mcp-zap-serverCAUTION
Give AI agents a safe, self-hosted ZAP operator for guided web security scans, findings, reports, and production guardrails.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
MCP ZAP Server
Give AI agents a safe, self-hosted ZAP operator for guided web security scans, findings, reports, and production guardrails.
Note This project is not affiliated with or endorsed by the ZAP project. It is an independent implementation.
mcp-zap-server exposes ZAP through MCP over streamable HTTP so agentic tools can run operator-controlled security workflows without brittle glue scripts or unsafe scanner access.
Use it when you want:
- safe agentic scanning with guided defaults for spider, active scan, passive scan, API imports, findings, and reports
- operator control through API-key or JWT auth, tool scopes, runtime policy bundles, rate limits, and audit events
- self-hosted deployment with Docker Compose for local adoption and Helm for Kubernetes
- expert ZAP access when you intentionally need lower-level ZAP context, user, scan, and report controls
Full documentation: danieltse.org/mcp-zap-server
Watch the demo: browser demo or YouTube
Quick Start
Prerequisites:
- Docker 20.10+
- Docker Compose v2 (`docker compo
0f0d122d2f46OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcp-zap-server:v0.15.0 --env ZAP_API_KEY=${ZAP_API_KEY} --env MCP_API_KEY=${MCP_API_KEY} --env ZAP_API_KEY=${ZAP_API_KEY} --env MCP_API_KEY=${MCP_API_KEY} -- docker run -i --rm ghcr.io/dtkmn/mcp-zap-server:v0.15.0:Noneclaude mcp add mcp-zap-server:v0.15.0 --env ZAP_API_KEY=${ZAP_API_KEY} --env MCP_API_KEY=${MCP_API_KEY} --env ZAP_API_KEY=${ZAP_API_KEY} --env MCP_API_KEY=${MCP_API_KEY} -- docker run -i --rm docker.io/dtkmn/mcp-zap-server:v0.15.0:NoneTrust audit
CAUTIONgrade D · trust 61/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (4 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
gradle-wrapper.jar
CMD ["/usr/local/bin/http-healthcheck", "http://127.0.0.1:7456/actuator/health"]
api_key="your-generated-mcp-api-key",
private static final String API_KEY = "synthetic-outage-api-key";
private static final String API_KEY = "claude-desktop-api-key";
private static final String SECRET = "synthetic-lifetime-secret-at-least-32-characters";
token = "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9." + payload.decode().rstrip("=") + "." + token_urlsafe(24).helmignore
'../../examples/cursor/mcp.json': 'https://github.com/dtkmn/mcp-zap-server/blob/main/examples/cursor/mcp.json',
'../../../examples/aws-ec2/': 'https://github.com/dtkmn/mcp-zap-server/tree/main/examples/aws-ec2',
'../../../helm/mcp-zap-server/README.md': 'https://github.com/dtkmn/mcp-zap-server/blob/main/helm/mcp-zap-server/README.md',
"/zap/wrk/../../tmp/secret.txt",
checks = [('smoke-target', 8080, True), ('169.254.169.254', 80, False),+ "jobs: [{type: requestor, requests: [{url: 'http://169.254.169.254/'}]}]\n");ENV + "jobs: [{type: requestor, requests: [{url: 'http://169.254.169.254/'}]}]",ENV + "requests: &requests [{url: 'http://169.254.169.254/'}]\njobs: [{type: requestor, requests: *requests}]","http://169.254.169.254/api", "http://0.0.0.0/api", "http://224.0.0.1/api",
parser.add_argument("--zap-proxy-url", default="http://127.0.0.1:8090")"--zap-proxy-url" "${INPUT_ZAP_PROXY_URL:-http://127.0.0.1:8090}"Your client endpoint is now **`http://127.0.0.1:17456/mcp`**. Configure your MCP
'http://127.0.0.1:8090/JSON/core/action/accessUrl/' \
@astrojs/sitemap, @astrojs/starlight, @fontsource/ibm-plex-mono, @fontsource/rajdhani, astro, sharp, @astrojs/check, typescript
- Normal unauthenticated scans and MCP access authentication through API keys or JWT remain supported.
use Spring configuration; the application does not automatically read `.env`.
No access credential is required. Never expose this mode to other users or
Gates applied: no_behavioural_pass.
0f0d122d2f46full audit observations/trust-audit/mcp-server/dtkmn__mcp-zap-server.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 0f0d122d2f46 | CAUTION | D | 61 | first audit |
Questions
What is the mcp-zap-server MCP server?
Give AI agents a safe, self-hosted ZAP operator for guided web security scans, findings, reports, and production guardrails.
Is mcp-zap-server safe to connect to an agent?
With care. The audit graded it D (61/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does mcp-zap-server need?
It reads MCP_API_KEY and ZAP_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does mcp-zap-server run?
It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as docs at 0.0.1.
How current is this page?
The grade is for one exact copy of the source (0f0d122d2f46), read on 2026-10-07. The repository is watched and re-audited when it changes.