bounty-hunter
Enables scanning and auditing GitHub issues and bounties, filtering out honeypots and high-competition targets before executing.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@bounty-huntercheck if https://github.com/owner/repo/issues/123 is a honeypot"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
BountyHunterOS š”ļøšÆ
The Zero-Token Bounty Radar Daemon, Anti-Honeypot Triage Engine, MCP Server & Autonomous Agent Protocol.
Stop paying Anthropic and OpenAI to get your GitHub account banned by open-source maintainers.
āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā
ā BOUNTY HUNTER OS v1.0 ā
ā Zero-Token Radar Daemon & Anti-Honeypot Engine ā
āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāš The Problem: The AI Bounty Gold Rush Trap
Thousands of developers are pointing Claude Code, Cursor, or autonomous agents at GitHub bounties expecting passive income.
What actually happens?
$50 Token Burn on Dead Repos: Claude crawls a repository with 2,900 open spam PRs or unassigned collaborator lockouts, burning $4 to $8 in tokens before realizing outside PRs are blocked.
Open Lotteries ($C_{\text{comp}} > 0$): Your bot spends 30 minutes solving a bug, only to submit a PR alongside 29 other bots that got there first.
Fake Web3 & Sybil Honeypots: Your agent "wins" a bounty paid in illiquid, unlisted shitcoins (
RTC,slopdotcash) or walks straight into a prompt exfiltration trap.The "AI Slop" Ban: The agent opens a 500-line PR stuffed with rocket emojis š and AI boilerplate, resulting in immediate maintainer bans.
Related MCP server: bug-bounty-hunter
ā” The Solution: Radar + Striker Architecture
BountyHunterOS divides autonomous engineering into two distinct layers:
āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā
ā THE RADAR (Daemon) ā
ā - Programmatic, $0 token cost, lightning fast ā
ā - Scrapes GitHub / Algora / Polar APIs via local GCM ā
ā - Executes Invariants 1ā5 in binary code: ā
ā ā 7-Layer Honeypot Nuke (Sybil, fake tokens, prompts) ā
ā ā Zero-Competition Gate (C_comp == 0 verified) ā
ā ā Collaborator Lockout & Bot Comment Audit ā
ā ā Escrow Provenance Check (Algora, Polar, Ubiquity) ā
ā - Emits ONLY pristine, 100% verified targets ā
āāāāāāāāāāāāāāāāāāāāāāāāāāāāāā¬āāāāāāāāāāāāāāāāāāāāāāāāāāāāāā
ā stdio / JSON / MCP
ā¼
āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā
ā THE STRIKER (The Skill) ā
ā - Loaded into Claude Code / Cursor / Windsurf ā
ā - Executes Invariants 6ā9 (Senior Engineer Camouflage) ā
ā - Reproduction test first -> Surgical fix -> Test pass ā
ā - Utilitarian PR description (< 25 lines, 0 emojis) ā
āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāš Quickstart
1. Installation
git clone https://github.com/your-username/bounty-hunter-os.git
cd bounty-hunter-os
npm link # or use node bin/bounty-hunter.js directly2. Verify Your GitHub Rate Limit (5,000 req/hr)
BountyHunterOS uses your stored Git Credential Manager (GCM) token automatically. No raw API keys needed:
bounty-hunter --auth-check3. Run the Live Radar Scan
Scan recent GitHub bounties and watch the radar filter out honeypots in real time:
bounty-hunter --scanOptional filters:
bounty-hunter --scan --lang typescript --tier14. Audit a Specific Issue URL
Wondering if an issue is a trap before you let Claude touch it?
bounty-hunter --audit https://github.com/owner/repo/issues/123š Model Context Protocol (MCP) Setup
Plug BountyHunterOS directly into Claude Desktop, Claude Code, or Cursor:
Add to your claude_desktop_config.json or Cursor MCP settings:
{
"mcpServers": {
"bounty-hunter": {
"command": "node",
"args": ["/path/to/bounty-hunter-os/bin/bounty-hunter.js", "--mcp"]
}
}
}Now Claude has native tools:
scan_verified_bounties: Returns pre-filtered, uncontested issues ready for execution.audit_bounty_issue: Validates an issue before writing a single line of code.
š§ The Striker Skill (Agent Rules)
Drop skills/.cursorrules into your project root, or include skills/hired-worker.skill.md in your agent's system prompt:
Invariant 1: Zero meeting/social overhead. 100% async text execution.
Invariant 2: Zero-Competition Gate ($C_{\text{comp}} == 0$).
Invariant 5: Strict Fork-and-Branch protocol.
Invariant 6: Reproduction Test First. Never edit source code without an isolated failing test.
Invariant 7: Native Verification Gate (
npm test && tsc --noEmitmust exit 0).Invariant 8: Utilitarian PR description under 25 lines with zero emojis and zero AI marketing slop.
šŖ¤ The Trojan Horse (Crawler Bait Funnel)
Included in this repository is the complete automated funnel to capture organic bot traffic:
bait-trap/BOUNTY_BAIT_TEMPLATE.md: An issue template tagged withbounty,reward: $250, andalgora. External bounty scrapers index this within 90 seconds and blast it to tens of thousands of automated agents.bait-trap/.github/workflows/anti-bot-trap.yml: A GitHub Action that automatically intercepts speculative bot pull requests, closes them immediately, calculates their wasted LLM tokens, and pitches BountyHunterOS.
š License
MIT License. Built for pragmatic developers who prefer cash flow over burned compute.
This server cannot be deployed
Maintenance
Related MCP Connectors
Audit GitHub repos for malicious and supply-chain code before you depend on them.
Screens public GitHub repos and PRs to generate risk maps, findings, and merge-readiness signals.
Discover verified deep-tech engineering bounties from any AI agent.
Scan GitHub-hosted AI skills for vulnerabilities: prompt injection, malware, OWASP LLM Top 10.
Related MCP Servers
- AlicenseCqualityDmaintenanceEnables AI agents to generate and manage specialized bug bounty hunting workflows including reconnaissance, vulnerability testing, OSINT gathering, and file upload testing. Provides REST API endpoints for comprehensive security assessments with intelligence-driven vulnerability prioritization.402MIT
- AlicenseNot gradedqualityCmaintenanceAutomates bug bounty hunting across Web2 and Web3 platforms, performing recon, vulnerability scanning, Solidity audits, and report generation.MIT
- AlicenseAqualityDmaintenanceEnables AI agents to find and query real-time GitHub coding bounties with built-in scam filtering, supporting listing, matching, and detailed bounty retrieval.427 npmApache 2.0
- AlicenseNot gradedqualityBmaintenanceEnables authorized bug bounty automation via a scope-enforced MCP bridge, supporting web, secrets, mobile, and LLM red-team scanning, with reporting and advisory.MIT