An MCP server for authorized bug bounty work that enforces an evidence-driven workflow with session management, preflight checks, surface discovery, and verified scanning.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
process.env. You'll be asked to provide them before it can run.BOUNTYPROOF_TIMEOUT_SECONDSBOUNTYPROOF_DELAY_MS— 350 Delay between preflight requestsBOUNTYPROOF_CONTACT— export ="researcher@example.com"BOUNTYPROOF_REPORT_DIR— .bountyproof/reports Local evidence directoryBOUNTYPROOF_MAX_BODY_BYTESBOUNTYPROOF_MAX_URLS— 100 Maximum number of discovered URLsBOUNTYPROOF_COMMAND_TIMEOUT_SECONDSBOUNTYPROOF_NUCLEI_RATE_LIMIT— 2 Maximum Nuclei requests per secondBOUNTYPROOF_KATANA_BIN— export ="$HOME/go/bin/katana"BOUNTYPROOF_NUCLEI_BIN— export ="$HOME/go/bin/nuclei"BOUNTYPROOF_SECURITYTRAILS_API_KEY— Historical A records from SecurityTrails when is configured.BOUNTYPROOF_IMPORT_ROOT— current directory Allowed root for HAR, OpenAPI, and Postman filesBOUNTYPROOF_MAX_IMPORT_BYTES— 20000000 Maximum imported surface file size[](https://m8ven.ai/mcp/skyxtools-bountyproof-mcp-1uq8d4)