# Bug Bounty Tools

> Use this tool when you need to streamline bug bounty hunting workflows and automate vulnerability discovery. It provides REST API endpoints and specialized tools for reconnaissance, vulnerability hunting, and testing, solving problems related to manual testing and workflow management. Ideal for security researchers and bug bounty hunters, it takes in inputs such as target URLs and file uploads, and outputs prioritized vulnerability reports and comprehensive testing workflows.

Canonical page: https://skillsregistry.net/skills/slanycukr-bugbounty  
JSON: https://api.skillsregistry.net/v1/skills/slanycukr-bugbounty

## Description

A specialized MCP server focused exclusively on bug bounty hunting workflows, providing both REST API endpoints and MCP tools for reconnaissance, vulnerability hunting, business logic testing, OSINT gathering, and file upload testing. Built with Python using Flask and FastMCP, it features prioritized vulnerability testing based on impact and bounty potential, comprehensive workflow generation for different phases of security testing, and integration with popular bug bounty tools like Nuclei, SQLMap, Subfinder, and HTTPx. The implementation uses a clean architecture with specialized managers for different testing phases and includes a dedicated file upload vulnerability testing framework with bypass techniques, making it ideal for bug bounty hunters and security researchers who need structured, automated workflows for systematic vulnerability discovery and testing.

## Trust

- **Trust score (0–1):** 0.37
- **Verification tier:** scanned
- **Last scanned:** 2026-09-19

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** security
- **Updated:** 2026-09-19

## Source

- **Source listing:** [PulseMCP](https://www.pulsemcp.com/servers/slanycukr-bugbounty)
- **Repository:** <https://github.com/slanycukr/bugbounty-mcp-server>

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "slanycukr-bugbounty"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/slanycukr-bugbounty` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/slanycukr-bugbounty/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
