ASMHunter MCP server
Drive ASMHunter attack-surface monitoring from an AI agent: recon, scans, findings, reports.
Little public usage data yet
Reviews
Write oneNobody has reviewed ASMHunter yet.
If you have run it, two minutes of your experience saves the next person an afternoon.
ASMHunter tools (34, 9 write)
write = sends, deletes, buys or postsRead from the package source without running it. The installed server may list more.
add_findingLog a confirmed finding (promote to a report later). method/url = request context; tags = labels; chain_id = link entries into one exploit chain; retest_at = ISO time to revisit.
add_leadLog a lead (a promising-but-unconfirmed angle). method/tags/chain_id/retest_at supported.
add_noteAdd a working note (recon synthesis, blockers, resume info). method/tags/chain_id/retest_at supported.
add_testedRecord a tested-and-clear surface so you don't retest it. method/tags/chain_id/retest_at supported.
add_winLog a bounty win. Pass vulnerability_id/report_id/target_id to link it (sets surfaced_by_asmhunter when a product finding is referenced).
bulk_add_entriesAdd many entries at once. Each: {type,title,body?,severity?,target_id?,url?}.
create_sessionwrite actionStart a hunt session (program-anchored or freeform). Auto-links the program's targets. Pass `goal` to state the objective for this session (e.g. "find IDOR in the billing API"). It is stored and returned by get_session, so you can keep the session focused on it.
create_targetwrite actionAdd a scan target (optionally linked to a program).
delete_entrywrite actionDelete an entry.
delete_reportwrite actionDelete a report draft.
delete_sessionwrite actionDelete a session and its entries.
draft_reportwrite actionCreate a report draft (vuln_class one of: xss,idor,ssrf,sqli,ssti,xxe,csrf,oauth,default_credentials,info_disclosure,rce,open_redirect).
get_findingsYour vulnerability findings (filter by severity/search).
get_my_statsYour hunt stats: sessions, entry breakdown, per-program activity.
get_programFull program detail + scope. `program` is a program_id (UUID) OR a handle (e.g. 'shopify'). Pass `platform` to disambiguate a handle shared across platforms. (Find ids/handles via search_programs / recommend_programs.)
get_scan_statusStatus of a scan run.
get_scope_changesRecent scope additions/removals across tracked programs.
get_sessionA session with all its entries + linked targets.
get_value_receiptWhat ASMHunter surfaced for you (30d) + your logged-win totals. Use this to ground recommendations in the user's actual monitored surface.
get_watchlistYour watched programs with full metrics (bounties, dupe, health, scope) + prior_sessions per program. Use to resume hunting on programs you track.
list_assetsDiscovered assets/hosts (filter by target/search).
list_entriesList a session's entries (optionally one type).
list_reportsList your report drafts/submissions.
list_sessionsList your hunt sessions (filter by active/paused/completed).
list_targetsYour scan targets.
list_winsList the user's logged bounty wins (private, self-reported).
list_workflowsAvailable scan workflows: each item has workflow_id + display_name + description + tier lock. Call this BEFORE trigger_scan to choose a valid workflow_id (e.g. recon, subdomain enumeration, vuln scan, JS secrets).
promote_entryPromote a finding entry into a report draft. Returns {report_id}.
recommend_programsRanked program recommendations with reasons (opportunity, dupe, health, prior sessions).
search_programsSearch bug-bounty programs by name.
trigger_scanQueue a real scan (pro+, consumes scan quota). Re-call with confirm=true to actually run it.
update_entrywrite actionUpdate an entry (close a lead, set severity, tag, schedule retest, link a chain).
update_reportwrite actionUpdate a report draft (pass the fields to change).
update_sessionwrite actionUpdate a session (title/status/notes/goal/time).
Public scan report
scanner v0.1.9 · 2026-09-26 · same rubric, same numbers if you re-run it
- Code scan10 source files scanned25/25
- –Live reliabilityno gateway calls yet and no remote to proben/a
- –Tool poisoningtools not inspected (local package is not executed); not countedn/a
- Auth qualitystatic API keys via environment variables6/15
- Maintenancerepository not readable: unknown3/15
- Maintainer identityverified namespace with website, no repo4/10
Install directly
claude mcp add asmhunter-mcp -- uvx asmhunter-mcp
ASMHunter: common questions
- Is ASMHunter MCP server safe?
- With care: it is graded C, so read the findings first (58/100). Read the ASMHunter safety report
- How do I install ASMHunter?
- It runs on your machine. Copy the Claude Code, Claude Desktop or Cursor config from the install section.
- Does ASMHunter need an API key?
- Yes. The registry entry asks for
ASMHUNTER_TOKEN. - Is ASMHunter maintained?
- The latest release is v0.1.2.
- What can I use instead of ASMHunter?
- Servers from other publishers that do the same job: Argent MCP server, Flutter MCP Toolkit MCP server and Omnidim MCP server. Compare all ASMHunter alternatives.
Alternatives to ASMHunter
Same job from other publishers: the closest match first, then the best rated.
- ArgentDrive iOS Simulators, Android emulators, TVs and Electron/web apps from your coding agentnot reviewedWidely usedA
Flutter MCP ToolkitInspect and drive Flutter debug apps/games: semantic snapshots, search, and custom client toolsnot reviewedGrowingA- OmnidimOfficial MCP server for OmniDimension. Drive voice agents, dispatch calls, and run bulk campaigns.not reviewedGrowingA
- HunchFocus-free macOS control for AI agents: drive your real Mac apps in the background, no stolen focus.not reviewedGrowingA
DOMShellDrive Chrome with filesystem commands (ls, cd, grep, click, type). One MCP tool, multi-agent.not reviewedGrowingA