H1 BrainSAFE
MCP server that connects AI assistants to HackerOne for bug bounty hunting
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
An MCP server that connects your AI assistant to HackerOne. It pulls your bug bounty history, program scopes, and report details into a local SQLite database, then exposes tools that let any MCP-compatible client (Claude Desktop, Claude Code, etc.) search, analyze, and build on your past work.
It also ships with a pre-built database of 3,600+ publicly disclosed bounty-awarded reports from the HackerOne community — full vulnerability write-ups, weakness types, and bounty amounts. The AI uses both your personal data and public knowledge to generate attack briefings.
The primary tool, hack(handle), generates a full hacking session briefing in a single call: fresh scope from the API, your past findings, public disclosures for that program, weakness patterns, untouched assets, and suggested attack vectors — all formatted as actionable instructions that put the AI in offensive mode.
How It Works
For a full walkthrough, check out the three-part [Bug Bounty Goldfish](https://clawd.it/series/bug-bounty-goldfish/) series:
- [Teaching Claude Everything You've Hacked](https://clawd.it/posts/11-teaching-claude-everything-youve-hacked/) — Why I built h1-brain and how to set it up
- [What h1-brain Actually Does](https://clawd.it/posts/12-what-h1-brain-actually-does/) — Every tool explained, from search to the
hack()briefing - [Running h1-brain Against a Real Target](https://clawd.it/posts/13-running-h1-brain-against-a-real-target/) — A start-to-finish walkthrough on an actual program
graph LR A["Claude Desktop / Code"] -->|MCP Protocol| B["h1-brain server"] B -->|API calls| C["HackerOne API"] B -->|reads / writes| D["Your Reports DB"] B -->|reads| E["Public Reports DB"] C -->|reports, programs, scopes| B D -->|your history + analysis| A E -->|community knowledge| A style A fill:#ff5c5c,stroke:#ff5c5c,color:#fff style B fill:#1a1d27,stroke:#ff5c5c,color:#fff
f27321353da2OBSERVED · 2026-10-03Exposed tools (12)
9 read · 3 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
fetch_attachment | read | Get fresh download URLs for report attachments (expire in ~1 hour). |
fetch_program_scopes | read | Fetch scopes for a program from the API. Called automatically by hack(). |
fetch_programs | write | Sync your accessible HackerOne programs into the local database. |
fetch_rewarded_reports | write | Sync your personal bounty-awarded reports from HackerOne API into the local database. Run once, re-run to update. |
get_disclosed_report | read | Get full details of a public disclosed report. For your own reports use get_report. |
get_report | read | Get full details of your personal report. For public reports use get_disclosed_report. |
get_report_summary | read | Summary of your rewarded reports grouped by program with totals. |
hack | write | Start a hacking session. Fetches fresh scope, cross-references your reports and public disclosures, returns an actionable attack briefing. |
search_disclosed_reports | read | Search public disclosed reports from other researchers that paid a bounty. For your own reports use search_reports. |
search_programs | read | Search your stored programs by handle or name. |
search_reports | read | Search your personal rewarded reports. For public community reports use search_disclosed_reports. |
search_scopes | read | Search in-scope assets across programs. |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (1)
mcp, httpx
Gates applied: no_behavioural_pass.
f27321353da2full audit observations/trust-audit/mcp-server/patrikfehrenbach__h1-brain.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-03 | f27321353da2 | SAFE | B | 89 | first audit |
Questions
What is the H1 Brain MCP server?
MCP server that connects AI assistants to HackerOne for bug bounty hunting
What tools does H1 Brain expose?
12 in total: 9 read-only, 3 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is H1 Brain safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does H1 Brain need?
It reads H1_API_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How current is this page?
The grade is for one exact copy of the source (f27321353da2), read on 2026-10-03. The repository is watched and re-audited when it changes.