Rifteo Context MCP
MCP server that gives AI agents live bug bounty program scope and Rifteo security contexts - load the right knowledge before starting an engagement.
Install
pip install rifteo-context-mcp
Or from source:
git clone https://github.com/rifteo/context-mcp
cd context-mcp
pip install -e .
Register with your agent
Auto-install (all detected agents)
rifteo-context install
Single agent
rifteo-context install --agent claude-code
rifteo-context install --agent cursor
rifteo-context install --agent gemini-cli
Project-level install
rifteo-context install --agent claude-code --project
See which agents are detected
rifteo-context agents
Supported agents
| Agent | Config location |
|---|---|
claude-code |
~/.claude.json (via claude mcp add) |
cursor |
~/.cursor/mcp.json |
windsurf |
~/.codeium/windsurf/mcp_config.json |
gemini-cli |
~/.gemini/settings.json |
cline |
~/.cline/data/settings/cline_mcp_settings.json |
kiro |
~/.kiro/settings/mcp.json |
codex |
~/.codex/config.toml |
opencode |
~/.config/opencode/opencode.json |
amp |
~/.config/amp/settings.json |
continue |
~/.continue/config.json |
Manual install (Claude Code)
claude mcp add --scope user rifteo-contexts rifteo-context-mcp
MCP Tools
Contexts
| Tool | Description |
|---|---|
list_contexts |
List all available contexts with one-line summaries |
get_context |
Load a context by name (L1 overview or L2 full methodology) |
search_contexts |
Search contexts by keyword |
Once registered, ask your agent:
list all available security contexts
get the web-app-pentest context
load cloud-audit full methodology
Each context has two levels:
- L1 - Overview and when to use (default)
- L2 - Full detailed methodology
Bug Bounty Platforms
| Tool | Description |
|---|---|
get_program_scope |
Fetch live scope for any bug bounty program (in-scope, out-of-scope, bounty eligibility, policy) |
search_hacktivity |
Search publicly disclosed reports by vulnerability type, technology, or keyword |
Connect your accounts:
HackerOne - get your token at https://hackerone.com/settings/api_token/edit
rifteo-context auth hackerone
# HackerOne username: yourname
# HackerOne API token: ****
Intigriti - get your token at https://app.intigriti.com/settings/api
rifteo-context auth intigriti
# Intigriti API token: ****
YesWeHack works without credentials. Immunefi has no public API.
Then ask your agent:
get the scope for hackerone program "security"
get the scope for yeswehack program "datadome-bot-bounty"
search hacktivity for GraphQL vulnerabilities
Platform support:
| Platform | Scope | Auth required |
|---|---|---|
hackerone |
Full scope + policy | Yes - username + API token |
bugcrowd |
Partial (public HTML only) | No (full scope coming soon) |
intigriti |
Full scope | Yes - API token |
yeswehack |
Full scope | No |
immunefi |
Direct link | No |
search_hacktivity searches HackerOne public disclosed reports and requires no credentials.
Manage connected platforms:
rifteo-context auth --list
rifteo-context auth --remove hackerone
Local development
Point the server at a local clone of the contexts repo:
RIFTEO_CONTEXTS_PATH=/path/to/contexts rifteo-context-mcp
Or set it in your agent's MCP config env:
{
"command": "rifteo-context-mcp",
"args": [],
"env": {
"RIFTEO_CONTEXTS_PATH": "/path/to/contexts"
}
}
Without this env var the server fetches contexts live from the GitHub API.
Part of Rifteo
Part of the Rifteo open security toolkit.
License
MIT
Metadata
Release files for rifteo-context-mcp 1.0.2
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| rifteo_context_mcp-1.0.2.tar.gz | 13.3 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| rifteo_context_mcp-1.0.2-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 27.0 kB
Release files / rifteo_context_mcp-1.0.2.tar.gz
| Download URL | rifteo_context_mcp-1.0.2.tar.gz |
|---|---|
| Size | 13.3 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
557aac09f7cb89ba257c50e0f8518e475eb0c13f2fbc4aeb543513285b3e8f0b
|
|
BLAKE2b-256 checksum How to use checksums |
4df7a65f765d358b37a6f029e9e2bbe3d20cc30b8f248b9bd4b63758054c0795
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jun 29, 2026.
Transparency logRelease files / rifteo_context_mcp-1.0.2-py3-none-any.whl
| Download URL | rifteo_context_mcp-1.0.2-py3-none-any.whl |
|---|---|
| Size | 13.8 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
b65221179e62d412db6d0b458d978914fe5903ae353441ac923bef1d2873c0ea
|
|
BLAKE2b-256 checksum How to use checksums |
d5c98a933789c4500214813b46168a66f9b3b977de049e27c8774767dc739dea
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jun 29, 2026.
Transparency log