
Bug Bounty Programs
io.github.pipeworx-iov0.1.0更新于 Oct 9, 2026
bug-bounty-programs
概览
让助手检索 Bugcrowd、YesWeHack 和 HackerOne 的公开漏洞赏金项目目录,获取名称、赏金、上线日期和范围资产。
- 功能
- 基于公开的漏洞赏金项目目录数据提供三个只读工具。bounty_programs_search 可按名称、最低赏金(美元)、上线日期以及范围是否包含通配符资产,在一个或全部三个平台上检索。bounty_program 按平台和 handle 返回单个项目,包含范围资产,YesWeHack 还返回按资产价值分级的严重性奖励表。bounty_new_programs 列出最近 N 天内上线的项目,仅限 HackerOne。不包含漏洞内容或研究者资料。
- 适用场景
- 适合让助手查询有哪些漏洞赏金项目、赏金多少、何时上线、哪些资产在范围内,而无需手动浏览各平台目录。覆盖并不均衡:Bugcrowd 的范围数据需要登录,HackerOne 不提供具体赏金金额,YesWeHack 没有上线日期。
- 运行要求
- 使用提供方网关上的远程 streamable HTTP 端点;最初几次调用无需账号、令牌或 API 密钥。也提供本地 stdio 版本,为 npm 包,通过 npx 运行,需要 Node.js。需要能访问该网关以及三个上游平台端点。
安装
在 SourceWeft 中
- 打开 控制台中的 Bug Bounty Programs,将其添加到工作区。
- 为需要使用其工具的对话启用该服务。
Web executable,通过 Streamable HTTP。 远程服务在工作区中配置后即可从网页运行时运行。
其他 MCP 客户端
把它添加到你客户端的 mcpServers 配置中。
{
"mcpServers": {
"bug-bounty-programs": {
"type": "http",
"url": "https://gateway.pipeworx.io/bug-bounty-programs/mcp"
}
}
}README
@pipeworx/bug-bounty-programs
Public bug-bounty PROGRAM DIRECTORY data — program name, bounty range, status and scope assets — from Bugcrowd, YesWeHack and HackerOne's own public directories. No vulnerability content, no researcher profiles or handles.
Part of Pipeworx — an MCP gateway connecting AI agents to 1743+ live data sources. This is an independent, unofficial integration — not affiliated with, endorsed by, or published by the upstream provider.
Tools
bounty_programs_search(platform?, query?, min_bounty?, launched_since?, has_wildcard?, limit?)— search across one or all three platforms by name, minimum bounty (USD), launch date (HackerOne only — see below), and whether scope includes a wildcard asset like*.example.com(checked live on yeswehack/hackerone; bugcrowd returns acount: 0with an explanatorynoteinstead of an error, because its scope is login-walled, not broken).bounty_program(platform, handle)— one program by platform + handle. YesWeHack returns a full severity x asset-value reward table and real scope; HackerOne returns real scope but no numeric reward table (not exposed anywhere on the public schema); Bugcrowd returns neither and says why.bounty_new_programs(days)— programs launched in the last N days, by real launch date. HackerOne only; see "What's not here" below for why Bugcrowd/YesWeHack can't contribute to this one honestly.
Auth
Keyless. Every endpoint below answers with no account, token, or API key.
Data sources
https://bugcrowd.com/engagements.json— paged (?page=N, 24/page,paginationMeta.totalCount) public program list: name, URL, reward summary, industry, access status. No scope/target data — Bugcrowd's scope "reveal" action redirects to/h/engagements/{handle}/reveal.json, its researcher-sign-in area. That is a genuine login wall, not a bug, andbounty_program/has_wildcardsay so rather than returning a silent empty result.https://api.yeswehack.com/programs(list,?page=N) andhttps://api.yeswehack.com/programs/{slug}(detail) — the richest of the three. Detail returnsscopes[](real asset identifiers, some with wildcards),out_of_scope, andreward_grid_default/low/medium/high/critical/very_low— a real severity x asset-value-tier reward table (only the tiers the program actually uses have non-null values; everything else isnull, not zero). No launch-date field anywhere on this endpoint — onlylast_update_at(last change, never surfaced aslaunched_athere to avoid implying a launch).https://hackerone.com/graphql(POST, unauthenticated) —query { teams }/query { team(handle) }. Introspection is disabled, so every field name below was found by probing a guess and reading GraphQL's own "did you meanX?" error back, not from a published schema doc:teams(first/last, after/before):handle name offers_bounties submission_state launched_at—launched_atis a REAL, verified launch date (confirmed againsthackerone.com/security→2013-11-06, the platform's own founding program).last: Nreturns the N most-recently-created teams, which is whatbounty_new_programswalks backward from; there is no workingorder_byvalue we could find (order_by: {field: ..., direction: DESC}is accepted syntactically but every field name we tried forfieldwas rejected), so sorting relies on sequential internal IDs rather than an explicit date sort.team(handle).structured_scopes_search(first): a union (DocumentUnion) — use... on StructuredScopeDocument { identifier asset_type eligible_for_bounty eligible_for_submission instruction }.identifieris the actual scope asset (domain/URL), sometimes a wildcard (*.rubyonrails.org,*.cloudflarepartners.comconfirmed live). No numeric bounty amount anywhere we could find —team.bounty_tableexists as a type but every plausible field name on it (rewards,severities,low_bounty/high_bounty,min/max,field_names, …) came backdoesn't exist. If HackerOne ever documents the real field names,bountyProgram()'shackeronebranch is the one place to add them.
