Atlas / MCP servers / patrikfehrenbach / H1 Brain

H1 BrainSAFE

mcp/patrikfehrenbach/h1-brain

MCP server that connects AI assistants to HackerOne for bug bounty hunting

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
12 9r · 3w · 0d
Transport
—
License
MIT
Stars
355
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

An MCP server that connects your AI assistant to HackerOne. It pulls your bug bounty history, program scopes, and report details into a local SQLite database, then exposes tools that let any MCP-compatible client (Claude Desktop, Claude Code, etc.) search, analyze, and build on your past work.

It also ships with a pre-built database of 3,600+ publicly disclosed bounty-awarded reports from the HackerOne community — full vulnerability write-ups, weakness types, and bounty amounts. The AI uses both your personal data and public knowledge to generate attack briefings.

The primary tool, hack(handle), generates a full hacking session briefing in a single call: fresh scope from the API, your past findings, public disclosures for that program, weakness patterns, untouched assets, and suggested attack vectors — all formatted as actionable instructions that put the AI in offensive mode.

How It Works

For a full walkthrough, check out the three-part [Bug Bounty Goldfish](https://clawd.it/series/bug-bounty-goldfish/) series:

  1. [Teaching Claude Everything You've Hacked](https://clawd.it/posts/11-teaching-claude-everything-youve-hacked/) — Why I built h1-brain and how to set it up
  2. [What h1-brain Actually Does](https://clawd.it/posts/12-what-h1-brain-actually-does/) — Every tool explained, from search to the hack() briefing
  3. [Running h1-brain Against a Real Target](https://clawd.it/posts/13-running-h1-brain-against-a-real-target/) — A start-to-finish walkthrough on an actual program
graph LR
A["Claude Desktop / Code"] -->|MCP Protocol| B["h1-brain server"]
B -->|API calls| C["HackerOne API"]
B -->|reads / writes| D["Your Reports DB"]
B -->|reads| E["Public Reports DB"]
C -->|reports, programs, scopes| B
D -->|your history + analysis| A
E -->|community knowledge| A
style A fill:#ff5c5c,stroke:#ff5c5c,color:#fff
style B fill:#1a1d27,stroke:#ff5c5c,color:#fff
Read from source at commit f27321353da2OBSERVED · 2026-10-03
02

Exposed tools (12)

9 read · 3 write · 0 destructive.

ToolRiskDescription
fetch_attachmentreadGet fresh download URLs for report attachments (expire in ~1 hour).
fetch_program_scopesreadFetch scopes for a program from the API. Called automatically by hack().
fetch_programswriteSync your accessible HackerOne programs into the local database.
fetch_rewarded_reportswriteSync your personal bounty-awarded reports from HackerOne API into the local database. Run once, re-run to update.
get_disclosed_reportreadGet full details of a public disclosed report. For your own reports use get_report.
get_reportreadGet full details of your personal report. For public reports use get_disclosed_report.
get_report_summaryreadSummary of your rewarded reports grouped by program with totals.
hackwriteStart a hacking session. Fetches fresh scope, cross-references your reports and public disclosures, returns an actionable attack briefing.
search_disclosed_reportsreadSearch public disclosed reports from other researchers that paid a bounty. For your own reports use search_reports.
search_programsreadSearch your stored programs by handle or name.
search_reportsreadSearch your personal rewarded reports. For public community reports use search_disclosed_reports.
search_scopesreadSearch in-scope assets across programs.
03

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (1)

LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements.txt
mcp, httpx
Why it matters. 2 requirement(s) not pinned with ==
Fix. pin exact versions

Gates applied: no_behavioural_pass.

Audited 2026-10-03 · audit v0.4.1 · source sha f27321353da2full audit observations/trust-audit/mcp-server/patrikfehrenbach__h1-brain.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-03f27321353da2SAFEB89first audit
05

Questions

What is the H1 Brain MCP server?

MCP server that connects AI assistants to HackerOne for bug bounty hunting

What tools does H1 Brain expose?

12 in total: 9 read-only, 3 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is H1 Brain safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does H1 Brain need?

It reads H1_API_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How current is this page?

The grade is for one exact copy of the source (f27321353da2), read on 2026-10-03. The repository is watched and re-audited when it changes.

Advertisement