← Back to browse

OWASP ZAP MCP Server

Indexed by io.github.pierre3

About

MCP server for OWASP ZAP vulnerability scanning with Docker management

Use this server

Add it to your MCP client. The catalogue lists this config verbatim from its source — it does not run, download, or vouch for the server. Review the command before you run it.

Transportstdio (runs a local command)
Env varsZAP_BASE_URL ZAP_API_KEY
Claude Code
claude mcp add --env ZAP_BASE_URL= --env ZAP_API_KEY= zap-mcp -- dnx dotnet-zap-mcp
Cursor

Add to Cursor

If the button doesn't open Cursor, use the JSON below — Cursor accepts the same mcpServers config.

VS Code
code --add-mcp '{"name":"zap-mcp","command":"dnx","args":["dotnet-zap-mcp"],"env":{"ZAP_BASE_URL":"","ZAP_API_KEY":""}}'
JSON
{
  "mcpServers": {
    "zap-mcp": {
      "command": "dnx",
      "args": [
        "dotnet-zap-mcp"
      ],
      "env": {
        "ZAP_BASE_URL": "",
        "ZAP_API_KEY": ""
      }
    }
  }
}

Environment variables are listed by name only — fill in your own values. Entries never carry secrets.