Hacker Bob public records
Read-only public CVE records, capability metadata, and agent instructions from Hacker Bob.
Should I use this
Quality & Safety
Findings (7)
- HIGH
- LOWin get_capabilities
- INFOin list_public_cve_records
- INFOin get_public_cve_record
- INFOin search_public_cve_records
- INFOin list_workspaces
- INFOin launch_assessment
Based on automated analysis of tool definitions and protocol compliance.
Context Cost
This is the approximate number of tokens consumed each time the server's tools are loaded into a model's context. Higher counts reduce the attention available for other tasks.
Install
One-Click Install
Add this to your `claude_desktop_config.json` file:
{
"mcpServers": {
"hacker-bob-public-records": {
"url": "https://hackerbob.ai/mcp"
}
}
}Remote endpoints
https://hackerbob.ai/mcpstreamable-httpWhat it can do
Tool inventory
Tools (22)
🟢list_public_cve_records(limit, cursor, project, status)
List cleared public Hacker Bob Common Vulnerabilities and Exposures records with cursor pagination and optional project or publication-status filters.
Input Schema
{
"type": "object",
"properties": {
"limit": {
"type": "integer",
"minimum": 1,
"maximum": 100,
"description": "Maximum records to return. Defaults to 20."
},
"cursor": {
"type": "string",
"description": "Opaque cursor returned by a previous list call."
},
"project": {
"type": "string",
"description": "Exact open-source project name to include."
},
"status": {
"type": "string",
"enum": [
"public",
"assigned-no-public-record"
],
"description": "Publication status to include."
}
},
"required": [],
"additionalProperties": false
}🟢get_public_cve_record(recordId)
Return one cleared Hacker Bob CVE record by identifier, including its open-source project, publication status, and upstream public record URL when available.
Input Schema
{
"type": "object",
"properties": {
"recordId": {
"type": "string",
"pattern": "^CVE-[0-9]{4}-[0-9]+$",
"description": "CVE identifier such as CVE-2026-47747."
}
},
"required": [
"recordId"
],
"additionalProperties": false
}🟢search_public_cve_records(query, limit)
Search cleared public Hacker Bob CVE records by CVE identifier, open-source project name, or publication status without contacting any assessment target.
Input Schema
{
"type": "object",
"properties": {
"query": {
"type": "string",
"minLength": 1,
"description": "Text to match against CVE identifiers, project names, and publication status."
},
"limit": {
"type": "integer",
"minimum": 1,
"maximum": 50,
"description": "Maximum matching records to return. Defaults to 20."
}
},
"required": [
"query"
],
"additionalProperties": false
}🟢get_capabilities
Return current public boundaries and, when authenticated, workspace-specific tool reachability, scopes, and role requirements.
Input Schema
{
"type": "object",
"properties": {},
"required": [],
"additionalProperties": false
}🟢get_my_account
Return the authenticated account and the workspace bound to this agent connection.
Input Schema
{
"type": "object",
"properties": {},
"required": [],
"additionalProperties": false
}🟢list_workspaces
List active Hacker Bob workspaces available to the authenticated account. The connection remains bound to its approved workspace.
Input Schema
{
"type": "object",
"properties": {},
"required": [],
"additionalProperties": false
}🟢get_workspace(workspaceSlug)
Return the approved workspace and current membership role.
Input Schema
{
"type": "object",
"properties": {
"workspaceSlug": {
"type": "string",
"minLength": 1,
"maxLength": 80,
"pattern": "^[a-z0-9]+(?:-[a-z0-9]+)*$",
"description": "Workspace slug selected during agent authorization."
}
},
"required": [
"workspaceSlug"
],
"additionalProperties": false
}🟢list_assets(workspaceSlug, includeArchived)
List workspace assets and current ownership-authorization state without contacting a target.
Input Schema
{
"type": "object",
"properties": {
"workspaceSlug": {
"type": "string",
"minLength": 1,
"maxLength": 80,
"pattern": "^[a-z0-9]+(?:-[a-z0-9]+)*$",
"description": "Workspace slug selected during agent authorization."
},
"includeArchived": {
"type": "boolean",
"description": "Include archived assets. Defaults to false."
}
},
"required": [
"workspaceSlug"
],
"additionalProperties": false
}🟢get_asset(workspaceSlug, assetId)
Return one workspace asset and its current authorization state.
Input Schema
{
"type": "object",
"properties": {
"workspaceSlug": {
"type": "string",
"minLength": 1,
"maxLength": 80,
"pattern": "^[a-z0-9]+(?:-[a-z0-9]+)*$",
"description": "Workspace slug selected during agent authorization."
