zap-mcp-server

LisBerndt/zap-mcp-server

3.3

If you are the rightful owner of zap-mcp-server and would like to certify it and/or have it hosted online, please leave a comment on the right or send an email to henry@mcphub.com.

The ZAP MCP Server is a robust Model Context Protocol (MCP) Server that integrates OWASP ZAP with AI assistants and MCP clients, enabling AI-powered security testing through automated vulnerability scanning.

Tools

Functions exposed to the LLM to take actions

start_active_scan

Run active security scan (Spider + Active).

start_complete_scan

Run complete scan (AJAX + Spider + Active + Passive).

start_passive_scan

Run passive security analysis.

start_ajax_scan

Run AJAX spider for modern web apps.

get_scan_status

Get real-time scan status.

Prompts

Interactive templates invoked by user choice

No prompts

Resources

Contextual data attached and managed by the client

No resources