Skip to main content
Glama
pablocian

h1-hacker-mcp

by pablocian

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault
HACKERONE_API_TOKENYesYour HackerOne API token
HACKERONE_API_IDENTIFIERYesYour HackerOne API token identifier

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Features and capabilities supported by this server

Protocol revision2025-11-25

CapabilityDetails
tools
{
  "listChanged": false
}
prompts
{
  "listChanged": false
}
resources
{
  "subscribe": false,
  "listChanged": false
}

Tools

Functions exposed to the LLM to take actions

NameDescription
check_credentialsA

Check the stored HackerOne API token by requesting one program.

list_programsA

List programs the hacker account can access.

Program policies are omitted from this list. Call get_program for the policy
and declaration flags. page_number starts at 1. page_size is 1-100.
get_programA

Get one program, including its policy and declaration flags.

Declaration flags are offers_bounties, open_scope, fast_payments,
gold_standard_safe_harbor, and allows_bounty_splitting. handle is the
program handle from list_programs, such as "security".
list_structured_scopesA

List a program's structured scope (in-scope and submission-eligible assets).

Each asset includes asset_identifier, asset_type, eligible_for_submission,
eligible_for_bounty, max_severity, and instruction. Limited to 50 requests
per minute. Page offsets cover at most 10,000 rows; pass id_gt (the last
seen scope id) to continue, and prefer that over high page numbers.
created_after and updated_after are ISO-8601 timestamps.
list_scope_exclusionsC

List report categories a program excludes from rewards, beyond core ineligible findings.

list_weaknessesB

List weakness types a program accepts. page_number starts at 1. page_size is 1-100.

list_my_reportsA

List reports submitted by the authenticated hacker.

This page does not include report activity. Call get_report for the full
report. page_number starts at 1. page_size is 1-100.
get_reportA

Get one report the account can view, including activity.

Includes reporter, program, weakness, severity, bounties, swag, activities,
attachment metadata (with expiring download URLs), structured scope, and
summaries. vulnerability_information is present when the hacker owns the
report. This tool does not download attachment bytes.
search_hacktivityA

Search publicly disclosed hacktivity reports.

query is an Apache Lucene query. Filters: severity_rating, asset_type,
substate, cwe, cve_ids, reporter, team, total_awarded_amount, disclosed_at,
has_collaboration, disclosed. Example:
severity_rating:critical AND disclosed_at:>=01-01-1970.
sort is latest_disclosable_activity_at, disclosed_at, total_awarded_amount,
or votes. Prefix with - for descending order. The API default is
-latest_disclosable_activity_at.
get_balanceA

Get the authenticated hacker's current payments balance.

list_earningsB

List earnings (bounties, retests, and pentests) for the authenticated hacker.

list_payoutsB

List payouts sent to the authenticated hacker.

list_report_intentsA

List unsubmitted report-intent drafts owned by the authenticated hacker.

This does not submit them.

get_report_intentB

Get one report-intent draft. This does not submit or update it.

list_report_intent_attachmentsA

List attachment metadata for a report-intent draft, including expiring download URLs.

This does not download file bytes or upload attachments.

Prompts

Interactive templates invoked by user choice

NameDescription

No prompts

Resources

Contextual data attached and managed by the client

NameDescription

No resources

TDQS

A3.7/5.0

Scored across 15 tools

Disambiguation5/5

Each tool targets a distinct resource and action: program listing/getting, report listing/getting, hacktivity search, scopes/exclusions/weaknesses, and financial tools (balance/earnings/payouts) are clearly separated. The report-intent trio (get_report_intent, list_report_intents, list_report_intent_attachments) also has clear boundaries via verb and object. No two tools appear to do the same thing.

Naming Consistency5/5

Every tool follows a strict verb_noun pattern (list_programs, get_program, list_my_reports, get_balance, search_hacktivity, etc.) with snake_case throughout. No camelCase or vague single-word verbs are mixed in.

Tool Count5/5

15 tools is within the well-scoped range and each maps to a distinct HackerOne resource family. No redundant or filler tools inflate the count.

Completeness3/5

Read coverage is strong (programs, reports, scopes, earnings, payouts, hacktivity), but the report-intent surface offers get/list/attachments with no create, update, submit, or delete, which is a notable lifecycle gap. There is also no way to submit or mutate reports, leaving several dead ends for the draft workflow the tools imply.

Maintenance

ActivityMaintained
ResponsivenessNo issues