What it does
A self-hosted MCP server that gives AI agents access to OWASP ZAP for web security scans. It offers guided spider, active and passive scans, API imports, findings summaries and report generation. An operator controls access with API keys or JWT, tool scopes, runtime policies, rate limits and audit events. It is an independent implementation, not part of the ZAP project.
Use cases
- 01Run a passive scan on a staging website
- 02Import an API definition and scan its endpoints
- 03Generate a findings report for a security review