MCP ZAP Server
Related Servers
Alternatives to MCP ZAP Server
No user-submitted related servers found.
Related Servers
- AlicenseNot gradedqualityAmaintenanceEnables AI assistants to drive OWASP ZAP for authorized penetration testing and bug-bounty workflows, including authenticated scans and vulnerability triage through 67 curated safety-gated tools.1MIT
- AlicenseNot gradedqualityDmaintenanceEnables AI agents to drive OWASP ZAP vulnerability scanning via the Model Context Protocol.4MIT
- AlicenseNot gradedqualityDmaintenanceIntegrates OWASP ZAP security testing with AI assistants through MCP, enabling automated vulnerability scanning and AI-powered security analysis during development. Supports multiple scan types including active, passive, and AJAX spider scans with real-time status updates.5MIT
- FlicenseNot gradedqualityDmaintenanceA lightweight MCP server that wraps OWASP ZAP's REST API as Model Context Protocol tools, enabling AI agents to perform automated security scanning.-
- AlicenseAqualityFmaintenanceMulti-engine container and system vulnerability scanning for AI agents. Wraps Trivy and Grype with cross-engine validation, SBOM generation, and IaC misconfiguration scanning.1525 npmMIT
- AlicenseNot gradedqualityDmaintenanceScan APIs for security vulnerabilities and get OWASP risk scores. Detects auth bypass, BOLA/IDOR, data exposure, prompt injection, and 12+ security categories.38 npmApache 2.0
TDQS
Scored across 20 tools
Most tools have distinct purposes (crawl, attack, scan history, findings, reports, auth), but zap_scan_history_list, zap_scan_history_get, zap_scan_history_export, and zap_scan_history_customer_handoff all operate on scan history and could be confused without careful reading. The descriptions do clarify different output formats and purposes, so the overlap is manageable.
The tools consistently use a zap_ prefix followed by a domain area (crawl, attack, scan, report, auth, findings) and a verb (start, stop, status, wait, get, list, export). Minor deviations like zap_findings_summary vs zap_findings_details and zap_scan_history_customer_handoff vs zap_scan_history_export are still readable and follow the general pattern.
20 tools is on the higher end but appropriate for a security scanner MCP covering crawl, attack, passive scan, findings, reports, auth, and scan history. Each tool maps to a distinct operation in the ZAP workflow, though a few could potentially be consolidated.
The tool set covers the main ZAP workflow: import target, prepare/validate auth, crawl, attack, passive scan wait/status, findings summary/details, report generation/read, and scan history export/handoff. Minor gaps include no explicit tool for managing crawl/attack configurations beyond start/stop, and no direct alert management, but the core lifecycle is well covered.