Bounty Operator

io.github.bountyoperatorv0.9.9Updated Oct 10, 2026

Argues against a security finding or a draft bug bounty report before you submit it.

VerifiedStreamable HTTPWeb executableDeveloper ToolsSecurity & Monitoring

Overview

AI-generated overview

Lets an assistant review code or a draft bug bounty report, check cited lines, and build an evidence packet before submission.

What it does
Bounty Operator provides six tools for pre-submission security review. list_profiles lists review profiles and their gauntlet order; prepare_review returns a SHA-256 manifest, privacy findings, reviewer instructions and a request your own model answers; build_packet returns a verdict, reference check and Markdown evidence packet; run_gauntlet_plan returns the eight-stage plan; account shows plan and daily allowance; run_review runs a profile on a provider's model. Three prompts cover report challenge, Solidity review and the gauntlet.
When to use it
Use it when you want an agent to challenge a security finding or draft bug bounty report before submitting it, or to run a structured multi-stage review of named files. The core profiles and packet building work without an account; hosted profiles and the full gauntlet need a token and provider key.
Requirements
Remote endpoint at bountyoperator.com, or a local stdio server via npx needing Node 22 or later. Core tools need nothing. account and run_review need a connection token (BOUNTY_OPERATOR_TOKEN, or Authorization header) and a provider API key (for example OPENROUTER_API_KEY, or X-Provider-Key header). Optional BOUNTY_OPERATOR_MODEL and BOUNTY_OPERATOR_ROOT. Network access for hosted calls.
Before you install
run_review sends the named files and your provider key to bountyoperator.com, which passes them to the chosen provider for that request. Files are read from the working directory only; secrets block a call, and emails or IPs require acknowledgeWarnings. Hosted reviews consume a daily allowance (one per UTC day on Free; unlimited on Operator at US$10 per week) and use your provider's own credit. Token and keys are read from the environment, never tool arguments.

Installation

In SourceWeft

  1. Open Bounty Operator in the dashboard and add it to a workspace.
  2. Enable the server for the chats that should use its tools.

Web executable via Streamable HTTP. Remote servers run from the web runtime once configured in a workspace.

Other MCP clients

Add this to your client's mcpServers config.

{
  "mcpServers": {
    "bounty-operator": {
      "type": "http",
      "url": "https://bountyoperator.com/api/mcp"
    }
  }
}

README

Bounty Operator MCP

Find the hole in your report before the triager does, from inside your coding agent.

This is the MCP server for Bounty Operator. Your agent names the files, the server scans them for secrets and returns the review request, your agent's own model writes the review, and the server checks every cited line and builds the evidence packet. Preparing a review and building the packet need no account and no key.

That route covers the three core profiles. Every other profile, and seven of the eight gauntlet stages, runs as a hosted review on the Bounty Operator service with your own provider key.

Install

Two routes. Both work today.

Remote endpoint

Nothing to install. One line per client.

Claude Code

bash
claude mcp add --transport http bounty-operator https://bountyoperator.com/api/mcp

Codex

bash
codex mcp add bounty-operator --url https://bountyoperator.com/api/mcp

Cursor, in ~/.cursor/mcp.json or .cursor/mcp.json in a project:

json
{ "mcpServers": { "bounty-operator": { "url": "https://bountyoperator.com/api/mcp" } } }

Local server

This package. It reads files by path, keeps review preparation on your machine and adds run_gauntlet_plan. Node 22 or later, no dependencies. npx installs it from the tarball the site serves.

Claude Code

bash
claude mcp add --transport stdio bounty-operator -- npx -y https://bountyoperator.com/dl/bounty-operator-mcp.tgz

Codex

bash
codex mcp add bounty-operator -- npx -y https://bountyoperator.com/dl/bounty-operator-mcp.tgz

Cursor, in ~/.cursor/mcp.json or .cursor/mcp.json in a project:

json
{ "mcpServers": { "bounty-operator": { "command": "npx", "args": ["-y", "https://bountyoperator.com/dl/bounty-operator-mcp.tgz"] } } }

Any other client: command npx, arguments -y https://bountyoperator.com/dl/bounty-operator-mcp.tgz, transport stdio.

On Windows outside WSL, Claude Code starts npx through cmd: end the command with -- cmd /c npx -y https://bountyoperator.com/dl/bounty-operator-mcp.tgz.

The package is coming to npm as bounty-operator-mcp. Until it is published, the tarball URL above is the install.

A first request to try:

text
Use bounty-operator to prepare a Solidity review of src/Vault.sol. Answer the request it returns, then build the packet.

