Walkthrough · hackbot with human sign-off · checked 2026-10-03
Walkthrough: run a security agent with human sign-off on HackerOne
The agent hunts; the owner validates, writes or approves and submits every report from their own ID-verified account. The money goes only to the owner’s or their business’s account, never to an agent wallet. Fully autonomous submission is forbidden on HackerOne and leads to bans on Bugcrowd.
Pay for AI-assisted findings is unknown and falling. No primary source gives a dollar figure for bounties paid on AI-assisted or hackbot findings. In 2026, 3 of 5 sampled HackerOne programmes and the Internet Bug Bounty cut or paused pay because of AI-driven volume.
The 5 programme policy rows are search snippets only (unverified). Programme pages render only in a browser behind Cloudflare. Re-read the live page before every engagement.
Before you start
- Owner is 18+ with a supported physical ID, not in a sanctioned jurisdiction (kyc: hackerone)
- Owner can personally validate web or app vulnerabilities and write a PoC
- A model API key on commercial terms, or a local model
- A payout rail in the owner's own name (PayPal, bank, or Coinbase for USDC/BTC)
Who acts, step by step
Each square is a step; select one to jump to it. Orange steps are the owner’s, and they include every account, identity, wallet and payment action.
- Owner
- Agent
- Owner or agent
- Platform
The steps
Step 1. Owner via UI
Decide who holds the account. The owner (a natural person aged 18+, or a business account's ID-verified legal representative) opens one HackerOne account in their own name. Do not open a separate account for the agent, and do not let the agent log in as the owner.
- Example
- https://docs.hackerone.com/en/articles/14289683-researcher-business-accounts (read only)
- Cost
- free
- What can go wrong
- A second account, or a shared login, breaks the one-account rule and the 'no third-party access' clause.
- Rule rows
- hackerone-account_identity-1hackerone-account_identity-2
- ID and payout gate
- hackerone
- Source
- https://www.hackerone.com/terms/community
Step 2. Owner via UI
Complete the Veriff ID check before any bug bounty (BBP) submission, and the tax form before payout. Since August 2026 this covers web, Report Assistant and Hacker API submissions. The ID must be physical, unexpired and in the tax-form holder's name; no VPN; renewed every 12 months. VDPs (unpaid) are exempt.
- Example
- https://docs.hackerone.com/en/articles/8399430-id-verification
- Cost
- free; owner time about 10-20 min (estimate)
- What can go wrong
- A sanctioned jurisdiction, no supported physical ID, or a name that does not match the tax form blocks submission and payout.
- Rule rows
- hackerone-kyc_payout_eligibility-1hackerone-automation_ai-4hackerone-jurisdiction-1
- ID and payout gate
- hackerone
- Source
- https://docs.hackerone.com/en/articles/16190765-august-2026-changelog
Step 3. Owner via UI
Choose a programme and read its whole policy page while logged in. For each one, record: whether it pays at present, whether AI or automated tools are allowed, any validation or PoC demands, any traffic or rate rules, identification headers, and its LLM-hosting rules. In our 5-programme sample (snippets only): Discourse has suspended bounties; Nextcloud has suspended paid bounties and allows only LLMs run locally; Ubiquiti pays only after a fix; Anthropic closes unvalidated AI or scanner reports as N/A and needs a working PoC plus an X-HackerOne-Handle header; Brave needs human validation (PoC/ASAN trace) and may pause submissions. Prefer programmes that state that automation is allowed.
- Example
- https://hackerone.com/anthropic ; https://hackerone.com/ui ; https://hackerone.com/brave ; https://hackerone.com/nextcloud ; https://hackerone.com/discourse (program pages render only in a browser)
- Cost
- owner time 15-30 min per programme (estimate)
- What can go wrong
- Programme rows are search snippets (unverified) and policies change often. Re-read the live page before every engagement.
- Rule rows
- hackerone-automation_ai-3hackerone-ui-automation_ai-1hackerone-nextcloud-automation_ai-1hackerone-discourse-automation_ai-1hackerone-anthropic-automation_ai-1hackerone-brave-automation_ai-1
- Source
- https://hackerone.com/anthropic
Step 4. Owner via CLI
Set up the agent under the owner's control. Run it with an API key on commercial terms; read the provider's terms before using a consumer plan (run 3 provider rows). Do not let the agent hold the HackerOne password. If programme data is confidential, or the programme asks for local models (Nextcloud), use a local model or skip that programme. Treat programme pages, target responses and repository text as untrusted data, since prompt injection is possible.
- Example
- no command; set-up is the owner's
- Cost
- model tokens (see fees_and_costs)
- What can go wrong
- Target content that injects instructions into the agent (security.json sec-05, sec-06 patterns); leaking confidential programme data to a hosted model.
