71
/ 100
20 days ago
glama

BountyProof MCP

An MCP server for authorized bug bounty work that enforces an evidence-driven workflow with session management, preflight checks, surface discovery, and verified scanning.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
Open source with a license and README
Anyone can audit the code, the license is declared, and the publisher documents what it does.
🔐
You'll be asked for 1 credential: BOUNTYPROOF_SECURITYTRAILS_API_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configBOUNTYPROOF_TIMEOUT_SECONDS
configBOUNTYPROOF_DELAY_MS350 Delay between preflight requests
configBOUNTYPROOF_CONTACTexport ="researcher@example.com"
configBOUNTYPROOF_REPORT_DIR.bountyproof/reports Local evidence directory
configBOUNTYPROOF_MAX_BODY_BYTES
configBOUNTYPROOF_MAX_URLS100 Maximum number of discovered URLs
configBOUNTYPROOF_COMMAND_TIMEOUT_SECONDS
configBOUNTYPROOF_NUCLEI_RATE_LIMIT2 Maximum Nuclei requests per second
configBOUNTYPROOF_KATANA_BINexport ="$HOME/go/bin/katana"
configBOUNTYPROOF_NUCLEI_BINexport ="$HOME/go/bin/nuclei"
🔐 secretBOUNTYPROOF_SECURITYTRAILS_API_KEYHistorical A records from SecurityTrails when is configured.
configBOUNTYPROOF_IMPORT_ROOTcurrent directory Allowed root for HAR, OpenAPI, and Postman files
configBOUNTYPROOF_MAX_IMPORT_BYTES20000000 Maximum imported surface file size
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 4 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/skyxtools-bountyproof-mcp-1uq8d4)](https://m8ven.ai/mcp/skyxtools-bountyproof-mcp-1uq8d4)
commit: f0c4bc88cc5881c7a2558e43bc51b803da0571b5
code hash: 687601364b9fe1d38f8603073fe18db78c050b922f6debe4649589edb21d258e
verified: 7/11/2026, 8:19:18 AM
view raw JSON →