Tools

ToolCall itIt returnsNeeds
list_profilesWhen you do not know which review fitsThe review profiles, each with hosted true or false, the gauntlet order, the verdicts, the providers and modelsNothing
prepare_reviewBefore reviewing code or a draft report with your own modelFor a core profile: SHA-256 manifest, privacy findings, reviewer instructions, output format, the request to answerNothing
run_gauntlet_planFor the full pre-submission runThe eight stages in order with the tool that runs each, the Context fields still empty, the call that ends the runNothing
build_packetAfter writing the reviewVerdict, reference check, the Markdown evidence packetNothing
accountBefore a hosted reviewPlan, reviews used today, reset timeToken
run_reviewTo run a review on a provider's modelThe review, its verdict, the reference check, the remaining allowanceToken and provider key

Six tools here, five on the remote endpoint: run_gauntlet_plan is local only.

Limits per call: 50 files, 120 KB per file, 240 KB and 20,000 lines in total.

Core and hosted profiles

prepare_review takes the three core profiles: general (Code security review), solidity (Solidity review) and report (Challenge a draft report). Their method is in this package and your agent's own model answers the request.

Every other profile is hosted: scope, provenance, prior-art, poc, severity, triage, report-edit and scanner. Each runs on the Bounty Operator service through run_review, on your own provider key. The method of a hosted profile is added on the service. It is not in this package and no tool returns it.

For a hosted profile:

  • list_profiles returns it with hosted: true.
  • prepare_review fails with the code hosted_profile before any file is read.
  • run_review runs it and uses one hosted review. A review the provider blocks under its usage policy is not counted. The two profiles no list shows, verdict and panel, are the last step of the gauntlet and of a panel review: they run on Operator only.
json
{  "profile": "triage",  "error": "Triager simulation runs on the server. Call run_review with profile \"triage\": it needs BOUNTY_OPERATOR_TOKEN and the provider key in this server's environment.",  "code": "hosted_profile"}

Files by path

prepare_review and run_review take paths, files, or both.

  • paths are read by the server from its working directory: ["report.md", "src/Vault.sol"]. The agent does not have to send the file text.
  • files carry the text inline: [{ "name": "src/Vault.sol", "content": "..." }].

A path resolves under the working directory and nowhere else. The server refuses .., an absolute path outside the directory, and a link that leaves it. File contents go to the review and are never returned: a result holds the label, size, line count and SHA-256 of each file.

A client that starts the server outside your project sets BOUNTY_OPERATOR_ROOT to the project folder.

The privacy check

Every call scans the files first. A secret blocks the call and the result lists file, line and kind of each match, never the matched text. An email or IP address stops the call until you repeat it with acknowledgeWarnings: true. run_review runs this check on your machine before anything is sent.

Prompts

Three prompts, listed by clients that support them as slash commands:

PromptWhat it does
challenge-reportChecks every claim in a draft report against the code it cites, then builds the packet
solidity-reviewMaps entry points and invariants in the contracts you name
gauntletTakes a finding through the eight stages in order and ends with one verdict

In Claude Code: /mcp__bounty-operator__gauntlet.

The gauntlet

Eight stages, in the order that ends a weak report early: scope, provenance, prior art, proof, severity, triager, report, verdict. run_gauntlet_plan returns the plan and names the tool that runs each stage. Seven stages are hosted and run through run_review, so the run needs a connection token and a provider key. The report stage is a core profile: prepare_review returns its request and your agent's own model answers it. Each review is passed forward as stage-<n>-<profile>.md, and the run ends with build_packet. The verdict is one of submit, rewrite-then-submit, prove-first, hold-duplicate, drop.

A run uses seven hosted reviews. Free covers one hosted review per UTC day, so a full run takes Operator. The plan carries the count under hosted, and account returns the allowance before the run starts.

Hosted reviews

run_review runs any profile on a provider's model with your own API key and returns the review checked. It is the only way to run a hosted profile from an agent. It uses the same allowance as the website: one hosted review per UTC day on Free, any profile, and unlimited on Operator at US$10 per week.

Three result fields say when the text is not a review. truncated is true when the provider cut the answer short. refused is true when the model or the provider declined. blocked is set when the review was blocked: anthropic-cyber, anthropic-reasoning or openai-cyber for that provider's safeguards, guardrail for a guardrail on the key or its account, policy for any other block under a usage policy. A blocked review is never counted. After a refusal or a block, do not call again with the same model: use another model or provider, or prepare_review for a core profile.