},
"assetId": {
"type": "string",
"minLength": 1,
"maxLength": 128
}
},
"required": [
"workspaceSlug",
"assetId"
],
"additionalProperties": false
}🟡begin_domain_authorization(workspaceSlug, domain, label, method, idempotencyKey)
Create a DNS TXT or HTTPS-file challenge proving control of a domain. This does not run an assessment.
Input Schema
{
"type": "object",
"properties": {
"workspaceSlug": {
"type": "string",
"minLength": 1,
"maxLength": 80,
"pattern": "^[a-z0-9]+(?:-[a-z0-9]+)*$",
"description": "Workspace slug selected during agent authorization."
},
"domain": {
"type": "string",
"minLength": 1,
"maxLength": 253,
"description": "Domain name only; no scheme, path, port, credentials, or wildcard."
},
"label": {
"type": "string",
"minLength": 1,
"maxLength": 120
},
"method": {
"type": "string",
"enum": [
"dns_txt",
"http_file"
]
},
"idempotencyKey": {
"type": "string",
"minLength": 8,
"maxLength": 128
}
},
"required": [
"workspaceSlug",
"domain",
"method",
"idempotencyKey"
],
"additionalProperties": false
}🟡check_domain_authorization(workspaceSlug, authorizationId, idempotencyKey)
Check the previously issued DNS or HTTPS proof and update the asset authorization state.
Input Schema
{
"type": "object",
"properties": {
"workspaceSlug": {
"type": "string",
"minLength": 1,
"maxLength": 80,
"pattern": "^[a-z0-9]+(?:-[a-z0-9]+)*$",
"description": "Workspace slug selected during agent authorization."
},
"authorizationId": {
"type": "string",
"minLength": 1,
"maxLength": 128
},
"idempotencyKey": {
"type": "string",
"minLength": 8,
"maxLength": 128
}
},
"required": [
"workspaceSlug",
"authorizationId",
"idempotencyKey"
],
"additionalProperties": false
}🟢list_assessments(workspaceSlug, includeArchived)
List assessments and current run states in the approved workspace.
Input Schema
{
"type": "object",
"properties": {
"workspaceSlug": {
"type": "string",
"minLength": 1,
"maxLength": 80,
"pattern": "^[a-z0-9]+(?:-[a-z0-9]+)*$",
"description": "Workspace slug selected during agent authorization."
},
"includeArchived": {
"type": "boolean"
}
},
"required": [
"workspaceSlug"
],
"additionalProperties": false
}🟢get_assessment(workspaceSlug, assessmentId)
Return one assessment, its verified asset, current run state, and any pending human approval.
Input Schema
{
"type": "object",
"properties": {
"workspaceSlug": {
"type": "string",
"minLength": 1,
"maxLength": 80,
"pattern": "^[a-z0-9]+(?:-[a-z0-9]+)*$",
"description": "Workspace slug selected during agent authorization."
},
"assessmentId": {
"type": "string",
"minLength": 1,
"maxLength": 128
}
},
"required": [
"workspaceSlug",
"assessmentId"
],
"additionalProperties": false
}🟡prepare_assessment(workspaceSlug, assetId, depth, coverage, interactionPolicy, ...)
Create an immutable assessment for a verified stored asset and return a browser approval URL. This never contacts the target.
Input Schema
{
"type": "object",
"properties": {
"workspaceSlug": {
"type": "string",
"minLength": 1,
"maxLength": 80,
"pattern": "^[a-z0-9]+(?:-[a-z0-9]+)*$",
"description": "Workspace slug selected during agent authorization."
},
"assetId": {
"type": "string",
"minLength": 1,
"maxLength": 128
},
"depth": {
"type": "string",
"enum": [
"standard",
"deep"
]
},
"coverage": {
"type": "object",
"properties": {
"mode": {
"type": "string",
"enum": [
"all",
"exclude",
"include"
]
},
"rules": {
"type": "array",
"items": {
"type": "string",
"minLength": 1,
"maxLength": 240
},
"maxItems": 100
}
},
"required": [
"mode",
"rules"
],
"additionalProperties": false
},
"interactionPolicy": {
"type": "string",
"enum": [
"safe",
"stateful"
]
},
"boundaries": {
"type": "string",
"maxLength": 1000
},
"idempotencyKey": {
"type": "string",
"minLength": 8,
"maxLength": 128
}
},
"required": [
"workspaceSlug",
"assetId",
"depth",
"coverage",
"interactionPolicy",
"idempotencyKey"
],
"additionalProperties": false
}🔴launch_assessment(workspaceSlug, assessmentId, idempotencyKey)
Consume a recent human approval and submit the immutable assessment to Hacker Bob's managed queue. The target is resolved only from the stored verified asset.
Input Schema
{
"type": "object",
"properties": {
"workspaceSlug": {
"type": "string",
"minLength": 1,
"maxLength": 80,
"pattern": "^[a-z0-9]+(?:-[a-z0-9]+)*$",
"description": "Workspace slug selected during agent authorization."
