MCPサーバー

Hacker Bob public records

io.github.bobnetsec/hacker-bob-public-records
セキュリティ 公開・接続可能 MCP 2026-07-28

このMCPでできること

Manages authorized security assessments and findings while exposing public CVE records, asset authorization, reports, approvals, credits, and audit history.

begin_domain_authorization
Begin domain authorization
Create a DNS TXT or HTTPS-file challenge proving control of a domain. This does not run an assessment.
冪等
入力スキーマ
{'type': 'object', 'required': ['workspaceSlug', 'domain', 'method', 'idempotencyKey'], 'properties': {'label': {'type': 'string', 'maxLength': 120, 'minLength': 1}, 'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'Domain name only; no scheme, path, port, credentials, or wildcard.'}, 'method': {'enum': ['dns_txt', 'http_file'], 'type': 'string'}, 'workspaceSlug': {'type': 'string', 'pattern': '^[a-z0-9]+(?:-[a-z0-9]+)*$', 'maxLength': 80, 'minLength': 1, 'description': 'Workspace slug selected during agent authorization.'}, 'idempotencyKey': {'type': 'string', 'maxLength': 128, 'minLength': 8}}, 'additionalProperties': False}
cancel_assessment
Cancel assessment
Cancel an eligible queued or running assessment and reconcile any refundable reserved credit.
破壊的操作あり 冪等
入力スキーマ
{'type': 'object', 'required': ['workspaceSlug', 'assessmentId', 'idempotencyKey'], 'properties': {'assessmentId': {'type': 'string', 'maxLength': 128, 'minLength': 1}, 'workspaceSlug': {'type': 'string', 'pattern': '^[a-z0-9]+(?:-[a-z0-9]+)*$', 'maxLength': 80, 'minLength': 1, 'description': 'Workspace slug selected during agent authorization.'}, 'idempotencyKey': {'type': 'string', 'maxLength': 128, 'minLength': 8}}, 'additionalProperties': False}
check_domain_authorization
Check domain authorization
Check the previously issued DNS or HTTPS proof and update the asset authorization state.
外部アクセスあり 冪等
入力スキーマ
{'type': 'object', 'required': ['workspaceSlug', 'authorizationId', 'idempotencyKey'], 'properties': {'workspaceSlug': {'type': 'string', 'pattern': '^[a-z0-9]+(?:-[a-z0-9]+)*$', 'maxLength': 80, 'minLength': 1, 'description': 'Workspace slug selected during agent authorization.'}, 'idempotencyKey': {'type': 'string', 'maxLength': 128, 'minLength': 8}, 'authorizationId': {'type': 'string', 'maxLength': 128, 'minLength': 1}}, 'additionalProperties': False}
get_assessment
Get assessment
Return one assessment, its verified asset, current run state, and any pending human approval.
読み取り専用 冪等
入力スキーマ
{'type': 'object', 'required': ['workspaceSlug', 'assessmentId'], 'properties': {'assessmentId': {'type': 'string', 'maxLength': 128, 'minLength': 1}, 'workspaceSlug': {'type': 'string', 'pattern': '^[a-z0-9]+(?:-[a-z0-9]+)*$', 'maxLength': 80, 'minLength': 1, 'description': 'Workspace slug selected during agent authorization.'}}, 'additionalProperties': False}
get_asset
Get authorized asset
Return one workspace asset and its current authorization state.
読み取り専用 冪等
入力スキーマ
{'type': 'object', 'required': ['workspaceSlug', 'assetId'], 'properties': {'assetId': {'type': 'string', 'maxLength': 128, 'minLength': 1}, 'workspaceSlug': {'type': 'string', 'pattern': '^[a-z0-9]+(?:-[a-z0-9]+)*$', 'maxLength': 80, 'minLength': 1, 'description': 'Workspace slug selected during agent authorization.'}}, 'additionalProperties': False}
get_capabilities
Get Hacker Bob capabilities
Return current public boundaries and, when authenticated, workspace-specific tool reachability, scopes, and role requirements.
読み取り専用 冪等
入力スキーマ
{'type': 'object', 'required': [], 'properties': {}, 'additionalProperties': False}
get_credit_summary
Get credit summary
Return available, reserved, and used assessment credits for the approved workspace.
読み取り専用 冪等
入力スキーマ
{'type': 'object', 'required': ['workspaceSlug'], 'properties': {'workspaceSlug': {'type': 'string', 'pattern': '^[a-z0-9]+(?:-[a-z0-9]+)*$', 'maxLength': 80, 'minLength': 1, 'description': 'Workspace slug selected during agent authorization.'}}, 'additionalProperties': False}
get_finding
Get finding
Return one finding with evidence-safe lifecycle history and related asset metadata.
読み取り専用 冪等
入力スキーマ
