Decepticon
Provides tools for automated bug bounty hunting on HackerOne, including report generation with CVSS/CWE and auto-submission via REST API.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@Decepticonhunt uber"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Decepticon v3.1 — Autonomous Bug Bounty Hunt Bundle
One command, full pipeline. Skill methodology + MCP server + H1 auto-submit + profit tracking. Works with OpenCode, Claude Desktop, and any MCP-compatible AI agent.
Quick Install
npx decepticon # Interactive setup wizardor via npm:
npm install -g decepticon
decepticon setupRelated MCP server: VulneraMCP
What You Get
Component | Purpose |
Skill | Complete H1 bug bounty methodology — 3-wave pipeline, reasoning engine, 20+ exploitation playbooks |
MCP Server | Real-time state coordination, credential vault, session management, payload generation |
H1 Auto-Submit | Generate H1-ready reports with CVSS/CWE → auto-submit via REST API |
Profit Tracking | Bounty ledger with 75%/15%/10% split — every dollar tracked |
Dashboard | Live web dashboard at http://127.0.0.1:9999 |
Setup Wizard | Interactive CLI that configures everything in 3 prompts |
Usage
# Setup (first time)
npx decepticon setup
# Start a hunt
opencode hunter
# Then type: HACK https://hackerone.com/program-handle
# View earnings
npx decepticon status
# Launch dashboard
npx decepticon dashboardProfit Split
75% — You (the hunter)
15% — Decepticon platform
10% — Referral partner
All tracked automatically in ~/.opencode/decepticon-state/bounty_ledger.json.
Requirements
Python 3.7+ (for MCP server)
OpenCode or Claude Desktop
Python 3.11+ recommended
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- AlicenseCqualityDmaintenanceEnables AI agents to generate and manage specialized bug bounty hunting workflows including reconnaissance, vulnerability testing, OSINT gathering, and file upload testing. Provides REST API endpoints for comprehensive security assessments with intelligence-driven vulnerability prioritization.Last updated402MIT
- AlicenseBqualityAmaintenanceAI-powered bug bounty hunting platform that integrates security tools (OWASP ZAP, Caido, Burp Suite) for automated reconnaissance, vulnerability testing, JavaScript analysis, and finding management with PostgreSQL storage.Last updated4737MIT
- Flicense-qualityDmaintenanceA comprehensive MCP server for automated bug bounty hunting and security reconnaissance, featuring over 28 specialized tools for subdomain discovery, vulnerability scanning, and traffic analysis. It integrates automated scope validation and professional reporting across multiple platforms like HackerOne and Bugcrowd to streamline security testing.Last updated5
- Flicense-qualityCmaintenanceWraps multiple bug bounty platform APIs (HackerOne, Bugcrowd, etc.) behind a uniform MCP tool surface, enabling LLM agents to query programs, scope, and briefs across platforms through a single interface.Last updated
Related MCP Connectors
Control plane for autonomous software labor. Agents claim objectives over MCP with audit trail.
HiveCapital MCP Server — autonomous investment layer for AI agents
MCP server for Pentest-Tools.com: run scans, manage findings and reports via your preffered LLM.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/itsdanylol/DECEPTICON'
If you have feedback or need assistance with the MCP directory API, please join our Discord server