{"name":"hacker-bob","version":"1.0.0","protocolVersion":"2025-11-25","transport":"streamable-http","endpoint":"https://hackerbob.ai/mcp","authentication":{"type":"oauth2_or_device_authorization","protectedResourceMetadata":"https://hackerbob.ai/.well-known/oauth-protected-resource"},"tools":[{"name":"list_public_cve_records","description":"List cleared public Hacker Bob Common Vulnerabilities and Exposures records with cursor pagination and optional project or publication-status filters."},{"name":"get_public_cve_record","description":"Return one cleared Hacker Bob CVE record by identifier, including its open-source project, publication status, and upstream public record URL when available."},{"name":"search_public_cve_records","description":"Search cleared public Hacker Bob CVE records by CVE identifier, open-source project name, or publication status without contacting any assessment target."},{"name":"get_capabilities","description":"Return current public boundaries and, when authenticated, workspace-specific tool reachability, scopes, and role requirements."},{"name":"get_my_account","description":"Return the authenticated account and the workspace bound to this agent connection."},{"name":"list_workspaces","description":"List active Hacker Bob workspaces available to the authenticated account. The connection remains bound to its approved workspace."},{"name":"get_workspace","description":"Return the approved workspace and current membership role."},{"name":"list_assets","description":"List workspace assets and current ownership-authorization state without contacting a target."},{"name":"get_asset","description":"Return one workspace asset and its current authorization state."},{"name":"begin_domain_authorization","description":"Create a DNS TXT or HTTPS-file challenge proving control of a domain. This does not run an assessment."},{"name":"check_domain_authorization","description":"Check the previously issued DNS or HTTPS proof and update the asset authorization state."},{"name":"list_assessments","description":"List assessments and current run states in the approved workspace."},{"name":"get_assessment","description":"Return one assessment, its verified asset, current run state, and any pending human approval."},{"name":"prepare_assessment","description":"Create an immutable assessment for a verified stored asset and return a browser approval URL. This never contacts the target."},{"name":"launch_assessment","description":"Consume a recent human approval and submit the immutable assessment to Hacker Bob's managed queue. The target is resolved only from the stored verified asset."},{"name":"cancel_assessment","description":"Cancel an eligible queued or running assessment and reconcile any refundable reserved credit."},{"name":"list_findings","description":"List workspace findings with optional lifecycle and severity filters."},{"name":"get_finding","description":"Return one finding with evidence-safe lifecycle history and related asset metadata."},{"name":"list_reports","description":"List non-revoked reports released to the approved workspace."},{"name":"get_report","description":"Return one released, non-revoked workspace report. Pending review material and access credentials are never returned."},{"name":"get_credit_summary","description":"Return available, reserved, and used assessment credits for the approved workspace."},{"name":"list_audit_events","description":"List recent workspace audit events with optional actor, action, and time filters."}],"resources":[{"uri":"hackerbob://public/cve-records","name":"public-cve-records","title":"Hacker Bob public CVE records","description":"Complete machine-readable index of cleared public CVE records and assigned IDs without public records.","mimeType":"application/json"},{"uri":"hackerbob://public/capabilities","name":"public-capabilities","title":"Hacker Bob public capabilities","description":"Read-only public API and MCP capabilities plus the explicit no-assessment-execution boundary.","mimeType":"application/json"},{"uri":"hackerbob://docs/agent-instructions","name":"agent-instructions","title":"Hacker Bob agent instructions","description":"When-to-use instructions and authorization boundaries for public records and the local runtime.","mimeType":"text/markdown"}]}