Owned-target web security assessment MCP server for authenticated, high-friction apps.
Analyst-first web application assessment workflow for authenticated, challenge-heavy, and edge-protected targets. It combines passive AI analysis, operator-controlled browser depth, deterministic active probing, and verification-first reporting to find chainable auth, workflow, API, and exposure risk without collapsing into generic scanner noise. v0.8.1 — 9 passive AI agents + 32 deterministic…
Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts — it cannot prove the absence of malicious code.
Analyst-first web application assessment workflow for authenticated, challenge-heavy, and edge-protected targets. It combines passive AI analysis, operator-controlled browser depth, deterministic active probing, and verification-first reporting to find chainable auth, workflow, API, and exposure risk without collapsing into generic scanner noise. v0.8.1 — 9 passive AI agents + 32 deterministic active agents + 4 advanced AI attack-intelligence modules. New in v0.8.x: Hypothesis Engine generates…