Mmcp.market

ASMHunter MCP server

by asmhunter.app·app.asmhunter/asmhunter-mcp·v0.1.2

Drive ASMHunter attack-surface monitoring from an AI agent: recon, scans, findings, reports.

C58/100grade C
What users say
No reviews yet
Be the first
Safety scan
C58/100

full report

Adoption
New

Little public usage data yet

Reviews

Write one

Nobody has reviewed ASMHunter yet.

If you have run it, two minutes of your experience saves the next person an afternoon.

ASMHunter tools (34, 9 write)

write = sends, deletes, buys or posts

Read from the package source without running it. The installed server may list more.

  • add_finding

    Log a confirmed finding (promote to a report later). method/url = request context; tags = labels; chain_id = link entries into one exploit chain; retest_at = ISO time to revisit.

  • add_lead

    Log a lead (a promising-but-unconfirmed angle). method/tags/chain_id/retest_at supported.

  • add_note

    Add a working note (recon synthesis, blockers, resume info). method/tags/chain_id/retest_at supported.

  • add_tested

    Record a tested-and-clear surface so you don't retest it. method/tags/chain_id/retest_at supported.

  • add_win

    Log a bounty win. Pass vulnerability_id/report_id/target_id to link it (sets surfaced_by_asmhunter when a product finding is referenced).

  • bulk_add_entries

    Add many entries at once. Each: {type,title,body?,severity?,target_id?,url?}.

  • create_sessionwrite action

    Start a hunt session (program-anchored or freeform). Auto-links the program's targets. Pass `goal` to state the objective for this session (e.g. "find IDOR in the billing API"). It is stored and returned by get_session, so you can keep the session focused on it.

  • create_targetwrite action

    Add a scan target (optionally linked to a program).

  • delete_entrywrite action

    Delete an entry.

  • delete_reportwrite action

    Delete a report draft.

  • delete_sessionwrite action

    Delete a session and its entries.

  • draft_reportwrite action

    Create a report draft (vuln_class one of: xss,idor,ssrf,sqli,ssti,xxe,csrf,oauth,default_credentials,info_disclosure,rce,open_redirect).

  • get_findings

    Your vulnerability findings (filter by severity/search).

  • get_my_stats

    Your hunt stats: sessions, entry breakdown, per-program activity.

  • get_program

    Full program detail + scope. `program` is a program_id (UUID) OR a handle (e.g. 'shopify'). Pass `platform` to disambiguate a handle shared across platforms. (Find ids/handles via search_programs / recommend_programs.)

  • get_scan_status

    Status of a scan run.

  • get_scope_changes

    Recent scope additions/removals across tracked programs.

  • get_session

    A session with all its entries + linked targets.

  • get_value_receipt

    What ASMHunter surfaced for you (30d) + your logged-win totals. Use this to ground recommendations in the user's actual monitored surface.

  • get_watchlist

    Your watched programs with full metrics (bounties, dupe, health, scope) + prior_sessions per program. Use to resume hunting on programs you track.

  • list_assets

    Discovered assets/hosts (filter by target/search).

  • list_entries

    List a session's entries (optionally one type).

  • list_reports

    List your report drafts/submissions.

  • list_sessions

    List your hunt sessions (filter by active/paused/completed).

  • list_targets

    Your scan targets.

  • list_wins

    List the user's logged bounty wins (private, self-reported).

  • list_workflows

    Available scan workflows: each item has workflow_id + display_name + description + tier lock. Call this BEFORE trigger_scan to choose a valid workflow_id (e.g. recon, subdomain enumeration, vuln scan, JS secrets).

  • promote_entry

    Promote a finding entry into a report draft. Returns {report_id}.

  • recommend_programs

    Ranked program recommendations with reasons (opportunity, dupe, health, prior sessions).

  • search_programs

    Search bug-bounty programs by name.

  • trigger_scan

    Queue a real scan (pro+, consumes scan quota). Re-call with confirm=true to actually run it.

  • update_entrywrite action

    Update an entry (close a lead, set severity, tag, schedule retest, link a chain).

  • update_reportwrite action

    Update a report draft (pass the fields to change).

  • update_sessionwrite action

    Update a session (title/status/notes/goal/time).

Public scan report

scanner v0.1.9 · 2026-09-26 · same rubric, same numbers if you re-run it

no findings
  • Code scan10 source files scanned25/25
  • –Live reliabilityno gateway calls yet and no remote to proben/a
  • –Tool poisoningtools not inspected (local package is not executed); not countedn/a
  • Auth qualitystatic API keys via environment variables6/15
  • Maintenancerepository not readable: unknown3/15
  • Maintainer identityverified namespace with website, no repo4/10
Overall 58/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON

Install directly

claude mcp add asmhunter-mcp -- uvx asmhunter-mcp
Add to Cursor

ASMHunter: common questions

Is ASMHunter MCP server safe?
With care: it is graded C, so read the findings first (58/100). Read the ASMHunter safety report
How do I install ASMHunter?
It runs on your machine. Copy the Claude Code, Claude Desktop or Cursor config from the install section.
Does ASMHunter need an API key?
Yes. The registry entry asks for ASMHUNTER_TOKEN.
Is ASMHunter maintained?
The latest release is v0.1.2.
What can I use instead of ASMHunter?
Servers from other publishers that do the same job: Argent MCP server, Flutter MCP Toolkit MCP server and Omnidim MCP server. Compare all ASMHunter alternatives.

Alternatives to ASMHunter

Same job from other publishers: the closest match first, then the best rated.

All ASMHunter alternatives →
  • Argent
    Drive iOS Simulators, Android emulators, TVs and Electron/web apps from your coding agent
    A
  • Flutter MCP Toolkit
    Inspect and drive Flutter debug apps/games: semantic snapshots, search, and custom client tools
    A
  • Omnidim
    Official MCP server for OmniDimension. Drive voice agents, dispatch calls, and run bulk campaigns.
    A
  • Hunch
    Focus-free macOS control for AI agents: drive your real Mac apps in the background, no stolen focus.
    A
  • DOMShell
    Drive Chrome with filesystem commands (ls, cd, grep, click, type). One MCP tool, multi-agent.
    A

More from asmhunter.app →