Download a HackerOne report attachment to tools/hackerone/downloads/ and get the saved file path. Specify the attachment ID, or review choices when multiple attachments exist.
Retrieve complete details of a HackerOne report by its ID, including vulnerability information, severity, CVSS score, bounty amounts, and program data.
A local, read-only MCP server that connects your HackerOne researcher account to Claude Desktop and Claude Code, helping you find targets, analyze program scopes, review reports and earnings, and draft bug reports.
Enables interacting with HackerOne through the official REST API for managing reports, earnings, and programs, plus browser automation to read disclosed reports, search hacktivity writeups, and view program policies even behind Cloudflare.
Search HackerOne vulnerability reports using filters for keywords, programs, severity, or state to find past reports for reference when drafting new ones.
Check the credential and operational status of HackerOne, YesWeHack, and Intigriti platforms. Identifies configured platforms and missing environment variables.
Check if a domain, IP, CIDR, or URL is in-scope for bug bounty programs. Handles wildcards, IP ranges, and path prefixes across HackerOne, YesWeHack, and Intigriti.