},
"assessmentId": {
"type": "string",
"minLength": 1,
"maxLength": 128
},
"idempotencyKey": {
"type": "string",
"minLength": 8,
"maxLength": 128
}
},
"required": [
"workspaceSlug",
"assessmentId",
"idempotencyKey"
],
"additionalProperties": false
}🔴cancel_assessment(workspaceSlug, assessmentId, idempotencyKey)
Cancel an eligible queued or running assessment and reconcile any refundable reserved credit.
Input Schema
{
"type": "object",
"properties": {
"workspaceSlug": {
"type": "string",
"minLength": 1,
"maxLength": 80,
"pattern": "^[a-z0-9]+(?:-[a-z0-9]+)*$",
"description": "Workspace slug selected during agent authorization."
},
"assessmentId": {
"type": "string",
"minLength": 1,
"maxLength": 128
},
"idempotencyKey": {
"type": "string",
"minLength": 8,
"maxLength": 128
}
},
"required": [
"workspaceSlug",
"assessmentId",
"idempotencyKey"
],
"additionalProperties": false
}🟢list_findings(workspaceSlug, status, severity, assetId)
List workspace findings with optional lifecycle and severity filters.
Input Schema
{
"type": "object",
"properties": {
"workspaceSlug": {
"type": "string",
"minLength": 1,
"maxLength": 80,
"pattern": "^[a-z0-9]+(?:-[a-z0-9]+)*$",
"description": "Workspace slug selected during agent authorization."
},
"status": {
"type": "string",
"maxLength": 40
},
"severity": {
"type": "string",
"enum": [
"critical",
"high",
"medium",
"low"
]
},
"assetId": {
"type": "string",
"minLength": 1,
"maxLength": 128
}
},
"required": [
"workspaceSlug"
],
"additionalProperties": false
}🟢get_finding(workspaceSlug, findingId)
Return one finding with evidence-safe lifecycle history and related asset metadata.
Input Schema
{
"type": "object",
"properties": {
"workspaceSlug": {
"type": "string",
"minLength": 1,
"maxLength": 80,
"pattern": "^[a-z0-9]+(?:-[a-z0-9]+)*$",
"description": "Workspace slug selected during agent authorization."
},
"findingId": {
"type": "string",
"minLength": 1,
"maxLength": 128
}
},
"required": [
"workspaceSlug",
"findingId"
],
"additionalProperties": false
}🟢list_reports(workspaceSlug)
List non-revoked reports released to the approved workspace.
Input Schema
{
"type": "object",
"properties": {
"workspaceSlug": {
"type": "string",
"minLength": 1,
"maxLength": 80,
"pattern": "^[a-z0-9]+(?:-[a-z0-9]+)*$",
"description": "Workspace slug selected during agent authorization."
}
},
"required": [
"workspaceSlug"
],
"additionalProperties": false
}🟢get_report(workspaceSlug, reportId)
Return one released, non-revoked workspace report. Pending review material and access credentials are never returned.
Input Schema
{
"type": "object",
"properties": {
"workspaceSlug": {
"type": "string",
"minLength": 1,
"maxLength": 80,
"pattern": "^[a-z0-9]+(?:-[a-z0-9]+)*$",
"description": "Workspace slug selected during agent authorization."
},
"reportId": {
"type": "string",
"minLength": 1,
"maxLength": 128
}
},
"required": [
"workspaceSlug",
"reportId"
],
"additionalProperties": false
}🟢get_credit_summary(workspaceSlug)
Return available, reserved, and used assessment credits for the approved workspace.
Input Schema
{
"type": "object",
"properties": {
"workspaceSlug": {
"type": "string",
"minLength": 1,
"maxLength": 80,
"pattern": "^[a-z0-9]+(?:-[a-z0-9]+)*$",
"description": "Workspace slug selected during agent authorization."
}
},
"required": [
"workspaceSlug"
],
"additionalProperties": false
}🟢list_audit_events(workspaceSlug, actor, action, fromAt, toAt)
List recent workspace audit events with optional actor, action, and time filters.
Input Schema
{
"type": "object",
"properties": {
"workspaceSlug": {
"type": "string",
"minLength": 1,
"maxLength": 80,
"pattern": "^[a-z0-9]+(?:-[a-z0-9]+)*$",
"description": "Workspace slug selected during agent authorization."
},
"actor": {
"type": "string",
"maxLength": 254
},
"action": {
"type": "string",
"maxLength": 80
},
"fromAt": {
"type": "number",
"minimum": 0
},
"toAt": {
"type": "number",
"minimum": 0
}
},
"required": [
"workspaceSlug"
],
"additionalProperties": false
}Community
Evidence