Bug Bounty Intelligence MCP Server
AI-powered smart contract security analysis for AI agents and developers. Drawn from a corpus of 27,681 submitted findings across 105 Sherlock and Code4rena contests. Cost: $5 USDC on Base (eip155:8453) via x402. Free tool: list_vulnerability_patterns - no payment needed. It is available as a remote MCP endpoint.
Teams that want a hosted security endpoint instead of running a local process. The project is written in JavaScript.
VERIFIED ACTIVE
LAST COMMIT 2026-08-20 · ★ 7 · #139 OF 182 MAINTAINED SECURITY · VERIFIED 2026-08-25
MIT · JavaScript servers · how we verify → /methodology
01 · Install Bug Bounty Intelligence
Claude Code
claude mcp add holistis-bug-bounty-intelligence-mcp --transport http https://wazir-x402.duckdns.org/api/bug-intel Claude Desktop / Cursor / VS Code - add to config
{
"mcpServers": {
"holistis-bug-bounty-intelligence-mcp": {
"url": "https://wazir-x402.duckdns.org/api/bug-intel"
}
}
} Same JSON for Cursor. For VS Code, rename the top-level key from `mcpServers` to `servers`.
Using another client? Same JSON, different key
Claude Desktop · mcpServers
Cursor · mcpServers
VS Code · servers
Windsurf · mcpServers
Zed · context_servers
Cline · mcpServers
Roo Code · mcpServers
Continue · mcpServers
LibreChat · mcpServers
Gemini CLI · mcpServers
Codex CLI · mcp_servers
Full setup guides: every client.
02 · Evidence
https://wazir-x402.duckdns.org/api/bug-intel
transport: streamable-http
endpoint responds (non-MCP reply - review) · probed 2026-08-25
Security posture
What to check before giving this server access to your agent - from the registry, GitHub, and our own probes. We don't score safety; we show what's verifiable.
runs as remote - your agent's requests go to wazir-x402.duckdns.org
repo age created 2026-07-19 - young repo, little track record yet
license MIT - declared in the repository
registry namespace io.github.holistis is GitHub-verified and matches the repo owner
03 · What Bug Bounty Intelligence can do
Prose above is summarized from the project's README and registry record - no invented capabilities.
What you can build
An agent gets 3 documented tools across read & search, scan, including scan_contract, get_scan_report, list_vulnerability_patterns.
The 3 tools it gives your agent
Extracted from the project's README - what Bug Bounty Intelligence lets an agent do.
- scan_contract
- - Submit repo for security analysis
- get_scan_report
- - Poll status and get report URL
- list_vulnerability_patterns
- - Show acceptance rates from exact-reconciled Sherlock contests
Latest releases
v1.0.3 · 2026-07-29
Changes since 1.0.0: · Embedded the vulnerability pattern library directly in the module so list_vulnerability_patterns works out of the box via npx (previously depended on a local file path that only existed on the…
04 · Who maintains Bug Bounty Intelligence
Bug Bounty Intelligence is maintained by holistis. We track 2 MCP servers from holistis - 2 actively maintained, 9 combined GitHub stars, oldest repo from Jul 2026. Full record: all servers from holistis.
05 · Facts
- category
- security - ranked #139 of 182 actively-maintained security servers as of 2026-08-25.
- release cadence
- 1 release in the last 90 days (latest 2026-07-29)
- registry
- io.github.holistis/bug-bounty-intelligence-mcp (active, first published 2026-07-20 · 2 versions)
06 · Bug Bounty Intelligence FAQ
Is Bug Bounty Intelligence still maintained?
Yes - as of 2026-08-25, its last commit was 2026-08-20 and it shipped 1 release in the last 90 days. We re-verify nightly.
What can Bug Bounty Intelligence do?
An agent gets 3 documented tools across read & search, scan, including scan_contract, get_scan_report, list_vulnerability_patterns.
How do I install Bug Bounty Intelligence?
Run `claude mcp add holistis-bug-bounty-intelligen --transport http https://wazir-x402.duckdns.org/api/bug-intel`. You can also paste the ready-made client config above.
07 · Alternatives to Bug Bounty Intelligence
Alternatives to Bug Bounty Intelligence
Maintained security servers if Bug Bounty Intelligence isn't the fit.
- SafeDep Vet MCP Protect your AI agents and IDEs from malicious open-source packages. ★ 1,102 · 2026-08-24
- SonarQube MCP Server Analyze code quality and security with SonarQube Server or Cloud directly in AI assistants. ★ 632 · 2026-08-24
- Decionis MCP Server Fail-closed policy gate for AI agent actions, with local evaluation and native pre-tool hooks. ★ 533 · 2026-08-24
- HOL Guard Local-first AI agent security evidence and approval workflows through HOL Guard's stdio MCP server. ★ 470 · 2026-08-25
- Emisar Let AI operate servers without SSH. Choose actions, approve risky changes, and audit every step. ★ 409 · 2026-08-23
- Bradesco MCP server for Bradesco - Pix, Cobrança (boleto), Arrecadação, Extrato (OAuth2 + mTLS) ★ 269 · 2026-08-12
Pairs well with
Servers that cover what Bug Bounty Intelligence doesn't - only shown when the pairing reason fits the companion.
More security MCP servers · Honey Labs · Q Ring · IdentArk Gateway · Thumb Gate · Inkog
More JavaScript MCP servers · Hostinger API MCP · Fmp · Lm · Read Only Local MySQL MCP Server · Read Only Local Postgres MCP Server · see all