hacker-bob / setup / windsurf
Setup guide

Set up hacker-bob in Windsurf

communitystdiounknown

A local MCP runtime that attacks what you own and only reports what it proved. 17 CVEs across 9 projects came out of this repo. Install: npx -y hacker-bob@latest install /path/to/project, then run /bob-evaluate target.com


01Configuration
{ "mcpServers": { "hacker-bob": { "command": "npx", "args": [ "-y", "hacker-bob@latest" ] } } }

Add this to ~/.codeium/windsurf/mcp_config.json. Generated from the captured install method (npx); the mcpServers shape is shared across Claude Desktop, Cursor, Windsurf, Cline, and VS Code.


02Steps
  1. Make sure Windsurf is installed and up to date.
  2. Open ~/.codeium/windsurf/mcp_config.json and add the block above (merge into any existing mcpServers).
  3. Provide any required API keys/credentials as environment variables.
  4. Restart Windsurf and confirm hacker-bob’s tools appear.

03Other runtimes

04Provenance
config_sourcegenerated from captured install method
last_checked2026-08-16 17:54Z
sourcesGitHub repo search [p4]

Next step

Want agents that act within guardrails? Apex is the live governed-agent product — paced, capped, and fully-logged actions with approvals before anything runs.

Explore Apex →

See also: server page · is it safe? · alternatives

Set up hacker-bob MCP in Windsurf — MCPExplorer