Atlas / MCP servers / sicks3c / HackerOne

HackerOneSAFE

mcp/sicks3c/hackerone

Unofficial MCP server for accessing your HackerOne reports, programs, scope, and earnings from Claude Code

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
16 14r · 2w · 0d
Transport
stdio
License
—
Stars
40
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Disclaimer: This is an unofficial, community-built project. It is not affiliated with, endorsed by, or maintained by HackerOne. "HackerOne" is a trademark of HackerOne, Inc. This project simply integrates with their publicly documented Hacker API.

MCP server that gives Claude Code (or any MCP client) full access to your HackerOne reports, programs, earnings, and scope data via the HackerOne API — including submitting reports and responding to triage.

Setup

1. Get your HackerOne API token

Go to HackerOne > Settings > API Token and generate one.

2. Install and build

git clone https://github.com/Sicks3c/hackerone-mcp-server.git
cd hackerone-mcp-server
npm install
npm run build

3. Add to Claude Code

claude mcp add hackerone \
-e H1_USERNAME=your-username \
-e H1_API_TOKEN=your-api-token \
-s user \
-- node /path/to/hackerone-mcp-server/dist/index.js

Or add manually to ~/.claude.json:

{
"mcpServers": {
"hackerone": {
"command": "node",
"args": ["/path/to/hackerone-mcp-server/dist/index.js"],
"env": {
"H1_USERNAME": "your-username",
"H1_API_TOKEN": "your-api-token"
}
}
}
}

4. Verify

claude
> /mcp
# You should see "hackerone" listed with 16 tools

Tools

Read

Read from source at commit 4c7d65bf35c1OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add hackerone-mcp-server --env H1_API_TOKEN=${H1_API_TOKEN} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "hackerone-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "H1_API_TOKEN": "${H1_API_TOKEN}"
      }
    }
  }
}
03

Exposed tools (16)

14 read · 2 write · 0 destructive.

ToolRiskDescription
add_commentwriteAdd a comment to an existing HackerOne report. Use this to respond to triage questions or provide additional information.
analyze_report_patternsreadFetch your recent reports and analyze patterns: most common vulnerability types, severity distribution, resolution rates, and programs. Useful for understanding your hunting profile.
close_reportreadWithdraw/close one of your own HackerOne reports. Sends a close request with an optional message.
get_balancereadGet your current unpaid bounty balance on HackerOne.
get_earningsreadGet your bounty earnings history. Shows amounts, currency, dates, and which programs paid out.
get_hacker_profilereadGet your HackerOne hacker profile: reputation, signal, impact, rank, and account info.
get_program_detailsreadGet detailed info about a single program: policy, response times, metrics, bounty splitting, and submission state.
get_program_scopereadGet the in-scope assets for a bug bounty program. Auto-paginates to return all scope items. Returns asset types, identifiers, bounty eligibility, and severity caps.
get_program_weaknessesreadGet the accepted vulnerability/weakness types for a program. Auto-paginates. Helps frame reports using the right CWE categories the program cares about.
get_reportreadGet the full details of a specific HackerOne report by ID. Returns title, vulnerability details, impact, severity, full CVSS vector/score, bounty amounts, attachments, timestamps, and program info.
get_report_activitiesreadGet the activity timeline of a report: comments, state changes, bounty awards, and triage responses.
get_report_with_conversationreadGet a report with its full triage conversation. Useful for understanding what questions triage asked, how you responded, and what led to resolution. Great for learning what works.
list_programsreadList bug bounty programs you have access to on HackerOne. Auto-paginates to return all programs.
search_disclosed_reportsreadSearch publicly disclosed HackerOne reports (hacktivity). Useful for learning what gets paid, finding prior art, and understanding what a program considers valid.
search_reportsreadSearch and list your HackerOne reports. Filter by keyword, program, severity, or state. Great for finding past reports to reference when drafting new ones.
submit_reportwriteSubmit a new vulnerability report to a HackerOne program. Returns the new report ID and URL. Use get_program_scope and get_program_weaknesses first to get the right scope/weakness IDs.
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (2 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (3)

LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, node-fetch, zod, @types/node, tsx, typescript
Why it matters. 6 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
README.md:5
MCP server that gives Claude Code (or any MCP client) full access to your HackerOne reports, programs, earnings, and scope data via the HackerOne API — including submitting reports and responding to t

Gates applied: no_behavioural_pass, no_license.

Audited 2026-10-08 · audit v0.4.1 · source sha 4c7d65bf35c1full audit observations/trust-audit/mcp-server/sicks3c__hackerone.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-084c7d65bf35c1SAFEB89first audit
06

Questions

What is the HackerOne MCP server?

Unofficial MCP server for accessing your HackerOne reports, programs, scope, and earnings from Claude Code

What tools does HackerOne expose?

16 in total: 14 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is HackerOne safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does HackerOne need?

It reads H1_API_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does HackerOne run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as hackerone-mcp-server at 1.0.0.

How current is this page?

The grade is for one exact copy of the source (4c7d65bf35c1), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement