Decepticon
Decepticon v3.1 — Autonomous Bug Bounty Hunt Bundle
One command, full pipeline. Skill methodology + MCP server + H1 auto-submit + profit tracking. Works with OpenCode, Claude Desktop, and any MCP-compatible AI agent.
Quick Install
npx decepticon # Interactive setup wizardor via npm:
npm install -g decepticon
decepticon setupWhat You Get
Component | Purpose |
Skill | Complete H1 bug bounty methodology — 3-wave pipeline, reasoning engine, 20+ exploitation playbooks |
MCP Server | Real-time state coordination, credential vault, session management, payload generation |
H1 Auto-Submit | Generate H1-ready reports with CVSS/CWE → auto-submit via REST API |
Profit Tracking | Bounty ledger with 75%/15%/10% split — every dollar tracked |
Dashboard | Live web dashboard at http://127.0.0.1:9999 |
Setup Wizard | Interactive CLI that configures everything in 3 prompts |
Usage
# Setup (first time)
npx decepticon setup
# Start a hunt
opencode hunter
# Then type: HACK https://hackerone.com/program-handle
# View earnings
npx decepticon status
# Launch dashboard
npx decepticon dashboardProfit Split
75% — You (the hunter)
15% — Decepticon platform
10% — Referral partner
All tracked automatically in ~/.opencode/decepticon-state/bounty_ledger.json.
Requirements
Python 3.7+ (for MCP server)
OpenCode or Claude Desktop
Python 3.11+ recommended
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/itsdanylol/DECEPTICON'
If you have feedback or need assistance with the MCP directory API, please join our Discord server