mcpbeat Sign in

Web Recon Agent MCP Server

local only

Web Recon Agent runs on your own machine — the client starts it, so there is no endpoint to ping. 17 installs a week from npm.

Owned-target web security assessment MCP server for authenticated, high-friction apps.

The linked repository no longer exists on GitHub — it was deleted or made private.

Installs per day peak 10 · avg 3 · -20% w/w
a month agotoday
17
Installs / week
npm · mcp-web-recon-agent
Stars
on GitHub
Last commit
0 releases in 90 days
License
language unknown

This one has been quiet for a while

Quiet is not dead — but it is worth knowing when it wakes up, or when someone else takes it over. We watch the repository and tell you either way.

Three servers free · no card

Connect this server

This server runs on your own machine — install it with the package manager and the client starts it for you. Package name taken from the official registry entry.

run in your terminal
claude mcp add web-recon-agent -- npx -y mcp-web-recon-agent
~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "web-recon-agent": {
      "args": [
        "-y",
        "mcp-web-recon-agent"
      ],
      "command": "npx"
    }
  }
}
~/.codex/config.toml
[mcp_servers.web-recon-agent]
command = "npx"
args = ["-y", "mcp-web-recon-agent"]
.cursor/mcp.json
{
  "mcpServers": {
    "web-recon-agent": {
      "args": [
        "-y",
        "mcp-web-recon-agent"
      ],
      "command": "npx"
    }
  }
}
.vscode/mcp.json
{
  "mcpServers": {
    "web-recon-agent": {
      "args": [
        "-y",
        "mcp-web-recon-agent"
      ],
      "command": "npx"
    }
  }
}

This one needs environment variables set before it will start: MCP_TARGET_ALLOWLIST (Comma-separated hostnames allowed for scanning. Required.), MCP_OWNED_TARGETS (Comma-separated hostnames you explicitly own to unlock active and owned-aggressive scan modes.), MCP_JOB_STORE_PATH (Optional path for persisted job metadata. Defaults to mcp-jobs.json in the current working directory.), MCP_MAX_CONCURRENT (Optional maximum number of concurrent scan jobs. Defaults to 2.), MCP_CONFIG_PATH (Optional path to a JSON config file that overrides allowlist and concurrency settings.). The author declared them in the registry entry; get the values from the project itself.

Alternatives to Web Recon Agent

same job, measured the same way
Wass MCP
by tb0hdan

MCP server for web application security scanning

local only
YunoHost MCP
by imattau

Nostr-authenticated MCP server for secure YunoHost administration.

19 722 installs/wk local only
Operant MCP
by operantlabs

Security testing MCP server for penetration testing, forensics, and vulnerability assessment

49 installs/wk local only
MCP Server for OSCAL
by awslabs

AI agent tools for Open Security Controls Assessment Language (OSCAL)

156 installs/wk local only
Security Mcp
by varvararatta

MCP server for Security

answering
Altr MCP Server
by altrsoftware

MCP server for ALTR data security: databases, tags, policies, classification, access, audits

242 installs/wk local only
n8n MCP Community
by drzamarian

A security-focused MCP server for self-hosted n8n Community Edition.

83 installs/wk local only
Cybersec Toolkit
by 26zl

Authorization-gated MCP server to discover and run 670+ security tools for CTF, pentest, and DFIR.

local only

Web Recon Agent — questions

Answers built from our own checks of this server.

Why is there no uptime for Web Recon Agent?
Web Recon Agent runs on your own machine over stdio — there is no network address to reach, so uptime cannot be measured for it by anyone. What can be measured is adoption: the npm package mcp-web-recon-agent was installed 17 times last week.
Is Web Recon Agent still maintained?
The linked repository no longer exists on GitHub — it was deleted or made private. We show this because it changes what you can expect: an unmaintained server may keep answering for months and then stop without warning.
How do I connect Web Recon Agent?
Copy the ready config from this page — we generate it for Claude Code, Claude Desktop, Codex, Cursor and VS Code, each with the file path that client actually reads. It runs locally, so the command pulls mcp-web-recon-agent straight from npm; nothing to host, nothing to sign up for.
How many people use Web Recon Agent?
The npm package mcp-web-recon-agent was installed 17 times in the last week. Week over week that is -20%. We show installs rather than GitHub stars on purpose: a star is a bookmark, an install is someone actually running it.