Bug Bounty Programs
liveReferencebug-bounty-programs
Tools
bounty_programs_searchSearch public bug-bounty program directories on Bugcrowd, YesWeHack and HackerOne — program name, cash bounty range, and status (open/paused/disabled), each sourced from that platform's own public, un
No parameters required.
Try it
bounty_programOne bug-bounty program by platform + handle: bounty range, status, and scope assets where the platform publishes them without a login. YesWeHack returns a full severity x asset-value reward table; Hac
No parameters required.
Try it
bounty_new_programsBug-bounty programs launched in the last N days, by real launch date. Currently HackerOne only — the only one of the three platforms that publishes a `launched_at` field without a login; Bugcrowd and
No parameters required.
Try it
Test with curl
The gateway speaks JSON-RPC 2.0 over HTTP POST. You can test any pack directly from the terminal.
curl -X POST https://gateway.pipeworx.io/bug-bounty-programs/mcp \
-H "Content-Type: application/json" \
-d '{"jsonrpc":"2.0","id":1,"method":"tools/list"}'curl -X POST https://gateway.pipeworx.io/bug-bounty-programs/mcp \
-H "Content-Type: application/json" \
-d '{"jsonrpc":"2.0","id":2,"method":"tools/call","params":{"name":"bounty_programs_search","arguments":{}}}'Use with the SDK
Install @pipeworx/sdk to call tools from any TypeScript/Node project.
import { Pipeworx } from '@pipeworx/sdk';
const px = new Pipeworx();
const result = await px.call("bounty_programs_search", {});// Or ask in plain English:
const answer = await px.ask("bug-bounty-programs");