MCP server for the HackerOne Hacker API (Hackers section only). Built from https://api.hackerone.com/hacker-resources/
Strong tool coverage (21 tools) with consistent naming patterns (verb_noun: list_, get_, create_, submit_, search_, delete_, update_). All tools have descriptions (avg ~150 chars, within 10-1024 baseline). Input schemas present for all tools with proper Zod validation and type constraints. Pagination parameters well-designed (min/max bounds). However, output schemas are NOT documented, responses are JSON-stringified but structure is opaque to LLMs. Error handling is minimal (generic try-catch returning error message text). Missing tool annotations (readOnlyHint, destructiveHint). Some parameter descriptions could be more prescriptive about format/constraints.
Create a new report intent / draft (POST /hackers/report_intents). Takes team_handle + a free-text description; HackerOne's assistant structures it into a draft you can later submit_report_intent.
Delete a report intent / draft (DELETE /hackers/report_intents/{id}).
Remove one attachment from a report intent (DELETE /hackers/report_intents/{id}/attachments/{attachment_id}).
Get your current unpaid bounty balance (GET /hackers/payments/balance).
Get your bounty earnings history (GET /hackers/payments/earnings): amount, currency, date, awarding program. Paginated.
Get your payout history (GET /hackers/payments/payouts): amount, paid_out_at, reference, provider, status. Paginated.
Output schemas not documented. Responses are JSON-stringified but LLMs cannot infer field structure, types, or which fields are safe to chain into downstream tools. This violates pattern:tool and pattern:response-shaper.
No tool annotations (readOnlyHint, destructiveHint, idempotentHint). Agents cannot distinguish safe reads from destructive writes without parsing descriptions. delete_report_intent and delete_report_intent_attachment should be marked destructiveHint=true.
Error handling is generic (catch-all try-catch returning error.message). No recovery guidance, error classification, or actionable next steps. Violates pattern:recovery-guide and pattern:error-classification.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | B | 74 | 2026-07-28+ | v2 |
Get one program's details (GET /hackers/programs/{handle}): policy, submission state, response metrics, bounty splitting.
Get a program's in-scope assets / structured scopes (GET /hackers/programs/{handle}/structured_scopes). Auto-paginated. Returns asset_type, asset_identifier, bounty eligibility, max_severity, and the id needed for submit_report.
Get a program's out-of-scope / ineligible categories (GET /hackers/programs/{handle}/scope_exclusions). Auto-paginated.
Get the weakness/CWE types a program accepts (GET /hackers/programs/{handle}/weaknesses). Auto-paginated. Returns the id needed for submit_report and external_id (e.g. 'cwe-79').
Get full details of one of your reports by ID (GET /hackers/reports/{id}): vulnerability info, impact, CVSS vector/score, bounty, attachments, timeline fields, program.
Get a single report intent / draft by ID (GET /hackers/report_intents/{id}).
List the reports you have submitted (GET /hackers/me/reports). Returns id, title, state, severity, bounty, program. Paginated.
List all bug bounty programs you have access to (GET /hackers/programs). Auto-paginated.
List attachments on a report intent (GET /hackers/report_intents/{id}/attachments).
List your report intents / drafts (GET /hackers/report_intents). Returns id, title, description, state, and AI job statuses.
Search publicly disclosed reports (GET /hackers/hacktivity). queryString uses Apache Lucene syntax, e.g. 'weakness_id:79', 'severity_rating:critical', 'cwe:79 AND disclosed:true'. Great for prior-art and what programs pay for.
Submit a NEW vulnerability report directly to a program (POST /hackers/reports). Use get_program_scope and get_program_weaknesses first to get structured_scope_id / weakness_id. Returns the new report id + URL.
Submit a report intent as a formal report (POST /hackers/report_intents/{id}/submit). The draft must be in a ready_to_submit state.
Update a report intent's description (PATCH /hackers/report_intents/{id}).
Upload one or more local files to a report intent (POST /hackers/report_intents/{id}/attachments, multipart files[]).
Parameter descriptions lack format/constraint details. E.g., 'team_handle' should specify format (lowercase alphanumeric, no spaces). 'file_paths' should clarify absolute vs relative, supported formats. Violates pattern:constrained-input.
No confirmation/dry-run for destructive operations (delete_report_intent, delete_report_intent_attachment). Agents can accidentally delete without safeguards. Violates pattern:confirmation-request.