h1-hacker-mcp
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| HACKERONE_API_TOKEN | Yes | Your HackerOne API token | |
| HACKERONE_API_IDENTIFIER | Yes | Your HackerOne API token identifier |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": false
} |
| prompts | {
"listChanged": false
} |
| resources | {
"subscribe": false,
"listChanged": false
} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| check_credentialsA | Check the stored HackerOne API token by requesting one program. |
| list_programsA | List programs the hacker account can access. |
| get_programA | Get one program, including its policy and declaration flags. |
| list_structured_scopesA | List a program's structured scope (in-scope and submission-eligible assets). |
| list_scope_exclusionsC | List report categories a program excludes from rewards, beyond core ineligible findings. |
| list_weaknessesB | List weakness types a program accepts. page_number starts at 1. page_size is 1-100. |
| list_my_reportsA | List reports submitted by the authenticated hacker. |
| get_reportA | Get one report the account can view, including activity. |
| search_hacktivityA | Search publicly disclosed hacktivity reports. |
| get_balanceA | Get the authenticated hacker's current payments balance. |
| list_earningsB | List earnings (bounties, retests, and pentests) for the authenticated hacker. |
| list_payoutsB | List payouts sent to the authenticated hacker. |
| list_report_intentsA | List unsubmitted report-intent drafts owned by the authenticated hacker. This does not submit them. |
| get_report_intentB | Get one report-intent draft. This does not submit or update it. |
| list_report_intent_attachmentsA | List attachment metadata for a report-intent draft, including expiring download URLs. This does not download file bytes or upload attachments. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 15 tools
Each tool targets a distinct resource and action: program listing/getting, report listing/getting, hacktivity search, scopes/exclusions/weaknesses, and financial tools (balance/earnings/payouts) are clearly separated. The report-intent trio (get_report_intent, list_report_intents, list_report_intent_attachments) also has clear boundaries via verb and object. No two tools appear to do the same thing.
Every tool follows a strict verb_noun pattern (list_programs, get_program, list_my_reports, get_balance, search_hacktivity, etc.) with snake_case throughout. No camelCase or vague single-word verbs are mixed in.
15 tools is within the well-scoped range and each maps to a distinct HackerOne resource family. No redundant or filler tools inflate the count.
Read coverage is strong (programs, reports, scopes, earnings, payouts, hacktivity), but the report-intent surface offers get/list/attachments with no create, update, submit, or delete, which is a notable lifecycle gap. There is also no way to submit or mutate reports, leaving several dead ends for the draft workflow the tools imply.