Mmcp.market

Bug Bounty Finder - HackerOne + Bugcrowd + security.txt MCP server

by AnshumanAtrey·io.github.AnshumanAtrey/bug-bounty-finder·v1.0.2

Bug Bounty Finder - HackerOne + Bugcrowd + security.txt

A97/100grade A
What users say
No reviews yet
Be the first
Safety scan
A97/100

full report

Adoption
Growing

0 stars

Reviews

Write one

Nobody has reviewed Bug Bounty Finder - HackerOne + Bugcrowd + security.txt yet.

If you have run it, two minutes of your experience saves the next person an afternoon.

Bug Bounty Finder - HackerOne + Bugcrowd + security.txt tools

Tool list not cached yet. `describe` through the gateway fetches it live.

Public scan report

scanner v0.1.9 · 2026-09-24 · same rubric, same numbers if you re-run it

no findings
  • –Code scanremote-only server, no package to scann/a
  • Live reliabilityremote reachable in 8ms (auth required)20/20
  • –Tool poisoningtools not inspected (endpoint requires auth); not countedn/a
  • Auth qualityOAuth resource metadata advertised on 40115/15
  • Maintenancelast push 0 days ago15/15
  • Maintainer identityregistry namespace matches repository owner; GitHub account older than a year8/10
Overall 97/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON

What the publisher says

From the Bug Bounty Finder - HackerOne + Bugcrowd + security.txt repository's README, as published. We do not edit it. Read it on GitHub

Bug Bounty Finder - HackerOne + Bugcrowd + security.txt

Find every public bug bounty or responsible-disclosure program covering a domain - aggregates HackerOne directory, Bugcrowd engagements, and security.txt in one call.

Available as an Apify Actor. Pay-per-event. No subscription. Daily-use tool for bug bounty hunters scoping new targets.

What does it do?

Takes a target domain and returns every public bug bounty program covering it. Aggregates the HackerOne public directory, Bugcrowd engagements page, and the target's own /.well-known/security.txt file (RFC 9116). Returns structured per-program records with platform, program URL, reward range (min/max bounty), report count where available, scope summary, and disclosure policy URL.

How is it different from manual checks across each platform plus visiting security.txt?

Daily-use tool for bug bounty hunters scoping new targets - the first call when evaluating a new acquisition target.

When should I use it?

  • Bug bounty target evaluation - 'is there a program for this domain?'
  • Responsible disclosure - find the right contact for reporting a vulnerability
  • Scope mapping - identify which subdomains are in scope for a known program
  • Competitive intel - track which companies offer bug bounties (not all do)
  • Compliance research - find vulnerability disclosure policies

What does it cost?

Pay-per-event:

Typical scan costs

  • Single domain (~3 programs): $0.015
  • Bulk 50 domains (~2 programs each): $0.50

Which inputs does it take?

What does the output look like?

Each dataset record:

{
  "domain": "example.com",
  "source": "hackerone",
  "program_name": "Example Inc",
  "program_url": "https://hackerone.com/example",
  "reward_min": 100,
  "reward_max": 20000,
  "reports_resolved": 142,
  "scope_summary": "Web, API, mobile apps",
  "disclosure_policy_url": "https://hackerone.com/example/policy"
}

Common questions

Q: Does this find private programs? No. Only public programs. Private programs are invitation-only and not enumerable without platform credentials.

Q: Want a daily diff feed of new programs? Planned feature. DM LinkedIn to request priority delivery.

Q: Other platforms (Intigriti, YesWeHack, Synack)? Currently HackerOne + Bugcrowd + security.txt. Other platforms shipped on request within 1-2 hours via LinkedIn DM.

About the maintainer (priority response within 1-2 hours)

Built and maintained by Anshuman Atrey (@AnshumanAtrey).

  • Purple-team security researcher, 5x hackathon winner
  • Co-founder of Project AISHA (AI cybersec SaaS) and The Drone Syndicate (autonomous defence drones)
  • Author of the canonical OSINT actor portfolio on Apify Store: 12+ shipped actors covering email, phone, username, IP/domain, network, secret, social, LinkedIn, and Indian fintech OSINT

Custom feature requests shipped within 1-2 hours (priority)

Shortened. The full README is on GitHub.

Nothing above is checked by us. What we check is on the safety report.

Install directly

claude mcp add --transport http bug-bounty-finder https://mcp.apify.com/?tools=anshumanatrey/bug-bounty-finder
Add to Cursor

Bug Bounty Finder - HackerOne + Bugcrowd + security.txt: common questions

Is Bug Bounty Finder - HackerOne + Bugcrowd + security.txt MCP server safe?
Yes, by our scan: it is graded A (97/100). Read the Bug Bounty Finder - HackerOne + Bugcrowd + security.txt safety report
How do I install Bug Bounty Finder - HackerOne + Bugcrowd + security.txt?
It runs remotely at mcp.apify.com. Add it to Claude Code, Claude Desktop or Cursor with the snippets above, or call it through the mcp.market gateway without installing anything.
Does Bug Bounty Finder - HackerOne + Bugcrowd + security.txt need an API key?
No key to paste: it signs you in with OAuth when your client connects.
Is Bug Bounty Finder - HackerOne + Bugcrowd + security.txt maintained?
The last commit was in the last day (2026-09-24). The latest release is v1.0.2.
Is Bug Bounty Finder - HackerOne + Bugcrowd + security.txt up?
100% of our last 2 checks got an answer. We check remote servers about four times a day.
What can I use instead of Bug Bounty Finder - HackerOne + Bugcrowd + security.txt?
Servers from other publishers that do the same job: Security Txt Cra Lint MCP server, CrowdStrike Falcon MCP Server and SSH Manager MCP server. Compare all Bug Bounty Finder - HackerOne + Bugcrowd + security.txt alternatives.

Alternatives to Bug Bounty Finder - HackerOne + Bugcrowd + security.txt

Same job from other publishers: the closest match first, then the best rated.

All Bug Bounty Finder - HackerOne + Bugcrowd + security.txt alternatives →
  • Security Txt Cra Lint
    13 rules that decide whether a vulnerability report ever reaches you
    A
  • CrowdStrike Falcon MCP Server
    Connects AI agents with CrowdStrike Falcon for security analysis and automation.
    A
  • SSH Manager
    SSH server management for agents, with per-server read-only and allowlist security modes
    B
  • Reversecore MCP
    Security-first MCP server for reverse engineering, malware analysis, forensics, and SAST.
    B
  • Notebooklm Secure
    Security-hardened NotebookLM MCP with post-quantum encryption
    A

More from AnshumanAtrey →