← Index

io.github.joepangallo/web-recon-agent

io.github.joepangallo/web-recon-agent·v0.8.1·Security

Owned-target web security assessment MCP server for authenticated, high-friction apps.

Trust verdict · v1 advisory · method
NOT YET SCREENEDno verdict on file

Verdict not yet evaluated for this tool. The semantic screen takes adversarial cases first; coverage rolls out as the corpus expands (15/150 labels to graduation). The deterministic conformance probe is built but has not yet run on the public corpus, so a recorded verdict here is REVIEW or UNVERIFIED, never a clearing ALLOW. Until a verdict is recorded, an agent should treat this tool as not-yet-cleared and fall back to its own checks. Method: the eval, four-state verdict, honest limits.

Own this server? Screen its description →

Environment variables
MCP_TARGET_ALLOWLIST
required

Comma-separated hostnames allowed for scanning. Required.

MCP_OWNED_TARGETS

Comma-separated hostnames you explicitly own to unlock active and owned-aggressive scan modes.

MCP_JOB_STORE_PATH

Optional path for persisted job metadata. Defaults to mcp-jobs.json in the current working directory.

MCP_MAX_CONCURRENT

Optional maximum number of concurrent scan jobs. Defaults to 2.

MCP_CONFIG_PATH

Optional path to a JSON config file that overrides allowlist and concurrency settings.

MCP quality score · maturity, not trust · methodology
freshness
21
completeness
10
installability
25
documentation
15
stability
5
Alternatives in Security