MCP ZAP Server
Safe, self-hosted OWASP ZAP operator for guided AI security scans and reports.
io.github.dtkmn/mcp-zap-server · Repository · Website · version 0.11.0 · 63 stars · listed from registry
Install
The sweep pulls the image and runs it in a throwaway container, but this is the command a user would run:
docker run -i --rm ghcr.io/dtkmn/mcp-zap-server:v0.11.0
Needs credentials: ZAP_API_KEY, MCP_API_KEY. The probe used placeholder values, so an amber needs credentials result below means the server asked for the real ones, not that it is broken. Maintainers: how to go green.
Results by platform
Linux
timed out2026-08-16 · probed over oci2 recorded runs, oldest first.
handshake failed: MCP error -32001: Request timed out transport: ition 4 (line 1 column 5) Unexpected non-whitespace character after JSON at position 4 (line 1 column 5) Unexpected non-whitespace character after JSON at position 4 (line 1 column 5) Unexpected non-whitespace character after JSON at position 4 (line 1 column 5) Unexpected non-whitespace character after JSON at position 4 (line 1 column 5) Unexpected non-whitespace character after JSON at position 4 (line 1 column 5) Unexpected non-whitespace character after JSON at position 4 (line 1 column 5) --- stderr (tail) --- WARNING: A restricted method in java.lang.System has been called WARNING: java.lang.System::loadLibrary has been called by io.netty.util.internal.NativeLibraryUtil in an unnamed module (jar:nested:/app/app.jar/!BOOT-INF/lib/netty-common-4.2.16.Final.jar!/) WARNING: Use --enable-native-access=ALL-UNNAMED to avoid a warning for callers in this module WARNING: Restricted methods will be blocked in a future release unless native access is enabled
macOS
not tested2026-08-162 recorded runs, oldest first.
docker not available on this runner, so container distributions are probed on Linux only
Windows
not tested2026-08-162 recorded runs, oldest first.
docker not available on this runner, so container distributions are probed on Linux only
Badge
Paste this into the project README to show the current result:
[](https://doesitinstall.com/s/io.github.dtkmn__mcp-zap-server.html)