
Bounty Operator
io.github.bountyoperatorv0.9.9Updated Oct 10, 2026
Argues against a security finding or a draft bug bounty report before you submit it.
Overview
Lets an assistant review code or a draft bug bounty report, check cited lines, and build an evidence packet before submission.
- What it does
- Bounty Operator provides six tools for pre-submission security review. list_profiles lists review profiles and their gauntlet order; prepare_review returns a SHA-256 manifest, privacy findings, reviewer instructions and a request your own model answers; build_packet returns a verdict, reference check and Markdown evidence packet; run_gauntlet_plan returns the eight-stage plan; account shows plan and daily allowance; run_review runs a profile on a provider's model. Three prompts cover report challenge, Solidity review and the gauntlet.
- When to use it
- Use it when you want an agent to challenge a security finding or draft bug bounty report before submitting it, or to run a structured multi-stage review of named files. The core profiles and packet building work without an account; hosted profiles and the full gauntlet need a token and provider key.
- Requirements
- Remote endpoint at bountyoperator.com, or a local stdio server via npx needing Node 22 or later. Core tools need nothing. account and run_review need a connection token (BOUNTY_OPERATOR_TOKEN, or Authorization header) and a provider API key (for example OPENROUTER_API_KEY, or X-Provider-Key header). Optional BOUNTY_OPERATOR_MODEL and BOUNTY_OPERATOR_ROOT. Network access for hosted calls.
Installation
In SourceWeft
- Open Bounty Operator in the dashboard and add it to a workspace.
- Enable the server for the chats that should use its tools.
Web executable via Streamable HTTP. Remote servers run from the web runtime once configured in a workspace.
Other MCP clients
Add this to your client's mcpServers config.
{
"mcpServers": {
"bounty-operator": {
"type": "http",
"url": "https://bountyoperator.com/api/mcp"
}
}
}README
Bounty Operator MCP
Find the hole in your report before the triager does, from inside your coding agent.
This is the MCP server for Bounty Operator. Your agent names the files, the server scans them for secrets and returns the review request, your agent's own model writes the review, and the server checks every cited line and builds the evidence packet. Preparing a review and building the packet need no account and no key.
That route covers the three core profiles. Every other profile, and seven of the eight gauntlet stages, runs as a hosted review on the Bounty Operator service with your own provider key.
Install
Two routes. Both work today.
Remote endpoint
Nothing to install. One line per client.
Claude Code
Codex
Cursor, in ~/.cursor/mcp.json or .cursor/mcp.json in a project:
Local server
This package. It reads files by path, keeps review preparation on your machine and adds run_gauntlet_plan. Node 22 or later, no dependencies. npx installs it from the tarball the site serves.
Claude Code
Codex
Cursor, in ~/.cursor/mcp.json or .cursor/mcp.json in a project:
Any other client: command npx, arguments -y https://bountyoperator.com/dl/bounty-operator-mcp.tgz, transport stdio.
On Windows outside WSL, Claude Code starts npx through cmd: end the command with -- cmd /c npx -y https://bountyoperator.com/dl/bounty-operator-mcp.tgz.
The package is coming to npm as bounty-operator-mcp. Until it is published, the tarball URL above is the install.
A first request to try:
Tools
Six tools here, five on the remote endpoint: run_gauntlet_plan is local only.
Limits per call: 50 files, 120 KB per file, 240 KB and 20,000 lines in total.
Core and hosted profiles
prepare_review takes the three core profiles: general (Code security review), solidity (Solidity review) and report (Challenge a draft report). Their method is in this package and your agent's own model answers the request.
Every other profile is hosted: scope, provenance, prior-art, poc, severity, triage, report-edit and scanner. Each runs on the Bounty Operator service through run_review, on your own provider key. The method of a hosted profile is added on the service. It is not in this package and no tool returns it.
For a hosted profile:
list_profilesreturns it withhosted: true.prepare_reviewfails with the codehosted_profilebefore any file is read.run_reviewruns it and uses one hosted review. A review the provider blocks under its usage policy is not counted. The two profiles no list shows,verdictandpanel, are the last step of the gauntlet and of a panel review: they run on Operator only.
