Skip to main content
Use Neo as the first pass on HackerOne reports: fetch the submission, validate where possible, and produce a Triage Summary with verdict, evidence, impact, and next steps. Three ways to run it:
  • Triage inbox — connect in Triage, browse a program queue, send reports to Neo
  • From Neo — ask Neo to triage a report by ID or URL; the Triage Summary stays in Neo
  • From HackerOne — a HackerOne automation starts Neo; the Triage Summary is posted back as an internal comment
Neo only posts internal Triage Summary comments for automation-started triage, and can create or update Neo-owned automations when you ask. It does not post public replies, change report state, assign bounty, or take other report-changing actions.

Setup

Triage inbox

  1. In HackerOne, create an organization API token under Organization Settings > API Tokens (docs).
  2. Open Triage, choose HackerOne, and enter the token identifier and token.
  3. Select a program, review the queue, and start triage on a report. Neo starts a background task; open it from the toast or stay on the queue.
See Vuln triage for the multi-source inbox overview.

From Neo (report ID or URL)

  1. Connect HackerOne in Triage (steps above).
  2. Start a Neo task and ask it to triage the report by ID or URL.

From HackerOne (automations)

  1. In HackerOne, open Organization Settings > Automations > Secrets (from https://hackerone.com/organizations/<your_organization>/automations). See HackerOne’s External Connectors guide.
  2. Create these secrets with the exact names:
  1. With HackerOne connected in Triage, ask Neo to create or enable:
Creating or updating automations requires an organization API token with Organization Administrator permissions.
Enabling the HackerOne on-demand triage automation from Neo

Examples

Triage Summary in Neo:
Triage Summary shown in a Neo task
Triage Summary posted back to HackerOne:
Triage Summary posted back to a HackerOne report