Web Recon Agent runs on your own machine — the client starts it, so there is no endpoint to ping. 17 installs a week from npm.
Owned-target web security assessment MCP server for authenticated, high-friction apps.
The linked repository no longer exists on GitHub — it was deleted or made private.
Quiet is not dead — but it is worth knowing when it wakes up, or when someone else takes it over. We watch the repository and tell you either way.
This server runs on your own machine — install it with the package manager and the client starts it for you. Package name taken from the official registry entry.
claude mcp add web-recon-agent -- npx -y mcp-web-recon-agent
{
"mcpServers": {
"web-recon-agent": {
"args": [
"-y",
"mcp-web-recon-agent"
],
"command": "npx"
}
}
}
[mcp_servers.web-recon-agent]
command = "npx"
args = ["-y", "mcp-web-recon-agent"]
{
"mcpServers": {
"web-recon-agent": {
"args": [
"-y",
"mcp-web-recon-agent"
],
"command": "npx"
}
}
}
{
"mcpServers": {
"web-recon-agent": {
"args": [
"-y",
"mcp-web-recon-agent"
],
"command": "npx"
}
}
}
This one needs environment variables set before it will start:
MCP_TARGET_ALLOWLIST (Comma-separated hostnames allowed for scanning. Required.), MCP_OWNED_TARGETS (Comma-separated hostnames you explicitly own to unlock active and owned-aggressive scan modes.), MCP_JOB_STORE_PATH (Optional path for persisted job metadata. Defaults to mcp-jobs.json in the current working directory.), MCP_MAX_CONCURRENT (Optional maximum number of concurrent scan jobs. Defaults to 2.), MCP_CONFIG_PATH (Optional path to a JSON config file that overrides allowlist and concurrency settings.).
The author declared them in the registry entry; get the values from the project itself.
MCP server for web application security scanning
Nostr-authenticated MCP server for secure YunoHost administration.
Security testing MCP server for penetration testing, forensics, and vulnerability assessment
AI agent tools for Open Security Controls Assessment Language (OSCAL)
MCP server for Security
MCP server for ALTR data security: databases, tags, policies, classification, access, audits
A security-focused MCP server for self-hosted n8n Community Edition.
Authorization-gated MCP server to discover and run 670+ security tools for CTF, pentest, and DFIR.
Answers built from our own checks of this server.