{"name":"io.github.dtkmn/mcp-zap-server","slug":"dtkmn-mcp-zap-server","title":"MCP ZAP Server","description":"Safe, self-hosted OWASP ZAP operator for guided AI security scans and reports.","url":"https://mcp.market/server/dtkmn-mcp-zap-server","rating":null,"grade":"B","score":73,"certified":false,"status":"active","category":"security","tags":["security"],"presence":{"score":35,"stars":66,"forks":11,"downloads_week":null,"last_push_at":"2026-09-22T13:18:14.000Z","license":"Apache-2.0"},"uptime":null,"claimed":false,"transport":"oci","callable_via_gateway":false,"default_price_micros":0,"repository":"https://github.com/dtkmn/mcp-zap-server","website":"https://danieltse.org/mcp-zap-server/","version":"0.11.0","remotes":[],"packages":[{"registryType":"oci","identifier":"ghcr.io/dtkmn/mcp-zap-server:v0.11.0","runtimeHint":"docker","transport":{"type":"streamable-http","url":"http://localhost:7456/mcp","headers":[{"description":"MCP API key configured with MCP_API_KEY.","isRequired":true,"isSecret":true,"name":"X-API-Key"}]},"runtimeArguments":[{"description":"Docker network containing the separately running OWASP ZAP daemon.","value":"mcp-zap-network","type":"named","name":"--network"},{"description":"Run with the standard zaproxy/zap-stable UID/GID so shared report workspace files remain writable by both containers.","value":"1000:1000","type":"named","name":"--user"},{"description":"Expose the streamable HTTP MCP endpoint on localhost.","value":"127.0.0.1:7456:7456","type":"named","name":"-p"},{"description":"Named report workspace volume. The external OWASP ZAP container must mount the same volume at /zap/wrk.","value":"mcp-zap-wrk:/zap/wrk","type":"named","name":"-v"}],"environmentVariables":[{"description":"Hostname or URL of a separately running OWASP ZAP daemon reachable from this container.","default":"mcp-zap-zap","name":"ZAP_API_URL"},{"description":"OWASP ZAP API port.","default":"8090","name":"ZAP_API_PORT"},{"description":"API key configured on the OWASP ZAP daemon.","isRequired":true,"isSecret":true,"name":"ZAP_API_KEY"},{"description":"API key clients must send as X-API-Key.","isRequired":true,"isSecret":true,"name":"MCP_API_KEY"},{"description":"Tool surface to expose. Use guided for the safer default workflow, including report readback. Use expert only when clients need raw ZAP tools outside the guided surface.","default":"guided","name":"MCP_SERVER_TOOLS_SURFACE"},{"value":"api-key","name":"MCP_SECURITY_MODE"},{"value":"true","name":"MCP_SECURITY_ENABLED"},{"value":"false","name":"MCP_SECURITY_ALLOW_PLACEHOLDER_API_KEY"}]},{"registryType":"oci","identifier":"docker.io/dtkmn/mcp-zap-server:v0.11.0","runtimeHint":"docker","transport":{"type":"streamable-http","url":"http://localhost:7456/mcp","headers":[{"description":"MCP API key configured with MCP_API_KEY.","isRequired":true,"isSecret":true,"name":"X-API-Key"}]},"runtimeArguments":[{"description":"Docker network containing the separately running OWASP ZAP daemon.","value":"mcp-zap-network","type":"named","name":"--network"},{"description":"Run with the standard zaproxy/zap-stable UID/GID so shared report workspace files remain writable by both containers.","value":"1000:1000","type":"named","name":"--user"},{"description":"Expose the streamable HTTP MCP endpoint on localhost.","value":"127.0.0.1:7456:7456","type":"named","name":"-p"},{"description":"Named report workspace volume. The external OWASP ZAP container must mount the same volume at /zap/wrk.","value":"mcp-zap-wrk:/zap/wrk","type":"named","name":"-v"}],"environmentVariables":[{"description":"Hostname or URL of a separately running OWASP ZAP daemon reachable from this container.","default":"mcp-zap-zap","name":"ZAP_API_URL"},{"description":"OWASP ZAP API port.","default":"8090","name":"ZAP_API_PORT"},{"description":"API key configured on the OWASP ZAP daemon.","isRequired":true,"isSecret":true,"name":"ZAP_API_KEY"},{"description":"API key clients must send as X-API-Key.","isRequired":true,"isSecret":true,"name":"MCP_API_KEY"},{"description":"Tool surface to expose. Use guided for the safer default workflow, including report readback. Use expert only when clients need raw ZAP tools outside the guided surface.","default":"guided","name":"MCP_SERVER_TOOLS_SURFACE"},{"value":"api-key","name":"MCP_SECURITY_MODE"},{"value":"true","name":"MCP_SECURITY_ENABLED"},{"value":"false","name":"MCP_SECURITY_ALLOW_PLACEHOLDER_API_KEY"}]}],"tools":[],"scan":{"score":73,"grade":"B","scanned_at":"2026-09-24T21:40:35.790Z","report":{"scannerVersion":"0.1.9","scannedAt":"2026-09-24T21:40:35.732Z","components":{"code":{"score":-1,"max":25,"notes":["package could not be scanned"]},"reliability":{"score":-1,"max":20,"notes":["no gateway calls yet and no remote to probe"]},"poisoning":{"score":-1,"max":15,"notes":["tools not inspected (local package is not executed); not counted"]},"auth":{"score":6,"max":15,"notes":["static API keys via environment variables"]},"maintenance":{"score":15,"max":15,"notes":["last push 2 days ago"]},"identity":{"score":8,"max":10,"notes":["registry namespace matches repository owner","GitHub account older than a year"]}},"findings":[],"inputs":{"packages":[],"repo":{"found":true,"owner":"dtkmn","repo":"mcp-zap-server","archived":false,"pushedAt":"2026-09-22T13:18:14Z","stars":66,"forks":11,"openIssues":3,"ownerType":"User","ownerAvatarUrl":"https://avatars.githubusercontent.com/u/714521?v=4","ownerCreatedAt":"2011-04-07T04:36:31Z","license":"Apache-2.0"},"icon":{"url":"https://raw.githubusercontent.com/dtkmn/mcp-zap-server/main/images/brand.png","source":"registry","width":1024,"height":1024},"presence":{"stars":66,"forks":11,"downloadsWeek":null,"license":"Apache-2.0","lastPushAt":"2026-09-22T13:18:14.000Z","score":35}}}},"grade_history":[],"reviews":[]}