recon-mcp
Related Servers
Alternatives to recon-mcp
No user-submitted related servers found.
Related Servers
- AlicenseAqualityBmaintenanceMCP server for offensive-security tooling, enabling AI agents to run reconnaissance, CVE intelligence, JavaScript analysis, HTTP probing, and port scanning against authorized targets.10MIT
- FlicenseNot gradedqualityCmaintenanceA production-style MCP server providing AI models with cybersecurity tools including port scanning, WHOIS, DNS, threat intelligence, CVE lookup, and more.-
- AlicenseAqualityBmaintenanceAn MCP server that provides passive and low-impact active reconnaissance tools for authorized bug bounty and security assessments, enabling LLMs to perform structured recon and generate reports.11Apache 2.0
- AlicenseAqualityCmaintenanceMCP server that lets AI agents use the Online Cyber Tools catalogue as a set of native MCP tools.1009 npm1MIT
- AlicenseNot gradedqualityCmaintenanceAn MCP server providing 15 OSINT tools over free, public sources for AI agents, enabling domain reconnaissance, subdomain discovery, DNS lookups, host profiling, CVE search, and more without API keys.MIT
- AlicenseCqualityCmaintenanceAI-powered security scanning MCP server that exposes 25+ professional tools, enabling penetration testing and security assessments through natural language interaction with AI agents like Claude Desktop.31MIT
TDQS
Scored across 13 tools
Each tool maps to a distinct reconnaissance technique — IP ownership, port scanning, DNS records/WHOIS, TLS, HTTP security headers, cookies, CORS, HTTP methods, subdomain enumeration, takeover checks, tech detection, well-known files, and the aggregate report — so misselection risk is low. The several *_audit tools are clearly differentiated by target (headers, cookies, methods, well-known files).
Names are uniformly lower_snake_case and mostly follow a predictable `<target>_<operation>` pattern (port_scan, dns_recon, tls_check, cookie_audit). A few entries use noun-like suffixes (ip_info, recon_report, subdomain_takeover) rather than a strict verb, so the convention is consistent but not perfectly uniform.
Thirteen tools is well within the ideal size for a security-recon server; every tool covers a distinct phase or technique and none feels redundant. This scope comfortably supports both targeted checks and the aggregate one-shot report.
The server covers the main recon lifecycle: discovery, DNS/WHOIS/email checks, TLS and HTTP posture, subdomain enumeration/takeover, tech fingerprinting, and a summary report. It omits deeper optional techniques such as banner grabbing, directory brute-forcing, and web vulnerability scanning, but those are reasonable workarounds rather than blocking gaps.