Install
Client config
Repo snippets:- Claude Code:
mcp/bughunter-mcp/claude-config.json - OpenCode:
mcp/bughunter-mcp/opencode-config.json
~/.claude/settings.json):
serve from a checkout where paths resolve, or point command/args at your install.
Scope and approval
Policy path:
Error codes
SCOPE_REQUIRED, OUT_OF_SCOPE, TARGET_REQUIRED, ACTIVE_TEST_APPROVAL_REQUIRED, REPORT_APPROVAL_REQUIRED, AUTHORIZATION_REQUIRED, INSUFFICIENT_EVIDENCE, RESEARCH_FAILED, CANCELLED
Tool catalog (25)
Backed by existing
tools/recon_engine.sh, tools/hunt.py, tools/validate.py, tools/lead_board.py, memory/*, and public HackerOne helpers under mcp/hackerone-mcp/.
Sibling MCP configs
Burp and Caido configs undermcp/ are third-party proxy integrations — see Integrations. Label experimental where your client setup is nonstandard.
Related
- Architecture
- Configuration
- Integrations
- Upstream notes: docs/mcp.md