h1-brain — security grade SAFE, quality 74/100

Security audit verdict: SAFE · quality 74/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by PatrikFehrenbach · MCP Server · ★ 333

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is h1-brain safe to install? View the security audit →

About h1-brain

h1-brain An MCP server that connects your AI assistant to HackerOne. It pulls your bug bounty history, program scopes, and report details into a local SQLite database, then exposes tools that let any MCP-compatible client (Claude Desktop, Claude Code, etc.) search, analyze, and build on your past work. It also ships with a pre-built database of 3,600+ publicly disclosed bounty-awarded reports from the HackerOne community — full vulnerability write-ups, weakness types, and bounty amounts. The AI uses both your personal data and public knowledge to generate attack briefings. The primary tool, , generates a full hacking session briefing in a single call: fresh scope from the API, your past findings, public disclosures for that program, weakness patterns, untouched assets, and suggested attack vectors — all formatted as actionable instructions that put the AI in offensive mode.

aibug-bountybug-bounty-toolsclaudehackeronehackingmcpmcp-serverpentestingsecurity

Quick Facts

Stars333
Forks46
LanguagePython
CategoryMCP Server
LicenseMIT
Quality Score73.8759201914111/100
Open Issues1
Last Updated2026-04-07
Created2026-03-10
Platformsclaude-code, mcp, python
Est. Tokens~20k

h1-brain alternative? Top 6 similar tools

Looking for a h1-brain alternative? If you're comparing h1-brain with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • mcp-security-hub by FuzzingLabs · ⭐ 758

    A growing collection of MCP servers bringing offensive security tools to AI assistants. Nmap, Ghidra, Nuclei,

  • pentest-ai by 0xSteph · ⭐ 1.7k

    Open-source AI pentester that proves every finding. Machine oracles re-run each exploit; verified bugs ship a

  • awesome-hacking-lists by taielab · ⭐ 1.4k

    A curated collection of top-tier penetration testing tools and productivity utilities across multiple domains.

  • Wazuh-MCP-Server by gensecaihq · ⭐ 216

    Production-grade MCP server for Wazuh SIEM — 55 security tools for alert triage, threat hunting, vulnerability

  • toolhive-studio by stacklok · ⭐ 163

    ToolHive is an application that allows you to install, manage and run MCP servers and connect them to AI agent

  • nyxstrike by CommonHuman-Lab · ⭐ 145

    AI Powered penetration testing Platform for offensive security research

More MCP Server Tools

Explore other popular mcp server tools:

View all MCP Server tools →

Popular Python Agent Tools

Frequently Asked Questions

What is h1-brain?

h1-brain is MCP server that connects AI assistants to HackerOne for bug bounty hunting. It is categorized as a MCP Server with 333 GitHub stars.

What programming language is h1-brain written in?

h1-brain is primarily written in Python. It covers topics such as ai, bug-bounty, bug-bounty-tools.

How do I install or use h1-brain?

You can find installation instructions and usage details in the h1-brain GitHub repository at github.com/PatrikFehrenbach/h1-brain. The project has 333 stars and 46 forks, indicating an active community.

What license does h1-brain use?

h1-brain is released under the MIT license, making it free to use and modify according to the license terms.

What are the best alternatives to h1-brain?

The top alternatives to h1-brain on Agent Skills Hub include mcp-security-hub, pentest-ai, awesome-hacking-lists. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse MCP Server tools