{'type': 'object', 'required': ['workspaceSlug', 'findingId'], 'properties': {'findingId': {'type': 'string', 'maxLength': 128, 'minLength': 1}, 'workspaceSlug': {'type': 'string', 'pattern': '^[a-z0-9]+(?:-[a-z0-9]+)*$', 'maxLength': 80, 'minLength': 1, 'description': 'Workspace slug selected during agent authorization.'}}, 'additionalProperties': False}
get_my_account
Get my Hacker Bob account
Return the authenticated account and the workspace bound to this agent connection.
読み取り専用 冪等
入力スキーマ
{'type': 'object', 'required': [], 'properties': {}, 'additionalProperties': False}
get_public_cve_record
Get one public CVE record
Return one cleared Hacker Bob CVE record by identifier, including its open-source project, publication status, and upstream public record URL when available.
読み取り専用 冪等
入力スキーマ
{'type': 'object', 'required': ['recordId'], 'properties': {'recordId': {'type': 'string', 'pattern': '^CVE-[0-9]{4}-[0-9]+$', 'description': 'CVE identifier such as CVE-2026-47747.'}}, 'additionalProperties': False}
get_report
Get released report
Return one released, non-revoked workspace report. Pending review material and access credentials are never returned.
読み取り専用 冪等
入力スキーマ
{'type': 'object', 'required': ['workspaceSlug', 'reportId'], 'properties': {'reportId': {'type': 'string', 'maxLength': 128, 'minLength': 1}, 'workspaceSlug': {'type': 'string', 'pattern': '^[a-z0-9]+(?:-[a-z0-9]+)*$', 'maxLength': 80, 'minLength': 1, 'description': 'Workspace slug selected during agent authorization.'}}, 'additionalProperties': False}
get_workspace
Get workspace
Return the approved workspace and current membership role.
読み取り専用 冪等
入力スキーマ
{'type': 'object', 'required': ['workspaceSlug'], 'properties': {'workspaceSlug': {'type': 'string', 'pattern': '^[a-z0-9]+(?:-[a-z0-9]+)*$', 'maxLength': 80, 'minLength': 1, 'description': 'Workspace slug selected during agent authorization.'}}, 'additionalProperties': False}
launch_assessment
Submit approved assessment
Consume a recent human approval and submit the immutable assessment to Hacker Bob's managed queue. The target is resolved only from the stored verified asset.
破壊的操作あり 外部アクセスあり 冪等
入力スキーマ
{'type': 'object', 'required': ['workspaceSlug', 'assessmentId', 'idempotencyKey'], 'properties': {'assessmentId': {'type': 'string', 'maxLength': 128, 'minLength': 1}, 'workspaceSlug': {'type': 'string', 'pattern': '^[a-z0-9]+(?:-[a-z0-9]+)*$', 'maxLength': 80, 'minLength': 1, 'description': 'Workspace slug selected during agent authorization.'}, 'idempotencyKey': {'type': 'string', 'maxLength': 128, 'minLength': 8}}, 'additionalProperties': False}
list_assessments
List assessments
List assessments and current run states in the approved workspace.
読み取り専用 冪等
入力スキーマ
{'type': 'object', 'required': ['workspaceSlug'], 'properties': {'workspaceSlug': {'type': 'string', 'pattern': '^[a-z0-9]+(?:-[a-z0-9]+)*$', 'maxLength': 80, 'minLength': 1, 'description': 'Workspace slug selected during agent authorization.'}, 'includeArchived': {'type': 'boolean'}}, 'additionalProperties': False}
list_assets
List authorized assets
List workspace assets and current ownership-authorization state without contacting a target.
読み取り専用 冪等
入力スキーマ
{'type': 'object', 'required': ['workspaceSlug'], 'properties': {'workspaceSlug': {'type': 'string', 'pattern': '^[a-z0-9]+(?:-[a-z0-9]+)*$', 'maxLength': 80, 'minLength': 1, 'description': 'Workspace slug selected during agent authorization.'}, 'includeArchived': {'type': 'boolean', 'description': 'Include archived assets. Defaults to false.'}}, 'additionalProperties': False}
list_audit_events
List audit events
List recent workspace audit events with optional actor, action, and time filters.
読み取り専用 冪等
入力スキーマ
{'type': 'object', 'required': ['workspaceSlug'], 'properties': {'toAt': {'type': 'number', 'minimum': 0}, 'actor': {'type': 'string', 'maxLength': 254}, 'action': {'type': 'string', 'maxLength': 80}, 'fromAt': {'type': 'number', 'minimum': 0}, 'workspaceSlug': {'type': 'string', 'pattern': '^[a-z0-9]+(?:-[a-z0-9]+)*$', 'maxLength': 80, 'minLength': 1, 'description': 'Workspace slug selected during agent authorization.'}}, 'additionalProperties': False}
list_findings
List findings
List workspace findings with optional lifecycle and severity filters.
読み取り専用 冪等
入力スキーマ