Files by path
prepare_review and run_review take paths, files, or both.
pathsare read by the server from its working directory:["report.md", "src/Vault.sol"]. The agent does not have to send the file text.filescarry the text inline:[{ "name": "src/Vault.sol", "content": "..." }].
A path resolves under the working directory and nowhere else. The server refuses .., an absolute path outside the directory, and a link that leaves it. File contents go to the review and are never returned: a result holds the label, size, line count and SHA-256 of each file.
A client that starts the server outside your project sets BOUNTY_OPERATOR_ROOT to the project folder.
The privacy check
Every call scans the files first. A secret blocks the call and the result lists file, line and kind of each match, never the matched text. An email or IP address stops the call until you repeat it with acknowledgeWarnings: true. run_review runs this check on your machine before anything is sent.
Prompts
Three prompts, listed by clients that support them as slash commands:
In Claude Code: /mcp__bounty-operator__gauntlet.
The gauntlet
Eight stages, in the order that ends a weak report early: scope, provenance, prior art, proof, severity, triager, report, verdict. run_gauntlet_plan returns the plan and names the tool that runs each stage. Seven stages are hosted and run through run_review, so the run needs a connection token and a provider key. The report stage is a core profile: prepare_review returns its request and your agent's own model answers it. Each review is passed forward as stage-<n>-<profile>.md, and the run ends with build_packet. The verdict is one of submit, rewrite-then-submit, prove-first, hold-duplicate, drop.
A run uses seven hosted reviews. Free covers one hosted review per UTC day, so a full run takes Operator. The plan carries the count under hosted, and account returns the allowance before the run starts.
Hosted reviews
run_review runs any profile on a provider's model with your own API key and returns the review checked. It is the only way to run a hosted profile from an agent. It uses the same allowance as the website: one hosted review per UTC day on Free, any profile, and unlimited on Operator at US$10 per week.
Three result fields say when the text is not a review. truncated is true when the provider cut the answer short. refused is true when the model or the provider declined. blocked is set when the review was blocked: anthropic-cyber, anthropic-reasoning or openai-cyber for that provider's safeguards, guardrail for a guardrail on the key or its account, policy for any other block under a usage policy. A blocked review is never counted. After a refusal or a block, do not call again with the same model: use another model or provider, or prepare_review for a core profile.
- Sign in at bountyoperator.com and create a connection in the account panel. The token starts with
bok_and is shown once. - Start the server with the token and one provider key in its environment.
Codex, in ~/.codex/config.toml:
A hosted review runs for up to 270 seconds. Codex stops a tool call after 60 by default, so keep the tool_timeout_sec line.
The token and the key are read from the environment. Neither is a tool argument, and both are removed from every result.
The remote endpoint takes the same two values as headers: Authorization: Bearer <token> and X-Provider-Key: <key>. The commands for each client are at bountyoperator.com/mcp.
Environment
What the server reaches
list_profiles,prepare_review,run_gauntlet_planandbuild_packetrun on your machine with no network call.accountandrun_reviewcallhttps://bountyoperator.comwith your token.run_reviewsends the files and your provider key. The service adds the method of the profile, passes the request and the key to the provider for that one request and returns the review. It stores no files, keys or review text.- The server reads the files you name under the working directory. It writes nothing to disk and runs no code from the files.
When a call fails
A failed call returns isError with one JSON object: error, a sentence the agent can act on, and code.
Verify the download
The tarball on the site is listed with its SHA-256 at https://bountyoperator.com/dl/SHA256SUMS.txt.
Start a downloaded tarball with the file: prefix and its absolute path. npm reads a bare path as a command to run.
Develop
The review engine lives in web/public of the repository and is copied into lib/ before every test and pack.
build-mcp.mjs packs the tarball, checks its contents against a whitelist, installs it into an empty folder, completes an MCP handshake and writes web/public/dl/.
Source: github.com/bountyoperator/bounty-operator. MIT licence.
Source: mcp/README.md at commit 88c77b3
Tools
0Version history
1- v0.9.9LatestOct 10, 2026


