Bug Bounty Programs

io.github.pipeworx-iov0.1.0更新於 Oct 9, 2026

bug-bounty-programs

已驗證Streamable HTTP可網頁執行Security & MonitoringWeb Search & Scraping

概覽

AI 產生的概覽

讓助理檢索 Bugcrowd、YesWeHack 與 HackerOne 的公開漏洞賞金計畫目錄,取得名稱、賞金、上線日期與範圍資產。

功能
以公開的漏洞賞金計畫目錄資料提供三個唯讀工具。bounty_programs_search 可依名稱、最低賞金(美元)、上線日期,以及範圍是否包含萬用字元資產,在單一或全部三個平台上搜尋。bounty_program 依平台與 handle 回傳單一計畫,包含範圍資產,YesWeHack 另回傳依資產價值分級的嚴重性獎勵表。bounty_new_programs 列出最近 N 天內上線的計畫,僅限 HackerOne。不含漏洞內容或研究者資料。
適用情境
適合讓助理查詢有哪些漏洞賞金計畫、賞金多少、何時上線、哪些資產在範圍內,而不必手動瀏覽各平台目錄。涵蓋範圍並不平均:Bugcrowd 的範圍資料需要登入,HackerOne 不提供具體賞金金額,YesWeHack 沒有上線日期。
執行需求
使用供應方閘道上的遠端 streamable HTTP 端點;最初幾次呼叫不需要帳號、權杖或 API 金鑰。另提供本機 stdio 版本,為 npm 套件,以 npx 執行,需要 Node.js。需要能連線至該閘道以及三個上游平台端點。
安裝前請注意
僅對公開目錄資料做唯讀查詢,不會寫入、傳送或刪除任何內容。閘道連線還會列出共用中繼工具,例如 ask_pipeworx、discover_tools 與 remember/recall,它們會把問題路由到供應方更廣的目錄,因此工具結構描述與上下文用量高於本套件本身。此整合為獨立且非官方,與上游平台無隸屬關係。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 Bug Bounty Programs,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Web executable,透過 Streamable HTTP。 遠端服務在工作區中設定後即可從網頁執行環境執行。

其他 MCP 客戶端

把它新增到你客戶端的 mcpServers 設定中。

{
  "mcpServers": {
    "bug-bounty-programs": {
      "type": "http",
      "url": "https://gateway.pipeworx.io/bug-bounty-programs/mcp"
    }
  }
}

README

@pipeworx/bug-bounty-programs

Public bug-bounty PROGRAM DIRECTORY data — program name, bounty range, status and scope assets — from Bugcrowd, YesWeHack and HackerOne's own public directories. No vulnerability content, no researcher profiles or handles.

Part of Pipeworx — an MCP gateway connecting AI agents to 1743+ live data sources. This is an independent, unofficial integration — not affiliated with, endorsed by, or published by the upstream provider.

Tools

  • bounty_programs_search(platform?, query?, min_bounty?, launched_since?, has_wildcard?, limit?) — search across one or all three platforms by name, minimum bounty (USD), launch date (HackerOne only — see below), and whether scope includes a wildcard asset like *.example.com (checked live on yeswehack/hackerone; bugcrowd returns a count: 0 with an explanatory note instead of an error, because its scope is login-walled, not broken).
  • bounty_program(platform, handle) — one program by platform + handle. YesWeHack returns a full severity x asset-value reward table and real scope; HackerOne returns real scope but no numeric reward table (not exposed anywhere on the public schema); Bugcrowd returns neither and says why.
  • bounty_new_programs(days) — programs launched in the last N days, by real launch date. HackerOne only; see "What's not here" below for why Bugcrowd/YesWeHack can't contribute to this one honestly.

Auth

Keyless. Every endpoint below answers with no account, token, or API key.

Data sources

  • https://bugcrowd.com/engagements.json — paged (?page=N, 24/page, paginationMeta.totalCount) public program list: name, URL, reward summary, industry, access status. No scope/target data — Bugcrowd's scope "reveal" action redirects to /h/engagements/{handle}/reveal.json, its researcher-sign-in area. That is a genuine login wall, not a bug, and bounty_program/has_wildcard say so rather than returning a silent empty result.
  • https://api.yeswehack.com/programs (list, ?page=N) and https://api.yeswehack.com/programs/{slug} (detail) — the richest of the three. Detail returns scopes[] (real asset identifiers, some with wildcards), out_of_scope, and reward_grid_default/low/medium/high/critical/very_low — a real severity x asset-value-tier reward table (only the tiers the program actually uses have non-null values; everything else is null, not zero). No launch-date field anywhere on this endpoint — only last_update_at (last change, never surfaced as launched_at here to avoid implying a launch).
  • https://hackerone.com/graphql (POST, unauthenticated) — query { teams } / query { team(handle) }. Introspection is disabled, so every field name below was found by probing a guess and reading GraphQL's own "did you mean X?" error back, not from a published schema doc:
    • teams(first/last, after/before): handle name offers_bounties submission_state launched_at — launched_at is a REAL, verified launch date (confirmed against hackerone.com/security → 2013-11-06, the platform's own founding program). last: N returns the N most-recently-created teams, which is what bounty_new_programs walks backward from; there is no working order_by value we could find (order_by: {field: ..., direction: DESC} is accepted syntactically but every field name we tried for field was rejected), so sorting relies on sequential internal IDs rather than an explicit date sort.
    • team(handle).structured_scopes_search(first): a union (DocumentUnion) — use ... on StructuredScopeDocument { identifier asset_type eligible_for_bounty eligible_for_submission instruction }. identifier is the actual scope asset (domain/URL), sometimes a wildcard (*.rubyonrails.org, *.cloudflarepartners.com confirmed live). No numeric bounty amount anywhere we could find — team.bounty_table exists as a type but every plausible field name on it (rewards, severities, low_bounty/high_bounty, min/max, field_names, …) came back doesn't exist. If HackerOne ever documents the real field names, bountyProgram()'s hackerone branch is the one place to add them.

