← Back to Plugins
MCP Server MCP

MCP ZAP Server

github By github 👁 1 views ▲ 0 votes

Safe, self-hosted OWASP ZAP operator for guided AI security scans and reports.

Homepage Verified source GitHub

Install

oci:ghcr.io/dtkmn/mcp-zap-server:v0.11.0

Configuration Example

{
  "remotes": [],
  "packages": [
    {
      "registryType": "oci",
      "identifier": "ghcr.io/dtkmn/mcp-zap-server:v0.11.0",
      "runtimeHint": "docker",
      "transport": {
        "type": "streamable-http",
        "url": "http://localhost:7456/mcp",
        "headers": [
          {
            "description": "MCP API key configured with MCP_API_KEY.",
            "isRequired": true,
            "isSecret": true,
            "name": "X-API-Key"
          }
        ]
      },
      "runtimeArguments": [
        {
          "description": "Docker network containing the separately running OWASP ZAP daemon.",
          "value": "mcp-zap-network",
          "type": "named",
          "name": "--network"
        },
        {
          "description": "Run with the standard zaproxy/zap-stable UID/GID so shared report workspace files remain writable by both containers.",
          "value": "1000:1000",
          "type": "named",
          "name": "--user"
        },
        {
          "description": "Expose the streamable HTTP MCP endpoint on localhost.",
          "value": "127.0.0.1:7456:7456",
          "type": "named",
          "name": "-p"
        },
        {
          "description": "Named report workspace volume. The external OWASP ZAP container must mount the same volume at /zap/wrk.",
          "value": "mcp-zap-wrk:/zap/wrk",
          "type": "named",
          "name": "-v"
        }
      ],
      "environmentVariables": [
        {
          "description": "Hostname or URL of a separately running OWASP ZAP daemon reachable from this container.",
          "default": "mcp-zap-zap",
          "name": "ZAP_API_URL"
        },
        {
          "description": "OWASP ZAP API port.",
          "default": "8090",
          "name": "ZAP_API_PORT"
        },
        {
          "description": "API key configured on the OWASP ZAP daemon.",
          "isRequired": true,
          "isSecret": true,
          "name": "ZAP_API_KEY"
        },
        {
          "description": "API key clients must send as X-API-Key.",
          "isRequired": true,
          "isSecret": true,
          "name": "MCP_API_KEY"
        },
        {
          "description": "Tool surface to expose. Use guided for the safer default workflow, including report readback. Use expert only when clients need raw ZAP tools outside the guided surface.",
          "default": "guided",
          "name": "MCP_SERVER_TOOLS_SURFACE"
        },
        {
          "value": "api-key",
          "name": "MCP_SECURITY_MODE"
        },
        {
          "value": "true",
          "name": "MCP_SECURITY_ENABLED"
        },
        {
          "value": "false",
          "name": "MCP_SECURITY_ALLOW_PLACEHOLDER_API_KEY"
        }
      ]
    },
    {
      "registryType": "oci",
      "identifier": "docker.io/dtkmn/mcp-zap-server:v0.11.0",
      "runtimeHint": "docker",
      "transport": {
        "type": "streamable-http",
        "url": "http://localhost:7456/mcp",
        "headers": [
          {
            "description": "MCP API key configured with MCP_API_KEY.",
            "isRequired": true,
            "isSecret": true,
            "name": "X-API-Key"
          }
        ]
      },
      "runtimeArguments": [
        {
          "description": "Docker network containing the separately running OWASP ZAP daemon.",
          "value": "mcp-zap-network",
          "type": "named",
          "name": "--network"
        },
        {
          "description": "Run with the standard zaproxy/zap-stable UID/GID so shared report workspace files remain writable by both containers.",
          "value": "1000:1000",
          "type": "named",
          "name": "--user"
        },
        {
          "description": "Expose the streamable HTTP MCP endpoint on localhost.",
          "value": "127.0.0.1:7456:7456",
          "type": "named",
          "name": "-p"
        },
        {
          "description": "Named report workspace volume. The external OWASP ZAP container must mount the same volume at /zap/wrk.",
          "value": "mcp-zap-wrk:/zap/wrk",
          "type": "named",
          "name": "-v"
        }
      ],
      "environmentVariables": [
        {
          "description": "Hostname or URL of a separately running OWASP ZAP daemon reachable from this container.",
          "default": "mcp-zap-zap",
          "name": "ZAP_API_URL"
        },
        {
          "description": "OWASP ZAP API port.",
          "default": "8090",
          "name": "ZAP_API_PORT"
        },
        {
          "description": "API key configured on the OWASP ZAP daemon.",
          "isRequired": true,
          "isSecret": true,
          "name": "ZAP_API_KEY"
        },
        {
          "description": "API key clients must send as X-API-Key.",
          "isRequired": true,
          "isSecret": true,
          "name": "MCP_API_KEY"
        },
        {
          "description": "Tool surface to expose. Use guided for the safer default workflow, including report readback. Use expert only when clients need raw ZAP tools outside the guided surface.",
          "default": "guided",
          "name": "MCP_SERVER_TOOLS_SURFACE"
        },
        {
          "value": "api-key",
          "name": "MCP_SECURITY_MODE"
        },
        {
          "value": "true",
          "name": "MCP_SECURITY_ENABLED"
        },
        {
          "value": "false",
          "name": "MCP_SECURITY_ALLOW_PLACEHOLDER_API_KEY"
        }
      ]
    }
  ]
}
mcp model-context-protocol oci

Comments

Sign in to leave a comment

Loading comments...