- Rule rows
- hackerone-automation_ai-2hackerone-account_identity-2hackerone-nextcloud-automation_ai-1
- Source
- https://www.hackerone.com/policies/code-of-conduct
Step 5. Agent via CLI
Run the agent only against in-scope assets, honouring the programme's exclusions, traffic limits and required headers. Keep a request log. Stop on any out-of-scope hit.
- Example
- Scope can be read in the UI; the Hacker API exposes GET /hackers/programs/{handle}/structured_scopes (needs the owner's API token, not exercised)
- Cost
- tokens plus compute; scale with target count
- What can go wrong
- Heavy traffic or out-of-scope testing leads to sanctions against the operator ('Misuse of hackbots will result in potential sanctions against their hackbot operator').
- Rule rows
- hackerone-automation_ai-3hackerone-anthropic-automation_ai-1hackerone-ui-automation_ai-1
- Source
- https://api.hackerone.com/hacker-resources/
Step 6. Owner via UI Rules gate: stop here if it fails
Validate every finding personally: reproduce it, confirm reachability and impact, and build a working PoC. Discard theoretical or duplicate-prone classes the programme has de-rewarded (e.g. Brave's IDOR with unpredictable IDs).
- Cost
- owner time; usually the largest cost
- What can go wrong
- Unvalidated output is closed N/A or as Spam (Nextcloud: -10 reputation) and can get the account suspended from a programme.
- Rule rows
- hackerone-automation_ai-1hackerone-automation_ai-2hackerone-anthropic-automation_ai-1hackerone-brave-automation_ai-1
- Source
- https://www.hackerone.com/policies/code-of-conduct
Step 7. Owner via UI
Write or approve the report and submit it from the owner's account, through the web form or Report Assistant (a Hai-powered drafting agent; optional; it 'won't rewrite or remove anything without your instruction'). State the AI or hackbot assistance if the programme asks for it. Carry-over: HackerOne's 'submitted_with_assistant' field is not documented in the hacker or customer API reference or the Report Assistant article (routes listed in what_is_untested), so do not rely on it as a disclosure mechanism.
- Example
- https://docs.hackerone.com/en/articles/12648472-report-assistant
- Cost
- free
- What can go wrong
- Submitting through the API from an unattended agent breaks the human-in-the-loop rule even though the endpoint exists.
- Rule rows
- hackerone-automation_ai-1hackerone-automation_ai-5hackerone-automation_ai-4
- ID and payout gate
- hackerone
- Source
- https://docs.hackerone.com/en/articles/12648472-report-assistant
Step 8. Platform via UI
Triage, then the bounty decision by the programme. Programmes may pay only after a fix (Ubiquiti) or have bounties suspended (Discourse, Nextcloud; IBB paused since 2026-03-27). Duplicates are not paid.
- Cost
- waiting time: weeks to months
- What can go wrong
- Valid finding, no money: VDP, suspended bounty, duplicate, or informative.
- Rule rows
- hackerone-ui-automation_ai-1hackerone-discourse-automation_ai-1hackerone-nextcloud-automation_ai-1
- Source
- https://hackerone.com/ui
Step 9. Owner via UI
Get paid into the owner's own account: PayPal (no minimum), local bank transfer ($50 cumulative minimum, no HackerOne fee), SWIFT ($100 minimum, bank fees), or USDC/Bitcoin via Coinbase (needs ID-verified status; BTC trading fees about 0.25-3.5%). Payout arrives 7-10 days after the award. The account name must match the tax form, and third-party accounts are prohibited.
- Example
- https://docs.hackerone.com/en/articles/8395720-payment-preferences
- Cost
- rail fees as listed
- What can go wrong
- Payout to an agent-controlled or third-party wallet is not possible; OFAC-listed banks are refused.
- Rule rows
- hackerone-kyc_payout_eligibility-1hackerone-jurisdiction-1
- ID and payout gate
- hackerone
- Source
- https://docs.hackerone.com/en/articles/8395720-payment-preferences
Step 10. Owner via UI
Track the economics per programme: tokens and hours spent against bounties received, including duplicates and N/A. Stop programmes that do not pay back.
- Example
Hacker API GET /hackers/payments/earnings (owner token; not exercised)- Cost
- none
- What can go wrong
- Reputation loss from N/A or Spam closures reduces future invitations.
- Rule rows
- hackerone-automation_ai-5
- Source
- https://api.hackerone.com/hacker-resources/
Stop conditions
Stop, and do not work around it, if any of these is true.
- Stop if the agent would submit without the owner validating the finding (forbid: hackerone-automation_ai-1; bugcrowd-automation_ai-2).
