{"repo":"vmihalis/hacker-bob","free":true,"listed":false,"github":"https://github.com/vmihalis/hacker-bob","clone":"git clone https://github.com/vmihalis/hacker-bob.git","description":"A local MCP runtime that attacks what you own and only reports what it proved. 17 CVEs across 9 projects came out of this repo. Install: npx -y hacker-bob@latest install /path/to/project, then run /bob-evaluate target.com","language":"JavaScript","stars":97,"topics":["appsec","claude-code","cve","fuzzing","mcp","model-context-protocol","offensive-security","pentesting","security","smart-contract-security"],"license":"Apache-2.0","category":"mcp-servers","readme_excerpt":"Hacker Bob Offensive security you run yourself — a local MCP workflow for authorized testing, in CI or against staging. Hacker Bob installs a local MCP runtime into a project directory and connects it to Claude Code, Codex, Kimi CLI, or another MCP-capable host. The runtime coordinates surface mapping, authentication setup, parallel surface testing, finding verification, grading, reporting, and local evidence handling. Bob runs offensive security on surfaces you control — your own code in CI, your staging and authorized live targets. It can send real network requests, run local surface-discovery tools, import local artifacts, and preserve sensitive run data on disk. You are responsible for using it only where you have permission. Quickstart Choose the project directory where you want to run Bob. Install into that project, not into this source checkout unless you are developing Bob itself. Restart your host CLI from the same project directory, then run the matching command: Host Command --- --- Claude Code /bob-evaluate target.com Codex $bob-evaluate target.com Kimi CLI /skill:bob-evaluate target.com Generic MCP host Connect the generated .mcp.json , then follow .hacker-bob/generic-mcp/hacker-bob.md . Run a status check before a full evaluation if you want to confirm the integration is loaded: Host Status command --- --- Claude Code /bob-status Codex $bob-status Kimi CLI /skill:bob-status Shell hacker-bob doctor /path/to/your/project Safety Only run Bob against targets, accoun","default_branch":null,"files":null,"tree":[],"storefront":"/r/vmihalis","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/vmihalis/hacker-bob/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}