What's not here: Immunefi

Immunefi is not a platform in this pack, on purpose. /explore and every /bug-bounty/{slug}/ page are public — no login needed — but the actual scope list and severity-tiered reward table load client-side from an internal API that is not reachable as a stable, documented JSON endpoint. Checked and ruled out, 2026-10-08:

  • Server-rendered HTML: the full page (200, ~210KB for /bug-bounty/ens/) carries zero reward-table fields and exactly one 0x... contract address — the scope list renders after hydration, client-side.
  • The Next.js RSC flight payload (RSC: 1 header, the app-router equivalent of Next's old _next/data/*.json): same result, no reward/scope keys in the ~30KB response.
  • robots.txt / sitemap-dynamic.xml: public and unauthenticated, and useful for discovering program slugs (/bug-bounty/{slug}/ × ~166), but a sitemap only carries lastmod (last content change), never a launch date.
  • The one genuinely public, static fact per program is the "rewards up to $X" line Immunefi bakes into the page's SEO meta description tag — real, but a single top-line number is too thin to ship as a program record next to the other three platforms' structured scope + reward tables.

If Immunefi ever publishes (or we find) a stable JSON endpoint for this, it's a fourth platform value to add, following the same shape as yeswehack.

Also not here: Intigriti

Not checked — Intigriti's public directory requires a researcher account/token to browse, per the task that specified this pack. Skipped rather than scraped from behind a login.

Quick Start

Add to your MCP client (Claude Desktop, Cursor, Windsurf, etc.):

json
{  "mcpServers": {    "bug-bounty-programs": {      "url": "https://gateway.pipeworx.io/bug-bounty-programs/mcp"    }  }}

What this endpoint actually serves

tools/list at https://gateway.pipeworx.io/bug-bounty-programs/mcp returns the tools in the table above plus the shared Pipeworx meta-tools — ask_pipeworx, discover_tools, search_within, remember/recall and the rest of the gateway-wide set. So the tool count you see is larger than this table: a single-pack endpoint currently lists roughly 30 shared tools alongside the pack's own. The connection's initialize response states its exact scope, and is the authoritative answer for a given day.

This is deliberate, not multiplexing by accident. The meta-tools are what let a scoped connection answer a question this pack does not cover — via ask_pipeworx, which routes across the whole catalog — without you adding a second MCP server. There is currently no way to mount a pack endpoint without them; if the extra schemas cost you more context than the routing is worth, connect to the full gateway once rather than to several pack endpoints.

Or connect to the full Pipeworx gateway to get every pack's tools listed directly, instead of just this one's:

json
{  "mcpServers": {    "pipeworx": {      "url": "https://gateway.pipeworx.io/mcp"    }  }}

Both URLs reach the same gateway and the same 1743+ data sources. The only difference is which pack's tools are listed directly; ask_pipeworx reaches all of them from either one.

No MCP client? Call it over HTTP

bash
curl -X POST https://gateway.pipeworx.io/v1/tools/bounty_programs_search \  -H 'Content-Type: application/json' \  -d '{"platform":"yeswehack","min_bounty":1000,"limit":10}'

No account needed for the first calls. Inspect any tool: GET https://gateway.pipeworx.io/v1/tools/bounty_programs_search. Find one: POST https://gateway.pipeworx.io/v1/tools/search_packs with {"query":"..."}.

Standalone (no gateway account)

This package also runs as a local stdio MCP server — no Pipeworx account, no gateway round-trip:

json
{  "mcpServers": {    "bug-bounty-programs": {      "command": "npx",      "args": ["-y", "@pipeworx/mcp-bug-bounty-programs"]    }  }}

Or run it directly to confirm it starts:

bash
npx -y @pipeworx/mcp-bug-bounty-programs

It speaks MCP over stdin/stdout and answers initialize/tools/list/tools/call for only this pack's tools — none of the shared meta-tools the gateway connection above adds. Same source, same tools, no ask_pipeworx routing.

Using with ask_pipeworx

Instead of calling tools directly, you can ask questions in plain English — this works on the pack endpoint above as well as on the full gateway:

ask_pipeworx({ question: "your question about Bug Bounty Programs data" })

The gateway picks the right tool and fills the arguments automatically.

More

License

MIT

來源:README.md,提交 228c93c

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v0.1.0最新Oct 9, 2026