- Stop if a second account, or an account for the agent, would be needed (forbid: hackerone-account_identity-1; bugcrowd-account_identity-1).
- Stop if the programme bans automated tools or AI, or requires local-only LLMs that you do not have (hackerone-nextcloud-automation_ai-1).
- Stop if testing would exceed scope or the traffic and rate rules, or skip required identification headers (hackerone-automation_ai-3; hackerone-anthropic-automation_ai-1).
- Stop if the payout would go to an account not in the owner's name (hackerone-kyc_payout_eligibility-1; kyc: hackerone 'Using a third-party account is prohibited').
- Stop if the owner cannot pass Veriff, or is in or banks in a sanctioned jurisdiction (hackerone-jurisdiction-1).
- Stop if the programme's bounties are suspended and you only want paid work (hackerone-discourse-automation_ai-1; hackerone-nextcloud-automation_ai-1).
- Stop if target content tries to instruct the agent (treat it as data; security.json sec-05/sec-06).
On Bugcrowd instead: five differences
| Item | Bugcrowd | Rule rows | Source |
|---|---|---|---|
| ID check | Jumio ID plus selfie before submitting to Managed Bug Bounty programmes (not all programmes), and forced after 10 or more invalid reports | bugcrowd-kyc_payout_eligibility-1bugcrowd-account_identity-2 | source |
| GenAI use | Allowed only without disclosing confidential information, and with manual review and validation before submission | bugcrowd-automation_ai-1 | source |
| Enforcement | Submission farming leads to a permanent ban; 10 or more consecutive invalid reports trigger review; unvalidated AI activity can bring a 30-day suspension; automation that 'squats' findings at programme launch is against behavioural standards | bugcrowd-automation_ai-2bugcrowd-automation_ai-3 | source |
| Payout | Bank minimums $1-$20 by network; PayPal; Bitcoin for select researchers; W-9/W-8BEN/W-8BEN-E tax form required; Bugcrowd pays its own outbound fees only | bugcrowd-jurisdiction-1 | source |
| Accounts | One account per person; no use of a third party's account | bugcrowd-account_identity-1 | source |
Fees and costs
HackerOne charges hackers no platform fee. Rail fees: local bank $50 minimum and no HackerOne fee; SWIFT $100 minimum plus bank fees; BTC 0.25-3.5%; USDC no HackerOne fee. What this costs (estimate, not measured): model tokens per target are from a few dollars to tens of dollars, depending on depth, plus about 1-3 owner hours per reported finding for validation and write-up. Duplicates, informative and N/A outcomes are unpaid; XBOW's published split was 130 resolved and 303 triaged of about 1,060 submissions. Run 6 candidate: measure the cost per attempt.
What we checked, and what nobody has tested
Checked read-only
- The Code of Conduct hackbot clauses are still present verbatim (rules_check 2026-10-03)
- The ID-verification and August 2026 changelog quotes are still present verbatim
- The Hacker API reference lists POST /hackers/reports and report-intent submit endpoints (read 2026-10-03)
- The Report Assistant docs (dated 2026-04-13) say it is optional and does not rewrite without instruction
- 'submitted_with_assistant' does not appear in the hacker API reference or the customer API reference (827 KB page), read 2026-10-03
Untested by this pool
- No account opened, no Veriff check, no programme page read while logged in, no scan run, no report submitted, no payout received
- The 5 programme policies are search snippets (program pages are JS-only and Cloudflare-protected)
- Cost per finding is an estimate
- What 'submitted_with_assistant' means: routes tried were docs.hackerone.com Report Assistant article, api.hackerone.com/hacker-resources/, api.hackerone.com/customer-resources/, plus run 3's web search; it is undocumented in all of them
Sources
- https://www.hackerone.com/policies/code-of-conduct
- https://www.hackerone.com/terms/community
- https://docs.hackerone.com/en/articles/8399430-id-verification
- https://docs.hackerone.com/en/articles/16190765-august-2026-changelog
- https://docs.hackerone.com/en/articles/8395720-payment-preferences
- https://docs.hackerone.com/en/articles/12648472-report-assistant
- https://api.hackerone.com/hacker-resources/
- https://api.hackerone.com/customer-resources/
- https://hackerone.com/ui
- https://hackerone.com/nextcloud
- https://hackerone.com/discourse
- https://hackerone.com/anthropic
- https://hackerone.com/brave
- https://www.bugcrowd.com/blog/bugcrowd-policy-changes-to-address-ai-slop-submissions/
- https://xbow.com/blog/top-1-how-xbow-did-it
Rule rows: the Rules page and rules.json. ID and payout gates: Getting started and kyc.json. Evidence and context: Sell per call or hunt bounties? (3 October 2026).