HackerOneSAFE
Unofficial MCP server for accessing your HackerOne reports, programs, scope, and earnings from Claude Code
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Disclaimer: This is an unofficial, community-built project. It is not affiliated with, endorsed by, or maintained by HackerOne. "HackerOne" is a trademark of HackerOne, Inc. This project simply integrates with their publicly documented Hacker API.
MCP server that gives Claude Code (or any MCP client) full access to your HackerOne reports, programs, earnings, and scope data via the HackerOne API — including submitting reports and responding to triage.
Setup
1. Get your HackerOne API token
Go to HackerOne > Settings > API Token and generate one.
2. Install and build
git clone https://github.com/Sicks3c/hackerone-mcp-server.git cd hackerone-mcp-server npm install npm run build
3. Add to Claude Code
claude mcp add hackerone \ -e H1_USERNAME=your-username \ -e H1_API_TOKEN=your-api-token \ -s user \ -- node /path/to/hackerone-mcp-server/dist/index.js
Or add manually to ~/.claude.json:
{
"mcpServers": {
"hackerone": {
"command": "node",
"args": ["/path/to/hackerone-mcp-server/dist/index.js"],
"env": {
"H1_USERNAME": "your-username",
"H1_API_TOKEN": "your-api-token"
}
}
}
}4. Verify
claude > /mcp # You should see "hackerone" listed with 16 tools
Tools
Read
4c7d65bf35c1OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add hackerone-mcp-server --env H1_API_TOKEN=${H1_API_TOKEN} -- npx -y [email protected]{
"mcpServers": {
"hackerone-mcp-server": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"H1_API_TOKEN": "${H1_API_TOKEN}"
}
}
}
}Exposed tools (16)
14 read · 2 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
add_comment | write | Add a comment to an existing HackerOne report. Use this to respond to triage questions or provide additional information. |
analyze_report_patterns | read | Fetch your recent reports and analyze patterns: most common vulnerability types, severity distribution, resolution rates, and programs. Useful for understanding your hunting profile. |
close_report | read | Withdraw/close one of your own HackerOne reports. Sends a close request with an optional message. |
get_balance | read | Get your current unpaid bounty balance on HackerOne. |
get_earnings | read | Get your bounty earnings history. Shows amounts, currency, dates, and which programs paid out. |
get_hacker_profile | read | Get your HackerOne hacker profile: reputation, signal, impact, rank, and account info. |
get_program_details | read | Get detailed info about a single program: policy, response times, metrics, bounty splitting, and submission state. |
get_program_scope | read | Get the in-scope assets for a bug bounty program. Auto-paginates to return all scope items. Returns asset types, identifiers, bounty eligibility, and severity caps. |
get_program_weaknesses | read | Get the accepted vulnerability/weakness types for a program. Auto-paginates. Helps frame reports using the right CWE categories the program cares about. |
get_report | read | Get the full details of a specific HackerOne report by ID. Returns title, vulnerability details, impact, severity, full CVSS vector/score, bounty amounts, attachments, timestamps, and program info. |
get_report_activities | read | Get the activity timeline of a report: comments, state changes, bounty awards, and triage responses. |
get_report_with_conversation | read | Get a report with its full triage conversation. Useful for understanding what questions triage asked, how you responded, and what led to resolution. Great for learning what works. |
list_programs | read | List bug bounty programs you have access to on HackerOne. Auto-paginates to return all programs. |
search_disclosed_reports | read | Search publicly disclosed HackerOne reports (hacktivity). Useful for learning what gets paid, finding prior art, and understanding what a program considers valid. |
search_reports | read | Search and list your HackerOne reports. Filter by keyword, program, severity, or state. Great for finding past reports to reference when drafting new ones. |
submit_report | write | Submit a new vulnerability report to a HackerOne program. Returns the new report ID and URL. Use get_program_scope and get_program_weaknesses first to get the right scope/weakness IDs. |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (2 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (3)
@modelcontextprotocol/sdk, node-fetch, zod, @types/node, tsx, typescript
MCP server that gives Claude Code (or any MCP client) full access to your HackerOne reports, programs, earnings, and scope data via the HackerOne API — including submitting reports and responding to t
Gates applied: no_behavioural_pass, no_license.
4c7d65bf35c1full audit observations/trust-audit/mcp-server/sicks3c__hackerone.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 4c7d65bf35c1 | SAFE | B | 89 | first audit |
Questions
What is the HackerOne MCP server?
Unofficial MCP server for accessing your HackerOne reports, programs, scope, and earnings from Claude Code
What tools does HackerOne expose?
16 in total: 14 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is HackerOne safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does HackerOne need?
It reads H1_API_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does HackerOne run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as hackerone-mcp-server at 1.0.0.
How current is this page?
The grade is for one exact copy of the source (4c7d65bf35c1), read on 2026-10-08. The repository is watched and re-audited when it changes.