools for interacting with the HackerOne API to manage vulnerability reports, bug bounty programs, and earnings, including capabilities to submit findings, respond to triage, and analyze hunting patterns.
FlicenseAqualityDmaintenanceProvides read-only access to HackerOne reports, program scopes, and bounty earnings through the HackerOne API. It enables users to analyze hunting patterns, check asset eligibility, and retrieve report details or triage conversations via natural language.940Why this server?
Integrates HackerOne's corpus of disclosed reports to find similar reports and provide intel during bug bounty hunts.
Alicense-qualityCmaintenanceA local MCP daemon that turns an agentic coding client into a bug bounty operator, with 103 tools for offensive security testing including MITM proxy, traffic analysis, and OOB callbacks.42MITWhy this server?
Supports security testing and reconnaissance for bug bounty programs, including subdomain enumeration, vulnerability scanning, and report generation for authorized assessments.
Alicense-qualityDmaintenanceProfessional security testing server with 50+ integrated tools for web application vulnerability scanning, reconnaissance, fuzzing, and API testing. Enables comprehensive bug bounty hunting workflows including subdomain enumeration, XSS/SQLi detection, and automated security assessments.1MITWhy this server?
Manage bug bounty reports and vulnerability disclosures via HackerOne API.
Alicense-qualityDmaintenanceA Model Context Protocol server for orchestrating red team security assessments, enabling LLMs to manage agents, targets, operations, and findings aligned with MITRE ATT&CK framework.MITWhy this server?
Loads HackerOne program scope from local H1-Scope-Watcher snapshots to enforce scope boundaries during recon activities.
Alicense-qualityBmaintenanceA local Python MCP server for safe, human-led bug bounty recon, providing lightweight helpers for scope checks, headers, robots.txt, sitemap.xml, JavaScript URL collection, endpoint extraction, URL deduplication, evidence notes, and manual test planning.MITWhy this server?
Integrates with HackerOne to fetch and search personal and public bug bounty reports, programs, and scopes, enabling AI-assisted vulnerability analysis and attack briefing generation.
Alicense-qualityCmaintenanceConnects AI assistants to HackerOne to pull bug bounty history, program scopes, and report details into a local SQLite database, exposing tools for searching, analyzing, and generating attack briefings using both personal and public disclosed reports.333MITWhy this server?
Provides bug bounty report templates and integrates with HackerOne for structured vulnerability reporting.
Alicense-qualityAmaintenanceAI-agent-optimized CVE exploit discovery toolkit that provides 19 tools for finding proof-of-concept exploits, CTF labs, bug bounty reports, and vulnerability intelligence from a single interface.5MIT