Mmcp.market

Web Recon Agent MCP server

by joepangallo·io.github.joepangallo/web-recon-agent·v0.8.1

Owned-target web security assessment MCP server for authenticated, high-friction apps.

F26/100grade F
What users say
No reviews yet
Be the first
Safety scan
F26/100

full report

Adoption
New

105 downloads/wk

Blocked at the gateway.Blocked at the gateway. A critical finding or a dead endpoint.

Reviews

Write one

Nobody has reviewed Web Recon Agent yet.

If you have run it, two minutes of your experience saves the next person an afternoon.

Web Recon Agent tools (8, 1 write)

write = sends, deletes, buys or posts

Read from the package source without running it. The installed server may list more.

  • explain_target_fit

    Check whether a target URL is allowed, owned, and what scan modes are available for it.

  • get_report_artifact

    Retrieve a specific scan artifact file. Returns the file content.

  • get_report_summary

    Get the structured report summary for a completed scan. Includes finding counts by severity and verification status.

  • get_scan_status

    Get the status of a scan job by ID. Returns status, timing, artifacts, and recent log output.

  • retest_scanwrite action

    Run a retest scan comparing current results against a previous baseline report.

  • start_owned_aggressive_scan

    Start an owned-aggressive active scan. Only works against targets in the owned-targets list. Auto-enables hypothesis engine, adaptive probing, attack chains, browser, and API body capture.

  • start_scan

    Start a passive web security scan against an allowlisted target. Returns a job ID for polling.

  • validate_assertion_pack

    Validate a set of assertion definitions (route-access, finding-absence) against a completed scan. Returns pass/fail status for each assertion.

Public scan report

scanner v0.1.10 · 2026-09-27 · same rubric, same numbers if you re-run it

2 high2 medium
  • Code scan222 source files scanned0/25
  • –Live reliabilityno gateway calls yet and no remote to proben/a
  • –Tool poisoningtools not inspected (local package is not executed); not countedn/a
  • Auth qualitylocal package, no credentials required12/15
  • Maintenancerepository not readable: repo not found3/15
  • Maintainer identityno repository or website to verify2/10

Findings (4)

  • mediumNetwork call to a raw IP addressnet.raw-ip
    dist/agents/active/ssrf.js: …S', severity: 'critical' }, { url: 'http://100.100.100.200/latest/meta-data/', label: 'Alibaba meta…
  • mediumeval / new Function usedexec.eval
    dist/agents/browser-discovery.js: …turePageLinks(page) { return page.$$eval('a[href]', (anchors) => anchors …
  • highShell command built from a string (injection risk)exec.shell-concat
    dist/agents/recon.js: …llenge pages const headersRaw = execSync(`curl -sI -m 10 --location --max-redirs 3 ${JSON.stringify(ctx.targetUrl)}`, { encod…
  • highNetwork call to a paste/tunnel/webhook hostnet.suspicious-host
    dist/oast-receiver.js: …eiver-manifest.json] [--public-base-url https://oast.example.net] [--token secret] [--retenti…
Overall 26/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON

Install Web Recon Agent in Claude Code, Cursor or VS Code

Runs npx -y mcp-web-recon-agent on your machine. Read the scan report first; the gateway never runs local packages.

claude mcp add web-recon-agent -- npx -y mcp-web-recon-agent
Add to Cursor

Web Recon Agent: common questions

Is Web Recon Agent MCP server safe?
No: it is graded F and blocked at the gateway (26/100). Read the Web Recon Agent safety report
How do I install Web Recon Agent?
It runs on your machine. Copy the Claude Code, Cursor, VS Code or Claude Desktop config from the install section.
Does Web Recon Agent need an API key?
No secret keys are declared. It reads 5 settings from the environment.
Is Web Recon Agent maintained?
The latest release is v0.8.1.
What can I use instead of Web Recon Agent?
Servers from other publishers that do the same job: agent-device MCP server, agent-device MCP server and Robin: AI-Powered Dark Web OSINT MCP server. Compare all Web Recon Agent alternatives.

Alternatives to Web Recon Agent

Same job from other publishers: the closest match first, then the best rated.

All Web Recon Agent alternatives →
  • agent-device
    Let AI agents inspect, control, and debug real iOS, Android, desktop, and TV apps
    A
  • agent-device
    MCP server for mobile app automation: verify, control, and debug iOS, Android, TV, and desktop apps
    A
  • Robin: AI-Powered Dark Web OSINT
    Dark web OSINT over Tor: search onion engines, scrape pages, report with your own model.
    A
  • Google Surf
    Web, academic and code search with graph RAG, data lineage, ontology and cross-project schema links.
    B
  • Shellward
    AI agent security: 7 MCP tools for injection detection, PII scanning, command safety, DLP.
    A

More from joepangallo →