BrowseFull catalogOutcomesSolve a specific problemRolesStack by teamTrustFilter by risk tier
← Back to the Claude Observatory

mcp-zap-server

Connector Documents & Content Usable

A Spring Boot application exposing OWASP ZAP as an MCP (Model Context Protocol) server. It lets any MCP‑compatible AI agent (e.g., Claude Desktop, Cursor) orchestrate ZAP actions—spider, active scan, import OpenAPI specs, and generate reports.

54 starsApache-2.0 (commercial OK)FreeNo code needed
Usable rating — This tool is functional but has notable gaps. Review the evaluation notes below before deploying.

Embeds OWASP ZAP security scanning directly into AI workflows, letting Claude automate security testing without manual tool switching. Reduces friction for security teams integrating scanning into CI/CD or ad-hoc pentesting.

Security engineers and DevSecOps leads who want Claude to orchestrate vulnerability scanning, parse ZAP reports, and recommend fixes within conversation context.

Claude Code Claude Cowork Claude Chat

https://github.com/dtkmn/mcp-zap-server

By dtkmn

How to Get It

Option 1: Claude Desktop AppOpen the Customize panel in the sidebar → browse connectors → search and add. Works in Claude Code, Claude Cowork, and Claude Chat.
Option 2: Paste into Claude CodeCopy the command below and paste it into a Claude Code conversation. Claude will run it for you.
Command
claude mcp add mcp-zap-server -- npx -y mcp-zap-server

Tip: Paste this into a Claude Code conversation. Verify command matches your Claude Code version.

CostFree

Trust Signals Auto-scanned

Stars54Last updated2026-05-19LicenseApache-2.0 (OK for commercial use)Known CVEsNone foundSources: GitHub Advisory Database + OSV.dev · Scanned 2026-05-20 · scanner v1

Data & Access

Data processingPrompts sent to Anthropic API. Enterprise/Team plans exclude training.

Community Pulse Growing

Discussed on Reddit

9 mentions across 1 sources

Reviewer notes

Auto-scanned review. These are observations, not a security certification.

Scored from trust signals (evidence-eval-v1): 54 GitHub stars; contributors unknown; last commit 1d ago; license Apache-2.0.

How to evaluate tools before deploying →

Data shown here comes from public APIs and automated scanning. Reviewer notes reflect one person's experience. This is not a security certification or legal recommendation. Always evaluate tools according to your own organization's policies.

Evaluation

Ease of Use
3/5
Versatility
3/5
Reliability
3/5
Security
3/5
Overall score3.00 / 5.00 UsableEvaluatedMay 2026
Scored from trust signals (evidence-eval-v1): 54 GitHub stars; contributors unknown; last commit 1d ago; license Apache-2.0.

← Back to the Claude Observatory

Rolling Claude out in your org? Let's talk.

Start a conversation →