Web Recon Agent MCP server
Owned-target web security assessment MCP server for authenticated, high-friction apps.
105 downloads/wk
Reviews
Write oneNobody has reviewed Web Recon Agent yet.
If you have run it, two minutes of your experience saves the next person an afternoon.
Web Recon Agent tools (8, 1 write)
write = sends, deletes, buys or postsRead from the package source without running it. The installed server may list more.
explain_target_fitCheck whether a target URL is allowed, owned, and what scan modes are available for it.
get_report_artifactRetrieve a specific scan artifact file. Returns the file content.
get_report_summaryGet the structured report summary for a completed scan. Includes finding counts by severity and verification status.
get_scan_statusGet the status of a scan job by ID. Returns status, timing, artifacts, and recent log output.
retest_scanwrite actionRun a retest scan comparing current results against a previous baseline report.
start_owned_aggressive_scanStart an owned-aggressive active scan. Only works against targets in the owned-targets list. Auto-enables hypothesis engine, adaptive probing, attack chains, browser, and API body capture.
start_scanStart a passive web security scan against an allowlisted target. Returns a job ID for polling.
validate_assertion_packValidate a set of assertion definitions (route-access, finding-absence) against a completed scan. Returns pass/fail status for each assertion.
Public scan report
scanner v0.1.10 · 2026-09-27 · same rubric, same numbers if you re-run it
- Code scan222 source files scanned0/25
- –Live reliabilityno gateway calls yet and no remote to proben/a
- –Tool poisoningtools not inspected (local package is not executed); not countedn/a
- Auth qualitylocal package, no credentials required12/15
- Maintenancerepository not readable: repo not found3/15
- Maintainer identityno repository or website to verify2/10
Findings (4)
- mediumNetwork call to a raw IP address
net.raw-ipdist/agents/active/ssrf.js: …S', severity: 'critical' }, { url: 'http://100.100.100.200/latest/meta-data/', label: 'Alibaba meta… - mediumeval / new Function used
exec.evaldist/agents/browser-discovery.js: …turePageLinks(page) { return page.$$eval('a[href]', (anchors) => anchors … - highShell command built from a string (injection risk)
exec.shell-concatdist/agents/recon.js: …llenge pages const headersRaw = execSync(`curl -sI -m 10 --location --max-redirs 3 ${JSON.stringify(ctx.targetUrl)}`, { encod… - highNetwork call to a paste/tunnel/webhook host
net.suspicious-hostdist/oast-receiver.js: …eiver-manifest.json] [--public-base-url https://oast.example.net] [--token secret] [--retenti…
Install Web Recon Agent in Claude Code, Cursor or VS Code
Runs npx -y mcp-web-recon-agent on your machine. Read the scan report first; the gateway never runs local packages.
claude mcp add web-recon-agent -- npx -y mcp-web-recon-agent
Web Recon Agent: common questions
- Is Web Recon Agent MCP server safe?
- No: it is graded F and blocked at the gateway (26/100). Read the Web Recon Agent safety report
- How do I install Web Recon Agent?
- It runs on your machine. Copy the Claude Code, Cursor, VS Code or Claude Desktop config from the install section.
- Does Web Recon Agent need an API key?
- No secret keys are declared. It reads 5 settings from the environment.
- Is Web Recon Agent maintained?
- The latest release is v0.8.1.
- What can I use instead of Web Recon Agent?
- Servers from other publishers that do the same job: agent-device MCP server, agent-device MCP server and Robin: AI-Powered Dark Web OSINT MCP server. Compare all Web Recon Agent alternatives.
Alternatives to Web Recon Agent
Same job from other publishers: the closest match first, then the best rated.
- agent-deviceLet AI agents inspect, control, and debug real iOS, Android, desktop, and TV appsnot reviewedWidely usedA
- agent-deviceMCP server for mobile app automation: verify, control, and debug iOS, Android, TV, and desktop appsnot reviewedWidely usedA
- Robin: AI-Powered Dark Web OSINTDark web OSINT over Tor: search onion engines, scrape pages, report with your own model.not reviewedEstablishedA
- Google SurfWeb, academic and code search with graph RAG, data lineage, ontology and cross-project schema links.not reviewedEstablishedB
- ShellwardAI agent security: 7 MCP tools for injection detection, PII scanning, command safety, DLP.not reviewedEstablishedA