Web Recon Agent MCP Server
by joepangalloio.github.joepangallo/web-recon-agentv0.8.1
MCP server for analyst-first owned-target web security assessments of authenticated, high-friction apps
context tax
queued
security
queued
cold start
queued
freshness
Stale7mo ago
Install Web Recon Agent MCP server
Install in Claude Code
claude mcp add web-recon-agent -e MCP_TARGET_ALLOWLIST='<mcp-target-allowlist>' -- npx -y mcp-web-recon-agentInstall in Cursor
{
"mcpServers": {
"web-recon-agent": {
"command": "npx",
"args": [
"-y",
"mcp-web-recon-agent"
],
"env": {
"MCP_TARGET_ALLOWLIST": "<mcp-target-allowlist>"
}
}
}
}Add to ~/.cursor/mcp.json (global) or .cursor/mcp.json (project).
Install in Claude Desktop
{
"mcpServers": {
"web-recon-agent": {
"command": "npx",
"args": [
"-y",
"mcp-web-recon-agent"
],
"env": {
"MCP_TARGET_ALLOWLIST": "<mcp-target-allowlist>"
}
}
}
}Settings → Developer → Edit Config (claude_desktop_config.json), then restart.
Install in VS Code
{
"servers": {
"web-recon-agent": {
"type": "stdio",
"command": "npx",
"args": [
"-y",
"mcp-web-recon-agent"
],
"env": {
"MCP_TARGET_ALLOWLIST": "<mcp-target-allowlist>"
}
}
}
}Add to .vscode/mcp.json in your workspace.
Install in Windsurf
{
"mcpServers": {
"web-recon-agent": {
"command": "npx",
"args": [
"-y",
"mcp-web-recon-agent"
],
"env": {
"MCP_TARGET_ALLOWLIST": "<mcp-target-allowlist>"
}
}
}
}Add to ~/.codeium/windsurf/mcp_config.json.
Configuration
| Variable | Required | Secret | Description |
|---|---|---|---|
| MCP_TARGET_ALLOWLIST | yes | — | Comma-separated hostnames allowed for scanning. Required. |
| MCP_OWNED_TARGETS | — | — | Comma-separated hostnames you explicitly own to unlock active and owned-aggressive scan modes. |
| MCP_JOB_STORE_PATH | — | — | Optional path for persisted job metadata. Defaults to mcp-jobs.json in the current working directory. |
| MCP_MAX_CONCURRENT | — | — | Optional maximum number of concurrent scan jobs. Defaults to 2. |
| MCP_CONFIG_PATH | — | — | Optional path to a JSON config file that overrides allowlist and concurrency settings. |
Freshness
Stale — last maintenance signal 7mo ago. The newest of the signals below sets the band.
Last commit (default branch)
no data · GitHub
Latest release
no data · GitHub
Package published
no data · npm/PyPI
Registry entry updated
2026-03-25 · 7mo ago · official registry · v0.8.1
FAQ
›How do I install the Web Recon Agent MCP server in Claude Code?
Run: claude mcp add web-recon-agent -e MCP_TARGET_ALLOWLIST='<mcp-target-allowlist>' -- npx -y mcp-web-recon-agent. For Cursor, VS Code, Claude Desktop and Windsurf, use the install tabs above.
›Does Web Recon Agent require an API key?
Yes. It expects MCP_TARGET_ALLOWLIST.
›Can I use Web Recon Agent as a remote (hosted) MCP server?
No hosted endpoint is published; it runs locally over stdio.
›Is Web Recon Agent in the official MCP registry?
Yes, as io.github.joepangallo/web-recon-agent.
Alternatives to Web Recon Agent
Other security MCP servers.