dtkmn/mcp-zap-server

A Spring Boot application exposing OWASP ZAP as an MCP (Model Context Protocol) server. It lets any MCP‑compatible AI agent (e.g., Claude Desktop, Cursor) orchestrate ZAP actions—spider, active scan, import OpenAPI specs, and generate reports.

47
/ 100
Emerging

Built on Spring Boot with a queued architecture, it separates scan orchestration from execution via claim-based worker ownership and Postgres-backed durable state, enabling horizontal scaling across multiple replicas. The server exposes both a guided intent-first tool surface and an expert raw-workflow surface, supports authenticated scanning workflows, passive/active scans with policy controls, and integrates findings snapshots with structured correlation IDs and Prometheus observability for production deployments.

No Package No Dependents
Maintenance 13 / 25
Adoption 7 / 25
Maturity 15 / 25
Community 12 / 25

How are scores calculated?

Stars

37

Forks

5

Language

Java

License

MIT

Category

java-mcp-servers

Last pushed

Mar 09, 2026

Commits (30d)

0

Get this data via API

curl "https://pt-edge.onrender.com/api/v1/quality/mcp/dtkmn/mcp-zap-server"

Open to everyone — 100 requests/day, no key needed. Get a free key for 1,000/day.