Smart contract security scanner trained on 27,681 real audit findings. $5 USDC on Base.
Smart contract security scanner trained on 27,681 real audit findings. $5 USDC on Base. That is what the bug bounty intelligence mcp server brings to an AI assistant: the same capability, reachable through the Model Context Protocol rather than a separate app or dashboard.
AI-powered smart contract security analysis for AI agents and developers.
The server publishes 3 tools. What each one is for:
scan_contract — Submit repo for security analysisget_scan_report — Poll status and get report URLlist_vulnerability_patterns — Show acceptance rates from exact-reconciled Sherlock contestsThe server ships on npm as bug-bounty-intelligence-mcp, so your MCP client can launch it on demand — there is no separate build step. Add the server block to your client's configuration, restart it, and the tools register themselves.
Among the developer tooling options, the useful question is rarely "what can it do" but "what does it cost you to run" — permissions, credentials, and how much of your context its toolset consumes. Bug Bounty Intelligence's toolset — scan_contract, get_scan_report, list_vulnerability_patterns — is a fair guide to whether it matches your workflow. It is maintained by holistis; worth a glance at recent repository activity before you build anything load-bearing on it.
This entry was verified against Bug Bounty Intelligence's own documentation before publication; SyncDev keeps the directory reviewed rather than auto-generated.
| Tool | What it does |
|---|---|
| scan_contract | Submit repo for security analysis |
| get_scan_report | Poll status and get report URL |
| list_vulnerability_patterns | Show acceptance rates from exact-reconciled Sherlock contests |
{
"mcpServers": {
"bug-bounty-intelligence": {
"command": "npx",
"args": ["-y", "bug-bounty-intelligence-mcp@latest"]
}
}
}Configuration as documented by the project. Restart the client after saving.
Kill hallucinated APIs — version-accurate, up-to-date library documentation injected straight into context.
Microsoft's official browser automation server — drive a real browser through the accessibility tree, no screenshots needed.
GitHub's official server — repos, issues, pull requests, Actions and code security, straight from your assistant.
Issue tracking at the speed of conversation — Linear's official hosted server with OAuth and zero install.
Local repository surgery — status, diffs, commits, branches and history for any repo on disk.
Timezone sanity for AI — current time anywhere and correct conversions, without the model doing date math.