Skip to main content
Glama
pablocian

h1-hacker-mcp

by pablocian
README.md
# h1-hacker-mcp

Read-only MCP server for the [HackerOne Hacker API](https://api.hackerone.com/hacker-resources/). An agent can read the programs, policies, scope, reports, and payments the authenticated hacker account can already see. It cannot create, update, or submit reports.

## Credentials

Create an API token in HackerOne under Settings → API Token, then set:

```bash
export HACKERONE_API_IDENTIFIER="your-api-token-identifier"
export HACKERONE_API_TOKEN="your-api-token"
```

## Cursor

Add this to your MCP config. The process needs the two environment variables above.

```json
{
  "mcpServers": {
    "h1-hacker": {
      "command": "uv",
      "args": ["run", "--directory", "/absolute/path/to/h1-hacker-mcp", "h1-hacker-mcp"]
    }
  }
}
```

## Run

```bash
uv run h1-hacker-mcp
```

## Docker

The image starts the same stdio server. Credentials are read from the environment at run time and are not copied into the image.

```bash
docker build -t h1-hacker-mcp .
```

Cursor must keep stdin open and must not allocate a TTY, because a TTY corrupts the MCP stream. `-e NAME` forwards each variable from the environment that launches Cursor.

```json
{
  "mcpServers": {
    "h1-hacker": {
      "command": "docker",
      "args": [
        "run", "-i", "--rm",
        "-e", "HACKERONE_API_IDENTIFIER",
        "-e", "HACKERONE_API_TOKEN",
        "h1-hacker-mcp"
      ]
    }
  }
}
```

TDQS

A3.7/5.0

Scored across 15 tools

Disambiguation5/5

Each tool targets a distinct resource and action: program listing/getting, report listing/getting, hacktivity search, scopes/exclusions/weaknesses, and financial tools (balance/earnings/payouts) are clearly separated. The report-intent trio (get_report_intent, list_report_intents, list_report_intent_attachments) also has clear boundaries via verb and object. No two tools appear to do the same thing.

Naming Consistency5/5

Every tool follows a strict verb_noun pattern (list_programs, get_program, list_my_reports, get_balance, search_hacktivity, etc.) with snake_case throughout. No camelCase or vague single-word verbs are mixed in.

Tool Count5/5

15 tools is within the well-scoped range and each maps to a distinct HackerOne resource family. No redundant or filler tools inflate the count.

Completeness3/5

Read coverage is strong (programs, reports, scopes, earnings, payouts, hacktivity), but the report-intent surface offers get/list/attachments with no create, update, submit, or delete, which is a notable lifecycle gap. There is also no way to submit or mutate reports, leaving several dead ends for the draft workflow the tools imply.

Maintenance

ActivityMaintained
ResponsivenessNo issues