io.github.joepangallo/web-recon-agent
Owned-target web security assessment MCP server for authenticated, high-friction apps.
Verdict not yet evaluated for this tool. The semantic screen takes adversarial cases first; coverage rolls out as the corpus expands (15/150 labels to graduation). The deterministic conformance probe is built but has not yet run on the public corpus, so a recorded verdict here is REVIEW or UNVERIFIED, never a clearing ALLOW. Until a verdict is recorded, an agent should treat this tool as not-yet-cleared and fall back to its own checks. Method: the eval, four-state verdict, honest limits.
Own this server? Screen its description →
MCP_TARGET_ALLOWLISTComma-separated hostnames allowed for scanning. Required.
MCP_OWNED_TARGETSComma-separated hostnames you explicitly own to unlock active and owned-aggressive scan modes.
MCP_JOB_STORE_PATHOptional path for persisted job metadata. Defaults to mcp-jobs.json in the current working directory.
MCP_MAX_CONCURRENTOptional maximum number of concurrent scan jobs. Defaults to 2.
MCP_CONFIG_PATHOptional path to a JSON config file that overrides allowlist and concurrency settings.
87 keyless tools of live, verifiable data for AI: weather, hazards, space, CVEs. Ed25519-signed.
Security tools for AI agents: scan MCP servers, validate HDP delegation chains, audit releases.
Draft cited RFP and security questionnaire answers from your knowledge base, with human review