h1-hacker-mcp
# h1-hacker-mcp
Read-only MCP server for the [HackerOne Hacker API](https://api.hackerone.com/hacker-resources/). An agent can read the programs, policies, scope, reports, and payments the authenticated hacker account can already see. It cannot create, update, or submit reports.
## Credentials
Create an API token in HackerOne under Settings → API Token, then set:
```bash
export HACKERONE_API_IDENTIFIER="your-api-token-identifier"
export HACKERONE_API_TOKEN="your-api-token"
```
## Cursor
Add this to your MCP config. The process needs the two environment variables above.
```json
{
"mcpServers": {
"h1-hacker": {
"command": "uv",
"args": ["run", "--directory", "/absolute/path/to/h1-hacker-mcp", "h1-hacker-mcp"]
}
}
}
```
## Run
```bash
uv run h1-hacker-mcp
```
## Docker
The image starts the same stdio server. Credentials are read from the environment at run time and are not copied into the image.
```bash
docker build -t h1-hacker-mcp .
```
Cursor must keep stdin open and must not allocate a TTY, because a TTY corrupts the MCP stream. `-e NAME` forwards each variable from the environment that launches Cursor.
```json
{
"mcpServers": {
"h1-hacker": {
"command": "docker",
"args": [
"run", "-i", "--rm",
"-e", "HACKERONE_API_IDENTIFIER",
"-e", "HACKERONE_API_TOKEN",
"h1-hacker-mcp"
]
}
}
}
```
TDQS
Scored across 15 tools
Each tool targets a distinct resource and action: program listing/getting, report listing/getting, hacktivity search, scopes/exclusions/weaknesses, and financial tools (balance/earnings/payouts) are clearly separated. The report-intent trio (get_report_intent, list_report_intents, list_report_intent_attachments) also has clear boundaries via verb and object. No two tools appear to do the same thing.
Every tool follows a strict verb_noun pattern (list_programs, get_program, list_my_reports, get_balance, search_hacktivity, etc.) with snake_case throughout. No camelCase or vague single-word verbs are mixed in.
15 tools is within the well-scoped range and each maps to a distinct HackerOne resource family. No redundant or filler tools inflate the count.
Read coverage is strong (programs, reports, scopes, earnings, payouts, hacktivity), but the report-intent surface offers get/list/attachments with no create, update, submit, or delete, which is a notable lifecycle gap. There is also no way to submit or mutate reports, leaving several dead ends for the draft workflow the tools imply.