  1. Sign in at bountyoperator.com and create a connection in the account panel. The token starts with bok_ and is shown once.
  2. Start the server with the token and one provider key in its environment.
bash
claude mcp add --transport stdio --env BOUNTY_OPERATOR_TOKEN=bok_... --env OPENROUTER_API_KEY=sk-or-... bounty-operator -- npx -y https://bountyoperator.com/dl/bounty-operator-mcp.tgz

Codex, in ~/.codex/config.toml:

toml
[mcp_servers.bounty-operator]command = "npx"args = ["-y", "https://bountyoperator.com/dl/bounty-operator-mcp.tgz"]env_vars = ["BOUNTY_OPERATOR_TOKEN", "OPENROUTER_API_KEY"]tool_timeout_sec = 1200

A hosted review runs for up to 270 seconds. Codex stops a tool call after 60 by default, so keep the tool_timeout_sec line.

The token and the key are read from the environment. Neither is a tool argument, and both are removed from every result.

The remote endpoint takes the same two values as headers: Authorization: Bearer <token> and X-Provider-Key: <key>. The commands for each client are at bountyoperator.com/mcp.

Environment

VariablePurpose
BOUNTY_OPERATOR_TOKENConnection token for account and run_review
BOUNTY_OPERATOR_MODELModel id run_review uses when the call names none
BOUNTY_OPERATOR_ROOTAbsolute path of the project folder that paths resolve under. Default: the working directory
OPENROUTER_API_KEY, ANTHROPIC_API_KEY, OPENAI_API_KEY, GEMINI_API_KEY, XAI_API_KEY, DEEPSEEK_API_KEY, MISTRAL_API_KEY, GROQ_API_KEYProvider key for run_review, one per provider

What the server reaches

  • list_profiles, prepare_review, run_gauntlet_plan and build_packet run on your machine with no network call.
  • account and run_review call https://bountyoperator.com with your token. run_review sends the files and your provider key. The service adds the method of the profile, passes the request and the key to the provider for that one request and returns the review. It stores no files, keys or review text.
  • The server reads the files you name under the working directory. It writes nothing to disk and runs no code from the files.

When a call fails

A failed call returns isError with one JSON object: error, a sentence the agent can act on, and code.

CodeMeaning
hosted_profileprepare_review was called with a hosted profile. Nothing was read or counted. Call run_review.
privacy_blockThe privacy check found a secret. The result lists file, line and kind.
privacy_warnThe privacy check found an email or IP address. Repeat the call with acknowledgeWarnings: true to send the files as they are.
tokenBOUNTY_OPERATOR_TOKEN is missing, malformed, expired or revoked.
daily_usedThe free review of the day is used. The result carries resetsAt.
operator_onlyrun_review was called with verdict or panel on an account without Operator. Nothing was sent to the provider and the review of the day is not used.
review_runningThe account is running as many reviews as its plan allows.
providerThe provider rejected the key or the model, had no credit, failed or timed out. The review is not counted.
provider_policyThe provider blocked the request under its usage policy. The key is not the cause and the review is not counted. Call again with another model or provider, not the same one.
output_withheldThe model repeated its instructions instead of reviewing, so the answer was stopped and the call used one review. Run it again or choose a stronger model.
bad_path, bad_rootA path cannot be read under the working directory, or the working directory itself cannot be used.
network, timeout, cancelledThe service was not reached, did not answer within 300 seconds, or the client cancelled the call.

Verify the download

The tarball on the site is listed with its SHA-256 at https://bountyoperator.com/dl/SHA256SUMS.txt.

bash
curl -sO https://bountyoperator.com/dl/bounty-operator-mcp-0.9.9.tgzcurl -s https://bountyoperator.com/dl/SHA256SUMS.txt | sha256sum -c --ignore-missingnpx -y file:$PWD/bounty-operator-mcp-0.9.9.tgz --version

Start a downloaded tarball with the file: prefix and its absolute path. npm reads a bare path as a command to run.

Develop

The review engine lives in web/public of the repository and is copied into lib/ before every test and pack.

bash
npm installnpm testnode ../scripts/build-mcp.mjs

build-mcp.mjs packs the tarball, checks its contents against a whitelist, installs it into an empty folder, completes an MCP handshake and writes web/public/dl/.

Source: github.com/bountyoperator/bounty-operator. MIT licence.

Source: mcp/README.md at commit 88c77b3

Tools

0
Tool metadata has not been indexed yet.

Version history

1
  1. v0.9.9LatestOct 10, 2026