Hacker Bob Security Evaluator
Under maintenancePricing
from $500,000.00 / 1,000 results
Hacker Bob Security Evaluator
Under maintenanceAuthorized-scope autonomous web-app security evaluator (recon, HTTP, headless-browser only) driving the unmodified Hacker Bob MCP engine. Ships a self-contained loopback demo that runs out of the box. Offensive Docker tooling stays dormant; model access is keyless via Apify's OpenRouter proxy.
Pricing
from $500,000.00 / 1,000 results
Rating
0.0
(0)
Developer
Hacker Bob
Maintained by CommunityActor stats
0
Bookmarked
2
Total users
1
Monthly active users
15 days ago
Last modified
Categories
Share
Hacker Bob — Authorized Web-App Security Evaluator
Point it at your own running app, live API, or PR surface → an autonomous recon → HTTP → headless-browser security evaluation, sealed into one signed report.
🌐 Website: hackerbob.ai
The official Hacker Bob engine, packaged for Apify.
💵 $500 per result
One signed report per completed run — $500 per completed evaluation. A run that delivers no report (rejected input, or a failure before the report) writes no result and is not charged.
What it does
Give it a target you're authorized to test; it maps the live surface, probes HTTP, drives a headless browser, verifies findings, grades, and delivers a signed report — fully autonomous, over the official Hacker Bob MCP engine.
- 🎯 Your target — a running app, live API, or PR/review URL. Not a repo to clone.
- 🔏 One signed result —
report.md+ evidence to the key-value store, one structured dataset row (grade, severity, top finding). - 🧱 Web-only — repo-review and smart-contract/RPC tooling is removed at the tool layer; it can only reach the live surface you point it at.
Quick start
- Set Target URL to a web app / API / PR you own or may test.
- Tick I am authorized to security-test this target.
- Start (defaults are fine).
No target? Enable Try the built-in demo instead for a self-contained sample run (bills the same $500).
Input
| Field | Default | Meaning |
|---|---|---|
target | (empty) | Your authorized web app / API / PR URL. |
confirmAuthorizedTarget | false | Attestation — required for any non-loopback target. |
useDemoTarget | false | Run the built-in loopback demo instead. |
modelProvider | apify-openrouter | Inference route: keyless (default), or BYO anthropic / openrouter key. |
modelApiKey | (empty) | Your key — only for anthropic / openrouter. Secret, never logged. |
budget | 2 | Max model spend, USD. Clamped [0, 20]. |
timeout | 780 | Invocation timeout (s), clamped [1, 43200]. Bob's pipeline runs for hours; latest snapshot is salvaged on timeout. |
mode | normal | paranoid adds private-address egress blocking. |
Scope & authorization
Authorization is your responsibility — Bob probes any target you give him and does not verify permission. Only run against a system you own, an active bug-bounty scope, or a written pentest agreement. A non-demo target without confirmAuthorizedTarget is refused before any spend, and the per-run domain pin prevents a prompt-injected model from pivoting to another host. Unauthorized access is a crime in most jurisdictions (US CFAA, EU 2013/40/EU, UK CMA 1990).
Provenance
The official hackerbob.ai engine (vmihalis/hacker-bob, Apache-2.0), vendored byte-identical except a per-run target pin and a BOB_APIFY_WEB_ONLY tool-family filter. No offensive capability added — only removed or infra-starved.
Official Hacker Bob — hackerbob.ai · authorized testing only · $500 per result


