Owned-target web security assessment MCP server for authenticated, high-friction apps.
io.github.joepangallo/web-recon-agent
https://github.com/joepangallo/web-recon-agent
STDIO
1 required env var
Hosted endpoint — paste into any MCP client.
Configuration this server reads at startup.
Comma-separated hostnames allowed for scanning. Required.
Comma-separated hostnames you explicitly own to unlock active and owned-aggressive scan modes.
Optional path for persisted job metadata. Defaults to mcp-jobs.json in the current working directory.
Optional maximum number of concurrent scan jobs. Defaults to 2.
Optional path to a JSON config file that overrides allowlist and concurrency settings.
Where to find authoritative docs and source for web-recon-agent.
Open MCP Agent Studio and connect this server to Claude, GPT, Gemini, DeepSeek and more — no install required.
Open Agent Studio