Skip to main content
Glama

Decepticon v3.1 — Autonomous Bug Bounty Hunt Bundle

One command, full pipeline. Skill methodology + MCP server + H1 auto-submit + profit tracking. Works with OpenCode, Claude Desktop, and any MCP-compatible AI agent.

Quick Install

npx decepticon           # Interactive setup wizard

or via npm:

npm install -g decepticon
decepticon setup

Related MCP server: VulneraMCP

What You Get

Component

Purpose

Skill

Complete H1 bug bounty methodology — 3-wave pipeline, reasoning engine, 20+ exploitation playbooks

MCP Server

Real-time state coordination, credential vault, session management, payload generation

H1 Auto-Submit

Generate H1-ready reports with CVSS/CWE → auto-submit via REST API

Profit Tracking

Bounty ledger with 75%/15%/10% split — every dollar tracked

Dashboard

Live web dashboard at http://127.0.0.1:9999

Setup Wizard

Interactive CLI that configures everything in 3 prompts

Usage

# Setup (first time)
npx decepticon setup

# Start a hunt
opencode hunter
# Then type: HACK https://hackerone.com/program-handle

# View earnings
npx decepticon status

# Launch dashboard
npx decepticon dashboard

Profit Split

  • 75% — You (the hunter)

  • 15% — Decepticon platform

  • 10% — Referral partner

All tracked automatically in ~/.opencode/decepticon-state/bounty_ledger.json.

Requirements

  • Python 3.7+ (for MCP server)

  • OpenCode or Claude Desktop

  • Python 3.11+ recommended

A
license - permissive license
-
quality - not tested
C
maintenance

Maintenance

Maintainers
Response time
Release cycle
Releases (12mo)
Commit activity

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Servers

  • A
    license
    C
    quality
    D
    maintenance
    Enables AI agents to generate and manage specialized bug bounty hunting workflows including reconnaissance, vulnerability testing, OSINT gathering, and file upload testing. Provides REST API endpoints for comprehensive security assessments with intelligence-driven vulnerability prioritization.
    Last updated
    40
    2
    MIT
  • A
    license
    B
    quality
    A
    maintenance
    AI-powered bug bounty hunting platform that integrates security tools (OWASP ZAP, Caido, Burp Suite) for automated reconnaissance, vulnerability testing, JavaScript analysis, and finding management with PostgreSQL storage.
    Last updated
    47
    37
    MIT
  • F
    license
    -
    quality
    D
    maintenance
    A comprehensive MCP server for automated bug bounty hunting and security reconnaissance, featuring over 28 specialized tools for subdomain discovery, vulnerability scanning, and traffic analysis. It integrates automated scope validation and professional reporting across multiple platforms like HackerOne and Bugcrowd to streamline security testing.
    Last updated
    5
  • F
    license
    -
    quality
    C
    maintenance
    Wraps multiple bug bounty platform APIs (HackerOne, Bugcrowd, etc.) behind a uniform MCP tool surface, enabling LLM agents to query programs, scope, and briefs across platforms through a single interface.
    Last updated

View all related MCP servers

Related MCP Connectors

  • Control plane for autonomous software labor. Agents claim objectives over MCP with audit trail.

  • HiveCapital MCP Server — autonomous investment layer for AI agents

  • MCP server for Pentest-Tools.com: run scans, manage findings and reports via your preffered LLM.

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/itsdanylol/DECEPTICON'

If you have feedback or need assistance with the MCP directory API, please join our Discord server