ZAP-MCP: Model Context Protocol for OWASP ZAP

Created By
ajtazera year ago
VIBE CODING 😈 lol
Overview

what is ZAP-MCP?

ZAP-MCP is a powerful integration between OWASP ZAP and AI models through the Model Context Protocol (MCP), enabling AI-driven security testing by allowing AI models to interact directly with ZAP's scanning capabilities.

how to use ZAP-MCP?

To use ZAP-MCP, clone the repository, install dependencies, set up the MCP server, and configure your AI model (like Claude) to connect to the ZAP-MCP server for security scanning.

key features of ZAP-MCP?

  • AI-Driven Security Testing: Perform security scans and analysis using AI models.
  • Real-time Scan Monitoring: Track scan progress and receive instant alerts.
  • Automated Analysis: Generate security reports and recommendations.
  • Flexible Integration: Works with various AI models through the MCP protocol.
  • WebSocket Communication: Provides real-time updates and interactions.

use cases of ZAP-MCP?

  1. Automating security testing for web applications.
  2. Integrating AI models for enhanced security analysis.
  3. Generating detailed security reports for compliance.

FAQ from ZAP-MCP?

  • What is the required setup for ZAP-MCP?

You need Python 3.8+, OWASP ZAP, and a compatible AI model like Claude.

  • Is ZAP-MCP free to use?

Yes! ZAP-MCP is open-source and free to use.

  • Can ZAP-MCP work with other AI models?

Yes! It is designed to work with various AI models through the MCP protocol.

Project Info
Created At
a year ago
Updated At
a year ago
Author Name
ajtazer
Star
3
Language
Python
License
-

Recommend Servers

View All
Bring your real authenticated browser session to AI coding agents. Local-first MCP server + Chrome MV3 extension. No cloud. No telemetry.
@Cubenest

peek records the user's actual logged-in browser (DOM via rrweb, console events, network metadata, optional response bodies via opt-in Deep capture) through a Chrome MV3 extension. The extension ships events through a native-messaging stdio bridge to a local MCP server (peek-mcp), which persists them to a SQLite database at ~/.peek/sessions.db. AI coding agents (Claude Code, Cursor, Cline, Windsurf) read sessions from the database via 10 MCP tools: Tool What it does list_recent_sessions List recently recorded sessions (id, origin, ts, event count). get_session_summary LLM-readable narrative summary of a session. get_session_console_errors Console errors recorded in a session. get_session_network_errors Failed/notable network requests in a session. get_user_action_before_error Last N user actions before a console error. generate_playwright_repro Generate a runnable Playwright test from a session. get_dom_snapshot Reconstruct the DOM at a given timestamp. query_dom_history Timeline of attribute/text changes for a selector. request_authorization Side-panel consent for write actions (Level 3). execute_action Dispatch a UI action (gated by permission level + destructive blocklist). Why local-first matters Every other "browser session for AI" tool ships to a vendor cloud. peek's SQLite + extension live on the user's machine — no remote endpoints, no telemetry. The privacy policy (docs/peek/PRIVACY_POLICY.md) is the source of truth. Install # 1. Add the MCP server to Claude Code claude mcp add peek -- npx -y @peekdev/mcp # 2. Install the Chrome extension from the Chrome Web Store # (link added once the CWS listing is approved)

a day ago
Crevio

2 days ago