OWASP ZAP
This ZAP MCP server by LisBerndt provides AI assistants with comprehensive web application security testing capabilities through OWASP ZAP integration, offering both synchronous and asynchronous scanning modes including active vulnerability scanning, passive analysis, traditional spidering, and AJAX crawling with configurable browser engines. Built with Python and FastAPI, it features Docker containerization with automatic ZAP startup, session management with unique timestamping, progress tracking with heartbeat mechanisms to prevent timeouts, and configurable scan policies with evidence collection options. The implementation includes robust HTTP session handling with retry logic, extensive logging capabilities, and supports both direct MCP protocol communication and HTTP endpoints, making it ideal for security professionals and developers who need AI-assisted vulnerability assessment, automated penetration testing workflows, and integration of security scanning into development pipelines through their existing ZAP infrastructure.
Composite of vulnerability cleanliness, spec conformance, provenance, stability, and usage signals — scanned and weighted by Cognium. Human and agent signals are tracked separately. Last scanned 2026-09-28.
Scan details: Circle-IR · 2026-09-28 · Appeal
View full trust & usage report →Metadata
- Version
- 1.0.0
- Skill type
- atomic
- Execution layer
- mcp-remote
- Category
- cloud-infra
- Source
- PulseMCP
- Repository
- github.com/lisberndt/zap-mcp-server
- Author type
- human
- Last scanned
- 2026-09-28
- Updated
- 2026-09-28
Use via MCP
Resolve OWASP ZAP from your agent
Streamable HTTP transport at https://api.skillsregistry.net/mcp. No auth for read tools. Discovery: .well-known/mcp.json.
One command in your shell — Claude Code wires it up and verifies the connection. Run /mcp in any session to confirm.
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp --scope user for --scope project to commit it to .mcp.json.