# OWASP ZAP

> Use this tool when you need to perform comprehensive web application security testing, identifying vulnerabilities and weaknesses through active scanning, passive analysis, and crawling. It solves problems related to security assessments, penetration testing, and integration of security scanning into development pipelines. The tool takes web application URLs and scan policies as inputs and outputs vulnerability reports and evidence, making it ideal for security professionals and developers seeking AI-assisted security testing.

Canonical page: https://skillsregistry.net/skills/lisberndt-zap  
JSON: https://api.skillsregistry.net/v1/skills/lisberndt-zap

## Description

This ZAP MCP server by LisBerndt provides AI assistants with comprehensive web application security testing capabilities through OWASP ZAP integration, offering both synchronous and asynchronous scanning modes including active vulnerability scanning, passive analysis, traditional spidering, and AJAX crawling with configurable browser engines. Built with Python and FastAPI, it features Docker containerization with automatic ZAP startup, session management with unique timestamping, progress tracking with heartbeat mechanisms to prevent timeouts, and configurable scan policies with evidence collection options. The implementation includes robust HTTP session handling with retry logic, extensive logging capabilities, and supports both direct MCP protocol communication and HTTP endpoints, making it ideal for security professionals and developers who need AI-assisted vulnerability assessment, automated penetration testing workflows, and integration of security scanning into development pipelines through their existing ZAP infrastructure.

## Trust

- **Trust score (0–1):** 0.68
- **Verification tier:** scanned
- **Last scanned:** 2026-09-28

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** cloud-infra
- **Updated:** 2026-09-28

## Source

- **Source listing:** [PulseMCP](https://www.pulsemcp.com/servers/lisberndt-zap)
- **Repository:** <https://github.com/lisberndt/zap-mcp-server>

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "lisberndt-zap"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/lisberndt-zap` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/lisberndt-zap/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
