# BugBounty Security Scanner

> Use this tool when you need to identify vulnerabilities and conduct penetration testing on networks, web applications, and systems. It solves problems related to security assessments, bug bounty hunting, and compliance testing by providing a unified interface for 90+ security tools and platforms. With inputs including target URLs and IP addresses, and outputs such as vulnerability reports and risk assessments, use the BugBounty Security Scanner in contexts where comprehensive security testing and penetration testing are required.

Canonical page: https://skillsregistry.net/skills/bugbounty  
JSON: https://api.skillsregistry.net/v1/skills/bugbounty

## Description

This MCP server provides a comprehensive bug bounty hunting and penetration testing toolkit built by Gokul, integrating 90+ security tools including Nuclei, Subfinder, Nmap, SQLMap, and OSINT platforms like Shodan and VirusTotal through a unified interface. The implementation features eight specialized tool categories (reconnaissance, scanning, vulnerability assessment, web application testing, network analysis, OSINT, exploitation, and reporting) with built-in safety mechanisms including target validation, rate limiting, and safe mode restrictions to prevent unauthorized testing. Designed with Docker deployment, extensive wordlist management, and configurable API integrations, it enables security researchers and penetration testers to conduct automated security assessments through natural language interactions with AI assistants, streamlining the entire bug bounty workflow from initial reconnaissance to vulnerability reporting.

## Trust

- **Trust score (0–1):** 0.74
- **Verification tier:** verified
- **Last scanned:** 2026-09-19

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** cloud-infra
- **Updated:** 2026-09-19

## Source

- **Source listing:** [PulseMCP](https://www.pulsemcp.com/servers/bugbounty)
- **Repository:** <https://github.com/gokulapap/bugbounty-mcp-server>

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "bugbounty"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/bugbounty` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/bugbounty/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