{'type': 'object', 'required': ['workspaceSlug'], 'properties': {'status': {'type': 'string', 'maxLength': 40}, 'assetId': {'type': 'string', 'maxLength': 128, 'minLength': 1}, 'severity': {'enum': ['critical', 'high', 'medium', 'low'], 'type': 'string'}, 'workspaceSlug': {'type': 'string', 'pattern': '^[a-z0-9]+(?:-[a-z0-9]+)*$', 'maxLength': 80, 'minLength': 1, 'description': 'Workspace slug selected during agent authorization.'}}, 'additionalProperties': False}
list_public_cve_records
List public CVE records
List cleared public Hacker Bob Common Vulnerabilities and Exposures records with cursor pagination and optional project or publication-status filters.
読み取り専用 冪等
入力スキーマ
{'type': 'object', 'required': [], 'properties': {'limit': {'type': 'integer', 'maximum': 100, 'minimum': 1, 'description': 'Maximum records to return. Defaults to 20.'}, 'cursor': {'type': 'string', 'description': 'Opaque cursor returned by a previous list call.'}, 'status': {'enum': ['public', 'assigned-no-public-record'], 'type': 'string', 'description': 'Publication status to include.'}, 'project': {'type': 'string', 'description': 'Exact open-source project name to include.'}}, 'additionalProperties': False}
list_reports
List released reports
List non-revoked reports released to the approved workspace.
読み取り専用 冪等
入力スキーマ
{'type': 'object', 'required': ['workspaceSlug'], 'properties': {'workspaceSlug': {'type': 'string', 'pattern': '^[a-z0-9]+(?:-[a-z0-9]+)*$', 'maxLength': 80, 'minLength': 1, 'description': 'Workspace slug selected during agent authorization.'}}, 'additionalProperties': False}
list_workspaces
List my workspaces
List active Hacker Bob workspaces available to the authenticated account. The connection remains bound to its approved workspace.
読み取り専用 冪等
入力スキーマ
{'type': 'object', 'required': [], 'properties': {}, 'additionalProperties': False}
prepare_assessment
Prepare assessment
Create an immutable assessment for a verified stored asset and return a browser approval URL. This never contacts the target.
冪等
入力スキーマ
{'type': 'object', 'required': ['workspaceSlug', 'assetId', 'depth', 'coverage', 'interactionPolicy', 'idempotencyKey'], 'properties': {'depth': {'enum': ['standard', 'deep'], 'type': 'string'}, 'assetId': {'type': 'string', 'maxLength': 128, 'minLength': 1}, 'coverage': {'type': 'object', 'required': ['mode', 'rules'], 'properties': {'mode': {'enum': ['all', 'exclude', 'include'], 'type': 'string'}, 'rules': {'type': 'array', 'items': {'type': 'string', 'maxLength': 240, 'minLength': 1}, 'maxItems': 100}}, 'additionalProperties': False}, 'boundaries': {'type': 'string', 'maxLength': 1000}, 'workspaceSlug': {'type': 'string', 'pattern': '^[a-z0-9]+(?:-[a-z0-9]+)*$', 'maxLength': 80, 'minLength': 1, 'description': 'Workspace slug selected during agent authorization.'}, 'idempotencyKey': {'type': 'string', 'maxLength': 128, 'minLength': 8}, 'interactionPolicy': {'enum': ['safe', 'stateful'], 'type': 'string'}}, 'additionalProperties': False}
search_public_cve_records
Search public CVE records
Search cleared public Hacker Bob CVE records by CVE identifier, open-source project name, or publication status without contacting any assessment target.
読み取り専用 冪等
入力スキーマ
{'type': 'object', 'required': ['query'], 'properties': {'limit': {'type': 'integer', 'maximum': 50, 'minimum': 1, 'description': 'Maximum matching records to return. Defaults to 20.'}, 'query': {'type': 'string', 'minLength': 1, 'description': 'Text to match against CVE identifiers, project names, and publication status.'}}, 'additionalProperties': False}
追加
list_audit_events
2026年9月17日12:40
追加
get_credit_summary
2026年9月17日12:40
追加
get_report
2026年9月17日12:40
追加
list_reports
2026年9月17日12:40
追加
get_finding
2026年9月17日12:40
追加
list_findings
2026年9月17日12:40
追加
cancel_assessment
2026年9月17日12:40
追加
launch_assessment
2026年9月17日12:40
追加
prepare_assessment
2026年9月17日12:40
追加
get_assessment
2026年9月17日12:40
追加
list_assessments
2026年9月17日12:40
追加
check_domain_authorization
2026年9月17日12:40
追加
begin_domain_authorization
2026年9月17日12:40
追加
get_asset
2026年9月17日12:40
追加
list_assets
2026年9月17日12:40
追加
get_workspace
2026年9月17日12:40
追加
list_workspaces
2026年9月17日12:40
追加
get_my_account
2026年9月17日12:40
追加
get_capabilities
2026年9月17日12:40
追加
search_public_cve_records
2026年9月17日12:40
追加
get_public_cve_record
2026年9月17日12:40
追加
list_public_cve_records
2026年9月17日12:40