{"name":"io.github.joepangallo/web-recon-agent","slug":"joepangallo-web-recon-agent","title":null,"description":"Owned-target web security assessment MCP server for authenticated, high-friction apps.","url":"https://mcp.market/server/joepangallo-web-recon-agent","rating":null,"grade":"F","score":26,"certified":false,"status":"active","category":"ai","tags":["ai","security"],"presence":{"score":10,"stars":null,"forks":null,"downloads_week":105,"last_push_at":null,"license":"UNLICENSED"},"uptime":null,"claimed":false,"transport":"npm","callable_via_gateway":false,"default_price_micros":0,"repository":"https://github.com/joepangallo/web-recon-agent","website":null,"version":"0.8.1","remotes":[],"packages":[{"registryType":"npm","identifier":"mcp-web-recon-agent","version":"0.8.1","transport":{"type":"stdio"},"environmentVariables":[{"description":"Comma-separated hostnames allowed for scanning. Required.","isRequired":true,"format":"string","name":"MCP_TARGET_ALLOWLIST"},{"description":"Comma-separated hostnames you explicitly own to unlock active and owned-aggressive scan modes.","format":"string","name":"MCP_OWNED_TARGETS"},{"description":"Optional path for persisted job metadata. Defaults to mcp-jobs.json in the current working directory.","format":"string","name":"MCP_JOB_STORE_PATH"},{"description":"Optional maximum number of concurrent scan jobs. Defaults to 2.","format":"number","name":"MCP_MAX_CONCURRENT"},{"description":"Optional path to a JSON config file that overrides allowlist and concurrency settings.","format":"string","name":"MCP_CONFIG_PATH"}]}],"tools":[{"name":"explain_target_fit","description":"Check whether a target URL is allowed, owned, and what scan modes are available for it.","write_action":false,"price_micros":0,"input_schema":null},{"name":"get_report_artifact","description":"Retrieve a specific scan artifact file. Returns the file content.","write_action":false,"price_micros":0,"input_schema":null},{"name":"get_report_summary","description":"Get the structured report summary for a completed scan. Includes finding counts by severity and verification status.","write_action":false,"price_micros":0,"input_schema":null},{"name":"get_scan_status","description":"Get the status of a scan job by ID. Returns status, timing, artifacts, and recent log output.","write_action":false,"price_micros":0,"input_schema":null},{"name":"retest_scan","description":"Run a retest scan comparing current results against a previous baseline report.","write_action":true,"price_micros":0,"input_schema":null},{"name":"start_owned_aggressive_scan","description":"Start an owned-aggressive active scan. Only works against targets in the owned-targets list. Auto-enables hypothesis engine, adaptive probing, attack chains, browser, and API body capture.","write_action":false,"price_micros":0,"input_schema":null},{"name":"start_scan","description":"Start a passive web security scan against an allowlisted target. Returns a job ID for polling.","write_action":false,"price_micros":0,"input_schema":null},{"name":"validate_assertion_pack","description":"Validate a set of assertion definitions (route-access, finding-absence) against a completed scan. Returns pass/fail status for each assertion.","write_action":false,"price_micros":0,"input_schema":null}],"scan":{"score":26,"grade":"F","scanned_at":"2026-09-27T23:34:24.913Z","report":{"scannerVersion":"0.1.10","scannedAt":"2026-09-27T23:34:24.851Z","components":{"code":{"score":0,"max":25,"notes":["222 source files scanned"]},"reliability":{"score":-1,"max":20,"notes":["no gateway calls yet and no remote to probe"]},"poisoning":{"score":-1,"max":15,"notes":["tools not inspected (local package is not executed); not counted"]},"auth":{"score":12,"max":15,"notes":["local package, no credentials required"]},"maintenance":{"score":3,"max":15,"notes":["repository not readable: repo not found"]},"identity":{"score":2,"max":10,"notes":["no repository or website to verify"]}},"findings":[{"id":"net.raw-ip","severity":"medium","component":"code","title":"Network call to a raw IP address","evidence":"dist/agents/active/ssrf.js: …S', severity: 'critical' }, { url: 'http://100.100.100.200/latest/meta-data/', label: 'Alibaba meta…"},{"id":"exec.eval","severity":"medium","component":"code","title":"eval / new Function used","evidence":"dist/agents/browser-discovery.js: …turePageLinks(page) { return page.$$eval('a[href]', (anchors) => anchors …"},{"id":"exec.shell-concat","severity":"high","component":"code","title":"Shell command built from a string (injection risk)","evidence":"dist/agents/recon.js: …llenge pages const headersRaw = execSync(`curl -sI -m 10 --location --max-redirs 3 ${JSON.stringify(ctx.targetUrl)}`, { encod…"},{"id":"net.suspicious-host","severity":"high","component":"code","title":"Network call to a paste/tunnel/webhook host","evidence":"dist/oast-receiver.js: …eiver-manifest.json] [--public-base-url https://oast.example.net] [--token secret] [--retenti…"}],"inputs":{"packages":[{"registryType":"npm","identifier":"mcp-web-recon-agent","version":"0.8.1","found":true,"license":"UNLICENSED","hasInstallScripts":false,"dependencyCount":3,"publishedAt":"2026-03-25T14:36:46.837Z","repositoryUrl":"git+https://github.com/joepangallo/web-recon-agent.git","weeklyDownloads":105}],"repo":{"found":false,"owner":"joepangallo","repo":"web-recon-agent","error":"repo not found"},"icon":{"url":null,"source":"none"},"presence":{"stars":null,"forks":null,"downloadsWeek":105,"license":"UNLICENSED","lastPushAt":null,"score":10}}}},"grade_history":[],"reviews":[]}