What's not here: Immunefi
Immunefi is not a platform in this pack, on purpose. /explore and every
/bug-bounty/{slug}/ page are public — no login needed — but the actual scope
list and severity-tiered reward table load client-side from an internal API
that is not reachable as a stable, documented JSON endpoint. Checked and ruled
out, 2026-10-08:
- Server-rendered HTML: the full page (200, ~210KB for
/bug-bounty/ens/) carries zero reward-table fields and exactly one0x...contract address — the scope list renders after hydration, client-side. - The Next.js RSC flight payload (
RSC: 1header, the app-router equivalent of Next's old_next/data/*.json): same result, no reward/scope keys in the ~30KB response. robots.txt/sitemap-dynamic.xml: public and unauthenticated, and useful for discovering program slugs (/bug-bounty/{slug}/× ~166), but a sitemap only carrieslastmod(last content change), never a launch date.- The one genuinely public, static fact per program is the "rewards up to $X" line Immunefi bakes into the page's SEO meta description tag — real, but a single top-line number is too thin to ship as a program record next to the other three platforms' structured scope + reward tables.
If Immunefi ever publishes (or we find) a stable JSON endpoint for this, it's a
fourth platform value to add, following the same shape as yeswehack.
Also not here: Intigriti
Not checked — Intigriti's public directory requires a researcher account/token to browse, per the task that specified this pack. Skipped rather than scraped from behind a login.
Quick Start
Add to your MCP client (Claude Desktop, Cursor, Windsurf, etc.):
What this endpoint actually serves
tools/list at https://gateway.pipeworx.io/bug-bounty-programs/mcp returns the tools in the table
above plus the shared Pipeworx meta-tools — ask_pipeworx,
discover_tools, search_within, remember/recall and the rest of the
gateway-wide set. So the tool count you see is larger than this table: a
single-pack endpoint currently lists roughly 30 shared tools alongside the
pack's own. The connection's initialize response states its exact scope, and
is the authoritative answer for a given day.
This is deliberate, not multiplexing by accident. The meta-tools are what let a
scoped connection answer a question this pack does not cover — via
ask_pipeworx, which routes across the whole catalog — without you adding a
second MCP server. There is currently no way to mount a pack endpoint without
them; if the extra schemas cost you more context than the routing is worth,
connect to the full gateway once rather than to several pack endpoints.
Or connect to the full Pipeworx gateway to get every pack's tools listed directly, instead of just this one's:
Both URLs reach the same gateway and the same 1743+ data sources. The
only difference is which pack's tools are listed directly; ask_pipeworx
reaches all of them from either one.
No MCP client? Call it over HTTP
No account needed for the first calls. Inspect any tool: GET https://gateway.pipeworx.io/v1/tools/bounty_programs_search. Find one: POST https://gateway.pipeworx.io/v1/tools/search_packs with {"query":"..."}.
Standalone (no gateway account)
This package also runs as a local stdio MCP server — no Pipeworx account, no gateway round-trip:
Or run it directly to confirm it starts:
It speaks MCP over stdin/stdout and answers initialize/tools/list/tools/call
for only this pack's tools — none of the shared meta-tools the gateway
connection above adds. Same source, same tools, no ask_pipeworx routing.
Using with ask_pipeworx
Instead of calling tools directly, you can ask questions in plain English — this works on the pack endpoint above as well as on the full gateway:
The gateway picks the right tool and fills the arguments automatically.
More
License
MIT
来源:README.md,提交 228c93c
工具
0版本历史
1- v0.1.0最新Oct 9, 2026

