MCP Server
MCP
MCP ZAP Server
Safe, self-hosted OWASP ZAP operator for guided AI security scans and reports.
Install
oci:ghcr.io/dtkmn/mcp-zap-server:v0.11.0
Configuration Example
{
"remotes": [],
"packages": [
{
"registryType": "oci",
"identifier": "ghcr.io/dtkmn/mcp-zap-server:v0.11.0",
"runtimeHint": "docker",
"transport": {
"type": "streamable-http",
"url": "http://localhost:7456/mcp",
"headers": [
{
"description": "MCP API key configured with MCP_API_KEY.",
"isRequired": true,
"isSecret": true,
"name": "X-API-Key"
}
]
},
"runtimeArguments": [
{
"description": "Docker network containing the separately running OWASP ZAP daemon.",
"value": "mcp-zap-network",
"type": "named",
"name": "--network"
},
{
"description": "Run with the standard zaproxy/zap-stable UID/GID so shared report workspace files remain writable by both containers.",
"value": "1000:1000",
"type": "named",
"name": "--user"
},
{
"description": "Expose the streamable HTTP MCP endpoint on localhost.",
"value": "127.0.0.1:7456:7456",
"type": "named",
"name": "-p"
},
{
"description": "Named report workspace volume. The external OWASP ZAP container must mount the same volume at /zap/wrk.",
"value": "mcp-zap-wrk:/zap/wrk",
"type": "named",
"name": "-v"
}
],
"environmentVariables": [
{
"description": "Hostname or URL of a separately running OWASP ZAP daemon reachable from this container.",
"default": "mcp-zap-zap",
"name": "ZAP_API_URL"
},
{
"description": "OWASP ZAP API port.",
"default": "8090",
"name": "ZAP_API_PORT"
},
{
"description": "API key configured on the OWASP ZAP daemon.",
"isRequired": true,
"isSecret": true,
"name": "ZAP_API_KEY"
},
{
"description": "API key clients must send as X-API-Key.",
"isRequired": true,
"isSecret": true,
"name": "MCP_API_KEY"
},
{
"description": "Tool surface to expose. Use guided for the safer default workflow, including report readback. Use expert only when clients need raw ZAP tools outside the guided surface.",
"default": "guided",
"name": "MCP_SERVER_TOOLS_SURFACE"
},
{
"value": "api-key",
"name": "MCP_SECURITY_MODE"
},
{
"value": "true",
"name": "MCP_SECURITY_ENABLED"
},
{
"value": "false",
"name": "MCP_SECURITY_ALLOW_PLACEHOLDER_API_KEY"
}
]
},
{
"registryType": "oci",
"identifier": "docker.io/dtkmn/mcp-zap-server:v0.11.0",
"runtimeHint": "docker",
"transport": {
"type": "streamable-http",
"url": "http://localhost:7456/mcp",
"headers": [
{
"description": "MCP API key configured with MCP_API_KEY.",
"isRequired": true,
"isSecret": true,
"name": "X-API-Key"
}
]
},
"runtimeArguments": [
{
"description": "Docker network containing the separately running OWASP ZAP daemon.",
"value": "mcp-zap-network",
"type": "named",
"name": "--network"
},
{
"description": "Run with the standard zaproxy/zap-stable UID/GID so shared report workspace files remain writable by both containers.",
"value": "1000:1000",
"type": "named",
"name": "--user"
},
{
"description": "Expose the streamable HTTP MCP endpoint on localhost.",
"value": "127.0.0.1:7456:7456",
"type": "named",
"name": "-p"
},
{
"description": "Named report workspace volume. The external OWASP ZAP container must mount the same volume at /zap/wrk.",
"value": "mcp-zap-wrk:/zap/wrk",
"type": "named",
"name": "-v"
}
],
"environmentVariables": [
{
"description": "Hostname or URL of a separately running OWASP ZAP daemon reachable from this container.",
"default": "mcp-zap-zap",
"name": "ZAP_API_URL"
},
{
"description": "OWASP ZAP API port.",
"default": "8090",
"name": "ZAP_API_PORT"
},
{
"description": "API key configured on the OWASP ZAP daemon.",
"isRequired": true,
"isSecret": true,
"name": "ZAP_API_KEY"
},
{
"description": "API key clients must send as X-API-Key.",
"isRequired": true,
"isSecret": true,
"name": "MCP_API_KEY"
},
{
"description": "Tool surface to expose. Use guided for the safer default workflow, including report readback. Use expert only when clients need raw ZAP tools outside the guided surface.",
"default": "guided",
"name": "MCP_SERVER_TOOLS_SURFACE"
},
{
"value": "api-key",
"name": "MCP_SECURITY_MODE"
},
{
"value": "true",
"name": "MCP_SECURITY_ENABLED"
},
{
"value": "false",
"name": "MCP_SECURITY_ALLOW_PLACEHOLDER_API_KEY"
}
]
}
]
}
mcp
model-context-protocol
oci
By
Comments
Sign in to leave a comment