hacker-bob / setup / openai-agents
Setup guide

Set up hacker-bob in OpenAI Agents SDK

communitystdiounknownno verified config · noindex

A local MCP runtime that attacks what you own and only reports what it proved. 17 CVEs across 9 projects came out of this repo. Install: npx -y hacker-bob@latest install /path/to/project, then run /bob-evaluate target.com


01Configuration
# hacker-bob via OpenAI Agents SDK # transport: stdio # launch: npx -y hacker-bob@latest

OpenAI Agents SDK connects to MCP servers in code. Use its MCP client with the command/URL below; exact API varies by version.


02Steps
  1. Make sure OpenAI Agents SDK is installed and up to date.
  2. Wire the server into OpenAI Agents SDK using its MCP client API.
  3. Provide any required API keys/credentials as environment variables.
  4. Restart OpenAI Agents SDK and confirm hacker-bob’s tools appear.

03Other runtimes

04Provenance
config_sourcegenerated from captured install method
last_checked2026-08-16 17:54Z
sourcesGitHub repo search [p4]

Next step

Want agents that act within guardrails? Apex is the live governed-agent product — paced, capped, and fully-logged actions with approvals before anything runs.

Explore Apex →

See also: server page · is it safe? · alternatives

Set up hacker-bob MCP in OpenAI Agents SDK — MCPExplorer