h1-brain — HackerOne context for AI-assisted bounty sessions

ToolsYesterday, 13:48
h1-brain is a local Python MCP server that syncs a researcher's rewarded reports, accessible programs, and scopes from the HackerOne API into SQLite. It also ships with a searchable database described as containing more than 3,600 bounty-awarded public disclosures.
Capabilities: • hack(handle) fetches the current program scope and combines it with personal and public report history; • personal reports can be filtered by program, weakness, and severity, then retrieved with their full write-ups; • the bundled disclosure database supports full-text search by query, program, or weakness; • the briefing highlights assets absent from personal report titles and weakness types rewarded on other programs; • attachment tools return fresh temporary download URLs from HackerOne.
The distinction is the prebuilt briefing rather than raw API access: it puts current scope, past successful techniques, coverage gaps, and public disclosures into one result for the connected agent. h1-brain does not scan or exploit targets by itself, and its recommendations remain heuristics derived from stored report metadata. It requires Python 3.10+, a HackerOne API token, and an MCP-compatible client.
Vendors
Hackerone
Patrikfehrenbach
Products
H1-Brain
Hackerone Api
Mcp
Python 3.10+
Sqlite