MCP低风险未认领
web-recon-agent
Owned-target web security assessment MCP server for authenticated, high-friction apps.
joepangallojoepangallo/web-recon-agent
server.json
{
"$schema": "https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json",
"name": "io.github.joepangallo/web-recon-agent",
"description": "Owned-target web security assessment MCP server for authenticated, high-friction apps.",
"repository": {
"url": "https://github.com/joepangallo/web-recon-agent",
"source": "github"
},
"version": "0.8.1",
"packages": [
{
"registryType": "npm",
"identifier": "mcp-web-recon-agent",
"version": "0.8.1",
"transport": {
"type": "stdio"
},
"environmentVariables": [
{
"description": "Comma-separated hostnames allowed for scanning. Required.",
"isRequired": true,
"format": "string",
"name": "MCP_TARGET_ALLOWLIST"
},
{
"description": "Comma-separated hostnames you explicitly own to unlock active and owned-aggressive scan modes.",
"format": "string",
"name": "MCP_OWNED_TARGETS"
},
{
"description": "Optional path for persisted job metadata. Defaults to mcp-jobs.json in the current working directory.",
"format": "string",
"name": "MCP_JOB_STORE_PATH"
},
{
"description": "Optional maximum number of concurrent scan jobs. Defaults to 2.",
"format": "number",
"name": "MCP_MAX_CONCURRENT"
},
{
"description": "Optional path to a JSON config file that overrides allowlist and concurrency settings.",
"format": "string",
"name": "MCP_CONFIG_PATH"
}
]
}
]
}权限
声明检测
运行代码—
node安装—
npm:mcp-web-recon-agent@0.8.1安装时运行脚本—无
网络无无
需要的凭据无无
工作区外的路径—无
智能体工具—无
检查
低风险 · 没有发现需要提醒的地方。
未经人工审核 · 已做规则检查;模型审核尚未开启。
版本
- #10.8.1最新2026年10月7日
web-recon-agent在 Codeg 中打开