h1-brain brings HackerOne context to local MCP clients
Patrik Grobshäuser’s open-source h1-brain is a local Python MCP server that syncs a researcher’s HackerOne history into SQLite and ships a searchable database of more than 3,600 bounty-awarded public disclosures. It briefs AI clients; it is not a vulnerability scanner and has no CVE.
Published 6 Oct 2026
What happened
Patrik Grobshäuser (GitHub PatrikFehrenbach) published h1-brain, an MIT-licensed Python MCP server that connects MCP-compatible assistants to HackerOne. The project description on GitHub is an MCP server for bug bounty hunting context. The repository was created on 10 March 2026. As of this check it had no GitHub Releases or tags, hundreds of stars, and a last code push in early April 2026.
This note is about researcher tooling. There is no CVE for h1-brain, and ThreatWire is not recording a vulnerability.
Who is affected
Nobody is “affected” in the vulnerability sense. The audience is bug bounty researchers who already have a HackerOne account, a HackerOne API token, Python 3.10 or newer, and an MCP client such as Claude Desktop or Claude Code. Operators who do not hunt on HackerOne have nothing to install. Sites and vendors are not the subject of this record.
What is confirmed
The README and server.py expose twelve MCP tools. Sync tools pull rewarded reports, accessible programs, and program scopes from the HackerOne API into a local h1_data.db SQLite file. Personal search tools query that database without further API calls. fetch_attachment returns fresh temporary HackerOne download URLs for report attachments. Public tools query disclosed_reports.db, which ships in the repository via Git LFS.
ThreatWire downloaded the LFS object for disclosed_reports.db (about 17 MB) and counted 3,673 rows in the disclosed_reports table, with a matching SQLite FTS index. That matches the README claim of more than 3,600 bounty-awarded public disclosures that include vulnerability write-ups.
The primary tool hack(handle) builds a single briefing: fresh scope from the API, the researcher’s past findings on that program, weakness patterns, bounty-eligible assets with no personal findings, public disclosures for the program, and suggested attack vectors framed as heuristics for the assistant. The project states it uses both personal and public data for that briefing. Dependencies listed in the repository are the mcp and httpx packages. The LICENSE names Patrik Grobshäuser under MIT (2026).
What is not confirmed
ThreatWire did not run h1-brain against a live HackerOne account and did not verify that every disclosed-row write-up is complete or current. A normal git clone without Git LFS leaves a pointer file instead of the 17 MB database; the README’s “no extra setup” claim assumes LFS content is present. Suggested attack vectors are heuristics, not confirmed bugs. The tool does not claim to scan or exploit remote targets by itself. There are no GitHub release artifacts to pin a version. Social posts that frame h1-brain as a vulnerability or as automatic exploitation overstate what the repository documents.
What to do
Researchers who want local HackerOne context in an MCP client can evaluate the public repository, review the MIT license, and follow the author’s setup documentation with their own API credentials. Treat briefing output as research notes, not as proof of a finding. Do not paste API tokens into shared chats or public configs. Program owners and defenders have no patch action for this announcement.
Sources: the h1-brain GitHub repository, its README, MIT LICENSE, and a direct count of the shipped disclosed_reports.db LFS object.