No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by PatrikFehrenbach · MCP Server · ★ 333
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is h1-brain safe to install? View the security audit →
h1-brain An MCP server that connects your AI assistant to HackerOne. It pulls your bug bounty history, program scopes, and report details into a local SQLite database, then exposes tools that let any MCP-compatible client (Claude Desktop, Claude Code, etc.) search, analyze, and build on your past work. It also ships with a pre-built database of 3,600+ publicly disclosed bounty-awarded reports from the HackerOne community — full vulnerability write-ups, weakness types, and bounty amounts. The AI uses both your personal data and public knowledge to generate attack briefings. The primary tool, , generates a full hacking session briefing in a single call: fresh scope from the API, your past findings, public disclosures for that program, weakness patterns, untouched assets, and suggested attack vectors — all formatted as actionable instructions that put the AI in offensive mode.
| Stars | 333 |
| Forks | 46 |
| Language | Python |
| Category | MCP Server |
| License | MIT |
| Quality Score | 73.8759201914111/100 |
| Open Issues | 1 |
| Last Updated | 2026-04-07 |
| Created | 2026-03-10 |
| Platforms | claude-code, mcp, python |
| Est. Tokens | ~20k |
Looking for a h1-brain alternative? If you're comparing h1-brain with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.
A growing collection of MCP servers bringing offensive security tools to AI assistants. Nmap, Ghidra, Nuclei,
Open-source AI pentester that proves every finding. Machine oracles re-run each exploit; verified bugs ship a
A curated collection of top-tier penetration testing tools and productivity utilities across multiple domains.
Production-grade MCP server for Wazuh SIEM — 55 security tools for alert triage, threat hunting, vulnerability
ToolHive is an application that allows you to install, manage and run MCP servers and connect them to AI agent
AI Powered penetration testing Platform for offensive security research
Explore other popular mcp server tools:
h1-brain is MCP server that connects AI assistants to HackerOne for bug bounty hunting. It is categorized as a MCP Server with 333 GitHub stars.
h1-brain is primarily written in Python. It covers topics such as ai, bug-bounty, bug-bounty-tools.
You can find installation instructions and usage details in the h1-brain GitHub repository at github.com/PatrikFehrenbach/h1-brain. The project has 333 stars and 46 forks, indicating an active community.
h1-brain is released under the MIT license, making it free to use and modify according to the license terms.
The top alternatives to h1-brain on Agent Skills Hub include mcp-security-hub, pentest-ai, awesome-hacking-lists. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: