BountyPilot
Provides an Alexa+ integration surface over MCP, exposing BountyPilot's tools for analyzing opportunities, saving them to a queue, comparing opportunities, building submission plans, tracking status, and asking for the next best action.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@BountyPilotanalyze this bounty opportunity and save it to my queue"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
BountyPilot
BountyPilot is a self-hosted Model Context Protocol server plus a web-based Alexa+ simulation built for the Amazon Developer Hackathon 2026 — Alexa+ track.
It turns bounty hunting into a stateful agent workflow instead of a one-shot Q&A:
analyze an opportunity against an async, code-first profile;
save it to a persistent queue;
compare opportunities without hiding blockers;
build a concrete submission plan;
track progress across sessions;
ask for the next best action.
The simulator invokes the same seven MCP tools through the official SDK using an in-memory MCP transport. The separately exposed /mcp route serves the same tool surface over Streamable HTTP for external clients and Alexa+ integration.
Track technology
Self-hosted MCP server
Streamable HTTP endpoint:
/mcpMCP TypeScript SDK v2
Verified negotiated protocol version:
2026-07-28(newer than the hackathon minimum2025-11-25)Web simulator uses an MCP client over the SDK's in-memory transport; it does not bypass the MCP tool layer
Public
/mcpuses Streamable HTTP and exposes the same seven tools
Related MCP server: BugBounty MCP Server
Run
npm install
npm startOpen http://127.0.0.1:4310.
Verify MCP
With the server running:
npm run smokeThe smoke client performs a real initialize handshake, lists tools, calls analyze_opportunity, and prints the negotiated protocol era.
Tools
analyze_opportunitysave_opportunityget_opportunity_queuecompare_opportunitiesbuild_submission_planset_opportunity_statusnext_best_action
State
Local demo state is stored in data/state.json and intentionally ignored by Git. data/state.example.json documents the shape.
On Vercel, the demo writes state under the function's /tmp directory so the app can operate without a separate database. That storage is ephemeral and may reset on a cold start. Durable hosted persistence is intentionally left as a follow-up integration rather than being overstated in the PoC.
Privacy and cost
The current proof of concept uses no paid model API and sends no listing text to a third-party model. State is local to the self-hosted server.
License
MIT.
This server cannot be deployed
Maintenance
Related MCP Connectors
Control plane for autonomous software labor. Agents claim objectives over MCP with audit trail.
MCP Hub: AI service discovery, per-user OAuth, and multi-service workflow orchestration
Enrich, search, assess, and manage threat intelligence through 80+ typed MCP tools.
AI workflow/MCP implementation package planner.
Related MCP Servers
- AlicenseBqualityDmaintenanceAn MCP server for authorized bug bounty work that enforces an evidence-driven workflow with session management, preflight checks, surface discovery, and verified scanning.12MIT
- AlicenseNot gradedqualityCmaintenanceEnables automated bug bounty hunting and security research with tools for reconnaissance, web vulnerability scanning, API testing, binary analysis, and mobile app analysis through an MCP interface.MIT
- AlicenseNot gradedqualityCmaintenanceEnables autonomous bug bounty hunting with H1 auto-submit, profit tracking, and a live dashboard. Coordinates real-time state, credential vault, session management, and payload generation for MCP-compatible AI agents.4 npmISC
- AlicenseCqualityBmaintenanceEnables authorized pentest and bug bounty workflows from any MCP client, with scoped recon, per-host rate limits, and scanner output turned into deduplicated, triaged finding cards.932 PyPI1MIT