Skip to main content
Glama
dtkmn

MCP ZAP Server

Related Servers

Alternatives to MCP ZAP Server

No user-submitted related servers found.

    Related Servers

    • A
      license
      Not graded
      quality
      A
      maintenance
      Enables AI assistants to drive OWASP ZAP for authorized penetration testing and bug-bounty workflows, including authenticated scans and vulnerability triage through 67 curated safety-gated tools.
      1
      MIT
    • A
      license
      Not graded
      quality
      D
      maintenance
      Integrates OWASP ZAP security testing with AI assistants through MCP, enabling automated vulnerability scanning and AI-powered security analysis during development. Supports multiple scan types including active, passive, and AJAX spider scans with real-time status updates.
      5
      MIT
    • F
      license
      Not graded
      quality
      D
      maintenance
      A lightweight MCP server that wraps OWASP ZAP's REST API as Model Context Protocol tools, enabling AI agents to perform automated security scanning.
      -
    • A
      license
      Not graded
      quality
      D
      maintenance
      Scan APIs for security vulnerabilities and get OWASP risk scores. Detects auth bypass, BOLA/IDOR, data exposure, prompt injection, and 12+ security categories.
      38 npm
      Apache 2.0

    TDQS

    A3.5/5.0

    Scored across 20 tools

    Disambiguation4/5

    Most tools have distinct purposes (crawl, attack, scan history, findings, reports, auth), but zap_scan_history_list, zap_scan_history_get, zap_scan_history_export, and zap_scan_history_customer_handoff all operate on scan history and could be confused without careful reading. The descriptions do clarify different output formats and purposes, so the overlap is manageable.

    Naming Consistency4/5

    The tools consistently use a zap_ prefix followed by a domain area (crawl, attack, scan, report, auth, findings) and a verb (start, stop, status, wait, get, list, export). Minor deviations like zap_findings_summary vs zap_findings_details and zap_scan_history_customer_handoff vs zap_scan_history_export are still readable and follow the general pattern.

    Tool Count4/5

    20 tools is on the higher end but appropriate for a security scanner MCP covering crawl, attack, passive scan, findings, reports, auth, and scan history. Each tool maps to a distinct operation in the ZAP workflow, though a few could potentially be consolidated.

    Completeness4/5

    The tool set covers the main ZAP workflow: import target, prepare/validate auth, crawl, attack, passive scan wait/status, findings summary/details, report generation/read, and scan history export/handoff. Minor gaps include no explicit tool for managing crawl/attack configurations beyond start/stop, and no direct alert management, but the core lifecycle is well covered.

    Maintenance

    ActivityActive
    ResponsivenessWithin a week