Browse
→ Identity & Auth
→ YesWeHack MCP
YesWeHack MCP
Unofficial read-only Node stdio MCP server for an authorized YesWeHack hunter account, including programs, reports and masked test-credential metadata. Login uses the account email, password and TOTP secret; keep these in a private credential store. Repository created September 20, 2026.
MCP unverified
Integration
| Transport | stdio |
| Auth | api-key |
| Endpoint | node dist/src/index.js |
| Install | git clone https://github.com/Miro-sh/yeswehack-mcp.git && cd yeswehack-mcp && npm ci && npm run build |
Use Cases
| 01 | List programs visible to an authorized hunter account |
| 02 | Inspect report status without changing it |
| 03 | Read masked test-credential metadata |
Tags
yeswehack bug-bounty security read-only totp stdio
Machine-readable: /api/servers.json
· JSON-LD schema embedded in <head>