An MCP server that provides access to Immunefi bug bounty program information
The Immunefi MCP server has three tools with basic parameter schemas visible, but falls short on definition quality in multiple critical areas. Tool names follow verb_noun convention adequately (search_program, get_program_assets, get_max_bounty). Descriptions exist for all tools and most parameters, but lack depth and actionable guidance. Input schemas are present with type declarations, but parameters often lack detailed constraints. Output schemas are documented in description text rather than formal schema definitions. Error handling exists but is generic, errors are caught and wrapped in JSON without guiding the LLM on recovery. The server lacks output schema formalization, per-parameter constraints, and dependency hints. Critically, the definitions are inferred from code rather than explicitly registered with schemas; tool registration uses @mcp.tool() decorator but underlying parameter schemas are implicit from function signatures, which limits visibility and composability.
Return the maximum bounty amount for specific programs. Returns: JSON string containing an object with: - result: Array of objects, each containing: - project_id: The requested project ID (string) - max_bounty: Maximum bounty amount (number) - error: Error message if project not found (string, optional)
Return assets in scope for specific Immunefi bug bounty programs. Returns: JSON string containing an object with: - result: Array of objects, each containing: - project_id: The requested project ID (string) - assets: Array of asset objects in scope (array) - error: Error message if project not found (string, optional)
Return a list of Immunefi bug bounty programs filtered by search query. The search is performed across project name, id, slug, and tags fields. Results are limited to a maximum of 20 programs. Returns: JSON string containing an object with: - result: Array of objects, each containing: - id: Project ID (string) - total_matching: Total number of matching programs (number) - returned: Number of programs returned (number, max 20)
Output schemas are documented only in natural language descriptions, not as formal JSON Schema definitions. LLMs cannot reliably parse free-text output schemas to plan downstream tool calls or extract specific fields.
Parameter constraints (enums, ranges, patterns) are absent. The 'query' parameter in search_program has no length limits, format constraints, or guidance on valid search terms. The 'project_ids' array in get_program_assets lacks min/max item counts and validation rules visible to the LLM.
Error responses are generic ('error': str(e)). They do not guide the LLM on recovery actions. E.g., when a project is not found, the error should suggest alternatives like 'Project not found. Call search_program() to discover available projects.' Currently, the LLM gets a raw error message with no next step.
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | D | 59 | <=2025-11-25 | v2 |
Tool definitions are inferred from Python function signatures rather than explicitly defined with JSON Schema in the registration. This limits static introspection and composability. The FastMCP framework infers schemas from type hints, but the resulting schemas are not visible in the provided source code.
Parameter descriptions are minimal or absent for several key params. 'project_ids' has a one-line description; no mention of valid formats, length constraints, or whether IDs are alphanumeric-only (which the code validates). The constraint 'alphanumeric' is enforced in code but not documented in the parameter description.
The search_program tool limits results to 20 items, but this limit is not exposed as a parameter; agents cannot request more results or paginate. The description mentions the limit, but no pagination parameters (offset, limit, next_cursor) are offered, preventing agent-driven exploration of the full result set.
No per-item success/failure reporting for batch operations. In get_program_assets, if one project ID is valid and another is not, the tool currently fails entirely rather than returning partial results with per-item error annotations.