# ZAP MCP Proxy

> Use this tool when you need to automate security scanning and vulnerability detection in your applications. The ZAP MCP Proxy solves problems related to web application security testing by providing a lightweight interface to OWASP ZAP's REST API, accepting inputs such as scan targets and configurations, and outputting vulnerability reports. It is ideal for use cases where automated security testing is required, such as in CI/CD pipelines or penetration testing scenarios.

Canonical page: https://skillsregistry.net/skills/madmystic-zap-mcp-proxy  
JSON: https://api.skillsregistry.net/v1/skills/madmystic-zap-mcp-proxy

## Description

A lightweight MCP server that wraps OWASP ZAP's REST API as Model Context Protocol tools, enabling AI agents to perform automated security scanning.

## Trust

- **Trust score (0–1):** 0.69
- **Verification tier:** scanned
- **Last scanned:** 2026-08-30

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** ai-ml
- **Updated:** 2026-08-30

## Source

- **Source listing:** [Glama](https://glama.ai/mcp/servers/fzujf745mo)
- **Repository:** <https://github.com/madmystic/zap-mcp-proxy>

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "madmystic-zap-mcp-proxy"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/madmystic-zap-mcp-proxy` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/madmystic-zap-mcp-proxy/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
