dtkmn/mcp-zap-server

A Spring Boot application exposing OWASP ZAP as an MCP (Model Context Protocol) server. It lets any MCP‑compatible AI agent (e.g., Claude Desktop, Cursor) orchestrate ZAP actions—spider, active scan, import OpenAPI specs, and generate reports.

44
/ 100
Emerging

This project helps security professionals and developers automate web application security testing. It connects OWASP ZAP, a popular vulnerability scanner, with AI agents like Claude Desktop or Cursor. You provide the web application to be scanned, and the AI agent orchestrates ZAP actions like spidering, active scanning, and report generation, giving you structured security findings and reports.

Use this if you want to integrate automated web vulnerability scanning directly into your AI-powered development or security workflows without manual command-line interaction.

Not ideal if you prefer to run ZAP entirely manually or programmatically via its native API, or if you do not use an MCP-compatible AI agent.

web-security-testing vulnerability-scanning application-security DevSecOps AI-assisted-development
No Package No Dependents
Maintenance 10 / 25
Adoption 7 / 25
Maturity 15 / 25
Community 12 / 25

How are scores calculated?

Stars

37

Forks

5

Language

Java

License

MIT

Category

java-mcp-servers

Last pushed

Mar 09, 2026

Commits (30d)

0

Get this data via API

curl "https://pt-edge.onrender.com/api/v1/quality/mcp/dtkmn/mcp-zap-server"

Open to everyone — 100 requests/day, no key needed. Get a free key for 1,000/day.