BrowseFull catalogOutcomesSolve a specific problemRolesStack by teamTrustFilter by risk tier
← Back to the Claude Observatory

mcp-zap-server

Connector Documents & Content Usable
Works inClaude Code Claude Cowork Claude Chat
Usable Scanned — metadata only

Embeds OWASP ZAP security scanning directly into AI workflows, letting Claude automate security testing without manual tool switching.

A Spring Boot application exposing OWASP ZAP as an MCP (Model Context Protocol) server. It lets any MCP‑compatible AI agent (e.g., Claude Desktop, Cursor) orchestrate ZAP actions—spider, active scan, import OpenAPI specs, and generate reports.

63 starsApache-2.0 (commercial OK)FreeNo code needed
Usable rating — This tool is functional but has notable gaps. Review the evaluation notes below before deploying.

Embeds OWASP ZAP security scanning directly into AI workflows, letting Claude automate security testing without manual tool switching. Reduces friction for security teams integrating scanning into CI/CD or ad-hoc pentesting.

Security engineers and DevSecOps leads who want Claude to orchestrate vulnerability scanning, parse ZAP reports, and recommend fixes within conversation context.

Claude Code Claude Cowork Claude Chat

https://github.com/dtkmn/mcp-zap-server

By dtkmn

How to Get It

Option 1: Claude Desktop AppOpen the Customize panel in the sidebar → browse connectors → search and add. Works in Claude Code, Claude Cowork, and Claude Chat.
Option 2: Paste into Claude CodeCopy the command below and paste it into a Claude Code conversation. Claude will run it for you.
Command
git clone https://github.com/dtkmn/mcp-zap-server.git && cd mcp-zap-server && ./bin/bootstrap-local.sh && ./dev.sh  # starts the Docker Compose stack; MCP endpoint for clients: http://localhost:7456/mcp

Tip: Paste this into a Claude Code conversation. Verify command matches your Claude Code version.

First thing to try

Once it’s connected, paste this into Claude:

Help me scan API endpoints and auto-generate remediation summaries
PrerequisitesDocker 20.10+ and Docker Compose v2, plus an MCP-capable client (or the bundled Open WebUI). The server runs alongside an OWASP ZAP sidecar container with explicit auth keys.CostFree

Trust Signals Auto-scanned

Stars63Contributors2Last updated2026-08-08LicenseApache-2.0 (OK for commercial use)Known CVEsNone foundSources: GitHub Advisory Database + OSV.dev · Scanned 2026-08-11 · scanner vattempted-no-data

Data & Access

Data processingPrompts sent to Anthropic API. Enterprise/Team plans exclude training.

Community Pulse Growing

Discussed on Reddit

1 mentions across 1 sources

Reviewer notes

Auto-scanned review. These are observations, not a security certification.

catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 63 GitHub stars; 2 contributors; last commit 10d ago; license Apache-2.0.

Things to check

  • Scanned, not hands-on tested — this entry was auto-scanned from public metadata (GitHub metrics, license, security flags). No reviewer has run it, and no tool-specific limitations have been documented yet.

How to evaluate tools before deploying →

Data shown here comes from public APIs and automated scanning. Reviewer notes reflect one person's experience. This is not a security certification or legal recommendation. Always evaluate tools according to your own organization's policies.

Evaluation

Ease of Use
3/5
Versatility
3/5
Reliability
3/5
Security
4/5
Overall score3.15 / 5.00 UsableEvaluatedAug 2026
catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 63 GitHub stars; 2 contributors; last commit 10d ago; license Apache-2.0.

← Back to the Claude Observatory

Rolling Claude out in your org? Let's talk.

Start a conversation →