mcp-zap-server
Embeds OWASP ZAP security scanning directly into AI workflows, letting Claude automate security testing without manual tool switching.
A Spring Boot application exposing OWASP ZAP as an MCP (Model Context Protocol) server. It lets any MCP‑compatible AI agent (e.g., Claude Desktop, Cursor) orchestrate ZAP actions—spider, active scan, import OpenAPI specs, and generate reports.
- Scan API endpoints and auto-generate remediation summaries
- Import OpenAPI specs and run baseline security checks
- Spider web apps and analyze crawl results for anomalies
Embeds OWASP ZAP security scanning directly into AI workflows, letting Claude automate security testing without manual tool switching. Reduces friction for security teams integrating scanning into CI/CD or ad-hoc pentesting.
Security engineers and DevSecOps leads who want Claude to orchestrate vulnerability scanning, parse ZAP reports, and recommend fixes within conversation context.
https://github.com/dtkmn/mcp-zap-server
By dtkmn
How to Get It
git clone https://github.com/dtkmn/mcp-zap-server.git && cd mcp-zap-server && ./bin/bootstrap-local.sh && ./dev.sh # starts the Docker Compose stack; MCP endpoint for clients: http://localhost:7456/mcp
Tip: Paste this into a Claude Code conversation. Verify command matches your Claude Code version.
Once it’s connected, paste this into Claude:
Help me scan API endpoints and auto-generate remediation summaries
Trust Signals Auto-scanned
Data & Access
Community Pulse Growing
Discussed on Reddit
1 mentions across 1 sources
Reviewer notes
Auto-scanned review. These are observations, not a security certification.
catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 63 GitHub stars; 2 contributors; last commit 10d ago; license Apache-2.0.
Things to check
- Scanned, not hands-on tested — this entry was auto-scanned from public metadata (GitHub metrics, license, security flags). No reviewer has run it, and no tool-specific limitations have been documented yet.
How to evaluate tools before deploying →
Data shown here comes from public APIs and automated scanning. Reviewer notes reflect one person's experience. This is not a security certification or legal recommendation. Always evaluate tools according to your own organization's policies.
Evaluation
catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 63 GitHub stars; 2 contributors; last commit 10d ago; license Apache-2.0.