Built for security professionals doing authenticated web app assessments on targets you own. This handles the tedious parts of recon against applications with complex authentication flows and high friction interfaces where traditional scanning tools fall short. You'd reach for this when you need to map out API endpoints, enumerate authenticated routes, or perform structured reconnaissance through Claude without repeatedly logging in or maintaining session state manually. Designed specifically for penetration testing and security audits where you have legitimate access but the app's authentication layer makes automated tooling painful to coordinate.
MCP_TARGET_ALLOWLIST*Comma-separated hostnames allowed for scanning. Required.
MCP_OWNED_TARGETSComma-separated hostnames you explicitly own to unlock active and owned-aggressive scan modes.
MCP_JOB_STORE_PATHOptional path for persisted job metadata. Defaults to mcp-jobs.json in the current working directory.
MCP_MAX_CONCURRENTOptional maximum number of concurrent scan jobs. Defaults to 2.
MCP_CONFIG_PATHOptional path to a JSON config file that overrides allowlist and concurrency settings.
io.github.ericm1018/skillfm-llm-cost-optimizer-openai-anthropic-usage
io.github.mikerawsonnz/llm-orchestration-agent
io.github.mikerawsonnz/authenticated-llm-agent
labforgedev/copilot-memory-mcp
csoai-org/agent-prompt-injection-firewall-mcp
io.github.mikerawsonnz/authenticated-multi-llm-agent