Skip to main content
Glama

Decepticon v3.1 — Autonomous Bug Bounty Hunt Bundle

One command, full pipeline. Skill methodology + MCP server + H1 auto-submit + profit tracking. Works with OpenCode, Claude Desktop, and any MCP-compatible AI agent.

Quick Install

npx decepticon           # Interactive setup wizard

or via npm:

npm install -g decepticon
decepticon setup

Related MCP server: platform-adapter-mcp

What You Get

Component

Purpose

Skill

Complete H1 bug bounty methodology — 3-wave pipeline, reasoning engine, 20+ exploitation playbooks

MCP Server

Real-time state coordination, credential vault, session management, payload generation

H1 Auto-Submit

Generate H1-ready reports with CVSS/CWE → auto-submit via REST API

Profit Tracking

Bounty ledger with 75%/15%/10% split — every dollar tracked

Dashboard

Live web dashboard at http://127.0.0.1:9999

Setup Wizard

Interactive CLI that configures everything in 3 prompts

Usage

# Setup (first time)
npx decepticon setup

# Start a hunt
opencode hunter
# Then type: HACK https://hackerone.com/program-handle

# View earnings
npx decepticon status

# Launch dashboard
npx decepticon dashboard

Profit Split

  • 75% — You (the hunter)

  • 15% — Decepticon platform

  • 10% — Referral partner

All tracked automatically in ~/.opencode/decepticon-state/bounty_ledger.json.

Requirements

  • Python 3.7+ (for MCP server)

  • OpenCode or Claude Desktop

  • Python 3.11+ recommended

Tool Schema Changelog

Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.

No tool schema history has been recorded yet.

Maintenance

ActivitySlowing
ResponsivenessSyncing

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Connectors

Related MCP Servers

  • F
    license
    Not graded
    quality
    D
    maintenance
    A comprehensive MCP server for automated bug bounty hunting and security reconnaissance, featuring over 28 specialized tools for subdomain discovery, vulnerability scanning, and traffic analysis. It integrates automated scope validation and professional reporting across multiple platforms like HackerOne and Bugcrowd to streamline security testing.
    5
    -
  • F
    license
    Not graded
    quality
    C
    maintenance
    Wraps multiple bug bounty platform APIs (HackerOne, Bugcrowd, etc.) behind a uniform MCP tool surface, enabling LLM agents to query programs, scope, and briefs across platforms through a single interface.
    -
  • A
    license
    Not graded
    quality
    C
    maintenance
    Enables automated bug bounty hunting and security research with tools for reconnaissance, web vulnerability scanning, API testing, binary analysis, and mobile app analysis through an MCP interface.
    MIT
  • A
    license
    A
    quality
    B
    maintenance
    MCP server for offensive-security tooling, enabling AI agents to run reconnaissance, CVE intelligence, JavaScript analysis, HTTP probing, and port scanning against authorized targets.
    10
    MIT

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/itsdanylol/DECEPTICON'

If you have feedback or need assistance with the MCP directory API, please join our Discord server