Skip to content
mcp/skillhub

OWASP ZAP MCP Server

by pierre3io.github.pierre3/zap-mcpv1.1.0

MCP server for OWASP ZAP vulnerability scanning with Docker management

4.NETstdioofficial registry

context tax

queued

security

queued

cold start

queued

freshness

Stale6mo ago

Install OWASP ZAP MCP server

Install in Claude Code

claude mcp add dotnet-zap -- dnx dotnet-zap-mcp --yes

Configuration

VariableRequiredSecretDescription
ZAP_BASE_URL——ZAP API base URL (default: http://localhost:8090)
ZAP_API_KEY——ZAP API key. Auto-generated if not set and DockerComposeUp is used.

Freshness

Stale — last maintenance signal 6mo ago. The newest of the signals below sets the band.

  1. Last commit (default branch)

    2026-03-31 · 6mo ago · GitHub

  2. Latest release

    no data · GitHub

  3. Package published

    no data · npm/PyPI

  4. Registry entry updated

    2026-03-31 · 6mo ago · official registry · v1.1.0

FAQ

›How do I install the OWASP ZAP MCP server in Claude Code?

Run: claude mcp add dotnet-zap -- dnx dotnet-zap-mcp --yes. For Cursor, VS Code, Claude Desktop and Windsurf, use the install tabs above.

›Does OWASP ZAP require an API key?

No required environment variables are declared in its published metadata.

›Can I use OWASP ZAP as a remote (hosted) MCP server?

No hosted endpoint is published; it runs locally over stdio.

›Is OWASP ZAP in the official MCP registry?

Yes, as io.github.pierre3/zap-mcp.

Alternatives to OWASP ZAP

Other devops & ci/cd MCP servers.

View all