@pipeworx/bug-bounty-programs
Connect: https://pipeworx.io/mcp — every tool in the catalog, including @pipeworx/bug-bounty-programs’s. Install: one-click buttons
Connect to just the @pipeworx/bug-bounty-programs pack
https://gateway.pipeworx.io/bug-bounty-programs/mcp — only @pipeworx/bug-bounty-programs’s own tools, nothing else in the catalog.
No MCP client? Skip the connection: POST https://gateway.pipeworx.io/v1/tools/search_packs {"query":"..."} to find a tool below, GET /v1/tools/<name> for its schema, POST the same URL with arguments for the data — see For AI agents.
Tools: 3
Public bug-bounty PROGRAM DIRECTORY data — program name, bounty range, status and scope assets — from Bugcrowd, YesWeHack and HackerOne’s own public directories. No vulnerability content, no researcher profiles or handles.
Tools
bounty_programs_search(platform?, query?, min_bounty?, launched_since?, has_wildcard?, limit?)— search across one or all three platforms by name, minimum bounty (USD), launch date (HackerOne only — see below), and whether scope includes a wildcard asset like*.example.com(checked live on yeswehack/hackerone; bugcrowd returns acount: 0with an explanatorynoteinstead of an error, because its scope is login-walled, not broken).bounty_program(platform, handle)— one program by platform + handle. YesWeHack returns a full severity x asset-value reward table and real scope; HackerOne returns real scope but no numeric reward table (not exposed anywhere on the public schema); Bugcrowd returns neither and says why.bounty_new_programs(days)— programs launched in the last N days, by real launch date. HackerOne only; see “What’s not here” below for why Bugcrowd/YesWeHack can’t contribute to this one honestly.
Auth
Keyless. Every endpoint below answers with no account, token, or API key.
Data sources
https://bugcrowd.com/engagements.json— paged (?page=N, 24/page,paginationMeta.totalCount) public program list: name, URL, reward summary, industry, access status. No scope/target data — Bugcrowd’s scope “reveal” action redirects to/h/engagements/{handle}/reveal.json, its researcher-sign-in area. That is a genuine login wall, not a bug, andbounty_program/has_wildcardsay so rather than returning a silent empty result.https://api.yeswehack.com/programs(list,?page=N) andhttps://api.yeswehack.com/programs/{slug}(detail) — the richest of the three. Detail returnsscopes[](real asset identifiers, some with wildcards),out_of_scope, andreward_grid_default/low/medium/high/critical/very_low— a real severity x asset-value-tier reward table (only the tiers the program actually uses have non-null values; everything else isnull, not zero). No launch-date field anywhere on this endpoint — onlylast_update_at(last change, never surfaced aslaunched_athere to avoid implying a launch).https://hackerone.com/graphql(POST, unauthenticated) —query { teams }/query { team(handle) }. Introspection is disabled, so every field name below was found by probing a guess and reading GraphQL’s own “did you meanX?” error back, not from a published schema doc:teams(first/last, after/before):handle name offers_bounties submission_state launched_at—launched_atis a REAL, verified launch date (confirmed againsthackerone.com/security→2013-11-06, the platform’s own founding program).last: Nreturns the N most-recently-created teams, which is whatbounty_new_programswalks backward from; there is no workingorder_byvalue we could find (order_by: {field: ..., direction: DESC}is accepted syntactically but every field name we tried forfieldwas rejected), so sorting relies on sequential internal IDs rather than an explicit date sort.team(handle).structured_scopes_search(first): a union (DocumentUnion) — use... on StructuredScopeDocument { identifier asset_type eligible_for_bounty eligible_for_submission instruction }.identifieris the actual scope asset (domain/URL), sometimes a wildcard (*.rubyonrails.org,*.cloudflarepartners.comconfirmed live). No numeric bounty amount anywhere we could find —team.bounty_tableexists as a type but every plausible field name on it (rewards,severities,low_bounty/high_bounty,min/max,field_names, …) came backdoesn't exist. If HackerOne ever documents the real field names,bountyProgram()’shackeronebranch is the one place to add them.
What’s not here: Immunefi
Immunefi is not a platform in this pack, on purpose. /explore and every
/bug-bounty/{slug}/ page are public — no login needed — but the actual scope
list and severity-tiered reward table load client-side from an internal API
that is not reachable as a stable, documented JSON endpoint. Checked and ruled
out, 2026-10-08:
- Server-rendered HTML: the full page (200, ~210KB for
/bug-bounty/ens/) carries zero reward-table fields and exactly one0x...contract address — the scope list renders after hydration, client-side. - The Next.js RSC flight payload (
RSC: 1header, the app-router equivalent of Next’s old_next/data/*.json): same result, no reward/scope keys in the ~30KB response. robots.txt/sitemap-dynamic.xml: public and unauthenticated, and useful for discovering program slugs (/bug-bounty/{slug}/× ~166), but a sitemap only carrieslastmod(last content change), never a launch date.- The one genuinely public, static fact per program is the “rewards up to $X” line Immunefi bakes into the page’s SEO meta description tag — real, but a single top-line number is too thin to ship as a program record next to the other three platforms’ structured scope + reward tables.
If Immunefi ever publishes (or we find) a stable JSON endpoint for this, it’s a
fourth platform value to add, following the same shape as yeswehack.
Also not here: Intigriti
Not checked — Intigriti’s public directory requires a researcher account/token to browse, per the task that specified this pack. Skipped rather than scraped from behind a login.
Tools
- bounty_programs_search — Search public bug-bounty program directories on Bugcrowd, YesWeHack and HackerOne — program name, cash bounty range, and status (open/paused/disabled), each sourced from that platform’s own public, un
- bounty_program — One bug-bounty program by platform + handle: bounty range, status, and scope assets where the platform publishes them without a login. YesWeHack returns a full severity x asset-value reward table; Hac
- bounty_new_programs — Bug-bounty programs launched in the last N days, by real launch date. Currently HackerOne only — the only one of the three platforms that publishes a
launched_atfield without a login; Bugcrowd and
Tools
bounty_new_programs— Bug-bounty programs launched in the last N days, by real launch date. Currently HackerOne only — the only one of the three platforms that publishes a `launched_at` field without a login; Bugcrowd andbounty_program— One bug-bounty program by platform + handle: bounty range, status, and scope assets where the platform publishes them without a login. YesWeHack returns a full severity x asset-value reward table; Hacbounty_programs_search— Search public bug-bounty program directories on Bugcrowd, YesWeHack and HackerOne — program name, cash bounty range, and status (open/paused/disabled), each sourced from that platform's own public, un