hackerone-mcp
An MCP (Model Context Protocol) server that connects Claude, Claude codex and other mcp clients to the HackerOne Hackers API.
Install / Use
claude mcp add alpernae -- npx -y github:alpernae/hackerone-mcpIf the server publishes to npm under a different name, use that package instead — check the repo README.
MCP Server
Model Context Protocol server
Quality Score
Category
Development & EngineeringSupported Platforms
Our assessment of hackerone-mcp
hackerone-mcp scores 74/100 on our quality scale, 3515th of 4,675 Development & Engineering skills we index.
Its MCP Server is 4.0 KB long, well organised into 13 sections with 9 code examples: a solid amount of guidance for an agent.
It has 3 GitHub stars, so there is little community track record yet; judge it on its content.
Maintenance, license and trust
- The repository was last updated about 3 months ago. That is recent enough to be usable, but agent tooling moves fast, so check the instructions against your agent's current version.
- Our last check on 2026-09-18 found the source still online.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 90/100, with 1 caution from licensing, adoption, age or documentation. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
Safety scan
No issues foundOur scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. An AI review of the same text found nothing harmful.
AI review by kimi-k2.7-code on 2026-09-24. Automated pattern scan on 2026-09-24. It catches known dangerous patterns, not every risk — read a skill before letting an agent act on it.
hackerone-mcp compared with similar skills
All 4 of these similar skills score higher than hackerone-mcp; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| hackerone-mcp (this skill)by alpernae | 74 | 3 | 3mo ago | MCP Server |
| Agent-Reachby Panniantong | 100 | 87.6k | 16d ago | CLAUDE.md |
| headroomby headroomlabs-ai | 100 | 74.3k | today | CLAUDE.md |
| rufloby ruvnet | 100 | 73.7k | today | CLAUDE.md |
| CowAgentby zhayujie | 100 | 47.2k | today | CLAUDE.md |
Frequently asked questions
- How do I install hackerone-mcp?
- Run
claude mcp add alpernae -- npx -y github:alpernae/hackerone-mcp. The install tabs above show the steps for each supported agent. - Which AI agents does hackerone-mcp work with?
- It is written for Claude Code, Claude Desktop and OpenAI Codex, as a MCP Server file. Other agents that read the same format can often use it too.
- Is hackerone-mcp safe to use?
- Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. An AI review of the same text found nothing harmful. It is MIT-licensed and scores 90/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is hackerone-mcp still maintained?
- The repository was last updated about 3 months ago. That is recent enough to be usable, but agent tooling moves fast, so check the instructions against your agent's current version.
Skill content
View source on GitHubHackerOne MCP Server
An MCP (Model Context Protocol) server that connects Claude, Codex, and other MCP clients to the HackerOne Hackers API.
Tools Available
21 tools cover the complete documented Hacker API surface:
- Hacktivity search
- Reports: list, get, and create
- Payments: balance, earnings, and payouts
- Programs: list, get, structured scopes, scope exclusions, and weaknesses
- Report intents: list, get, create, update, delete, submit, and attachment management
Setup
1. Install dependencies
cd hackerone-mcp
npm install
2. Get your HackerOne API credentials
- Go to https://hackerone.com/settings/api_token/edit
- Create a new API token
- Note your username and the generated token
Configuration
Claude Desktop
Edit your Claude Desktop config file:
- macOS:
~/Library/Application Support/Claude/claude_desktop_config.json - Windows:
%APPDATA%\Claude\claude_desktop_config.json
{
"mcpServers": {
"hackerone": {
"command": "node",
"args": ["/absolute/path/to/hackerone-mcp/index.js"],
"env": {
"HACKERONE_API_USERNAME": "your_api_token_identifier",
"HACKERONE_API_TOKEN": "your_api_token"
}
}
}
}
Restart Claude Desktop after saving.
Claude Code (CLI)
Run once to add the MCP server to your Claude Code config:
claude mcp add hackerone \
-e HACKERONE_API_USERNAME=your_api_token_identifier \
-e HACKERONE_API_TOKEN=your_api_token \
-- node /absolute/path/to/hackerone-mcp/index.js
Or set credentials as shell environment variables first:
export HACKERONE_API_USERNAME=your_api_token_identifier
export HACKERONE_API_TOKEN=your_api_token
claude mcp add hackerone -- node /absolute/path/to/hackerone-mcp/index.js
Verify it's registered:
claude mcp list
Codex CLI
Run once to add the MCP server to Codex:
codex mcp add hackerone \
--env HACKERONE_API_USERNAME=your_api_token_identifier \
--env HACKERONE_API_TOKEN=your_api_token \
-- node /absolute/path/to/hackerone-mcp/index.js
Or configure it directly in config.toml:
- macOS/Linux:
~/.codex/config.toml - Windows:
%USERPROFILE%\.codex\config.toml
[mcp_servers.hackerone]
command = "node"
args = ["/absolute/path/to/hackerone-mcp/index.js"]
[mcp_servers.hackerone.env]
HACKERONE_API_USERNAME = "your_api_token_identifier"
HACKERONE_API_TOKEN = "your_api_token"
Verify it's registered:
codex mcp list
In Codex TUI, run /mcp to view active MCP servers.
Other MCP Clients (generic stdio)
Pass the environment variables when launching:
HACKERONE_API_USERNAME=your_api_token_identifier \
HACKERONE_API_TOKEN=your_api_token \
node /path/to/hackerone-mcp/index.js
Or configure your client's MCP settings with:
- command:
node - args:
["/path/to/hackerone-mcp/index.js"] - env:
{ "HACKERONE_API_USERNAME": "...", "HACKERONE_API_TOKEN": "..." }
Example prompts
Once connected, you can ask your MCP client (Claude, Codex, etc.) things like:
- "List my HackerOne reports"
- "Search Hacktivity for disclosed critical reports"
- "Get the full details of report 12345"
- "What's in scope for the nodejs program?"
- "Show me the policy and bounty info for the security program"
- "List all programs I have access to"
Security Notes
- Never hardcode your API token in the source files
- Always use environment variables or your client's secrets manager
- Your API token provides full access to your HackerOne account — treat it like a password
Reliability settings (optional)
If you see intermittent failures (timeouts, 429 rate limits, transient 5xx), you can tune these environment variables:
HACKERONE_TIMEOUT_MS(default:20000) — per-request timeoutHACKERONE_MAX_RETRIES(default:2) — retries for 429/5xx and transient network errorsHACKERONE_API_BASE(default:https://api.hackerone.com/v1) — API base URL
Related Skills
Agent-Reach
87.6kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu — one CLI, zero API fees.
headroom
74.3kCompress tool outputs, logs, files, and RAG chunks before they reach the LLM. 20% fewer tokens for coding agents, 60-95% fewer tokens for JSON, same answers. Library, proxy, MCP server.
ruflo
73.7k🌊 The original agent harness. Deploy intelligent multi-player swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory, self-learning intelligence, federation, vector RAG integration, and native Claude Code / Codex / Hermes and many more Integrated
CowAgent
47.2kOpen-source personal AI assistant & Agent Harness. Plans tasks, runs tools and skills, self-evolves with memory and knowledge. Multi-agent, multi-model, multi-channel. Lightweight, extensible, one-line install.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
