# mcp-zap-server

> mcp-zap-server — dtkmn-mcp-zap-server. Use this tool when you need to integrate vulnerability scanning and web application security testing into your AI workflow, leveraging OWASP ZAP's capabilities through a standardized Model Context Protocol (MCP) interface. It solves problems such as automating security audits and generating reports, accepting inputs like OpenAPI specs and producing outputs like scan reports. Ideal for use cases where AI agents require programmatic control over web application security testing, such as in DevSecOps pipelines or automated testing environments.

Canonical page: https://skillsregistry.net/skills/dtkmn-mcp-zap-server  
JSON: https://api.skillsregistry.net/v1/skills/dtkmn-mcp-zap-server

## Description

Give AI agents a safe, self-hosted ZAP operator for guided web security scans, findings, reports, and production guardrails.

## Trust

- **Trust score (0–1):** 0.71
- **Verification tier:** verified
- **Last scanned:** 2026-09-28

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** container
- **Runtime environment:** vm
- **Category:** ai-ml
- **Updated:** 2026-09-28

## Source

- **Source listing:** [GitHub](https://github.com/dtkmn/mcp-zap-server)

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "dtkmn-mcp-zap-server"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/dtkmn-mcp-zap-server` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/dtkmn-mcp-zap-server/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
