AgentHubAgentHub

MCP ZAP Server MCP Setup & Guide

MCP ServerMCP RegistryOfficial

io.github.dtkmn/mcp-zap-server · v0.14.0

Safe, self-hosted ZAP operator for guided AI security scans and reports.

Copy the install config on this page first, then verify docs and permissions upstream.

Overview

Safe, self-hosted ZAP operator for guided AI security scans and reports. MCP ZAP Server is a MCP Server listed from MCP Registry. Transports: streamable-http. This page includes an overview, setup tutorial, install commands, and use cases for Trae, Tongyi Lingma, Cursor, Claude Code, and VS Code.

Use cases

AgentHub Verified AvailabilityTested & Ready

Automated pipeline validated install commands, protocol & client compatibility

Verified At2026-10-04
Install Snippets TestedCLI & JSON config syntax verified
Protocol Handshake ReadyComplies with JSON-RPC 2.0 specifications
Origin Registry ActiveSourced from official-mcp-registry
Verified ClientsClaude Code、Claude Desktop、Cursor 等
Security Tier: A+ 级 · 官方认证推荐 (A+)·Maintained by official/verified teams, audited for standard MCP protocol compliance.

Copy by platform

Choose your platform

  1. Open or create .cursor/mcp.json in your project root
  2. Click Copy config and paste; merge only this mcpServers entry if others exist
  3. Replace <placeholders> in env with real secrets (see Environment variables below)
  4. Save, then Cmd+Shift+P → Reload Window

Pre-fill Environment Variables (Optional)

Requiredsecret
Requiredsecret
Requiredsecret
Requiredsecret
Privacy Guarantee: Keys are replaced 100% locally in your browser memory and are NEVER uploaded or stored on any server.
Click to copy snippet
{
  "mcpServers": {
    "mcp-zap-server": {
      "command": "docker",
      "args": [
        "run",
        "-i",
        "--rm",
        "ghcr.io/dtkmn/mcp-zap-server:v0.14.0"
      ],
      "env": {
        "ZAP_API_KEY": "<ZAP_API_KEY>",
        "MCP_API_KEY": "<MCP_API_KEY>"
      }
    }
  }
}

Setup tutorial

  1. Open the MCP ZAP Server page and confirm this MCP Server (source: MCP Registry).
  2. Copy the Cursor, Claude Code, or VS Code snippet.
  3. Merge it into mcpServers and replace env placeholders with real secrets.
  4. Reload the window, then call the MCP tools from your agent chat.

Install commands

Install commands and setup steps are in the HTML so search engines and no-JS browsers can read them without running client JavaScript.

Claude Code (local)

  1. Install Claude Code CLI
  2. Copy the command below, replace <placeholders> with real env values, then run in terminal
  3. See Environment variables below if listed
claude mcp add mcp-zap-server --env ZAP_API_KEY=<ZAP_API_KEY> --env MCP_API_KEY=<MCP_API_KEY> -- docker run -i --rm ghcr.io/dtkmn/mcp-zap-server:v0.14.0

Cursor — .cursor/mcp.json (local)

  1. Open or create .cursor/mcp.json in your project root
  2. Click Copy config and paste; merge only this mcpServers entry if others exist
  3. Replace <placeholders> in env with real secrets (see Environment variables below)
  4. Save, then Cmd+Shift+P → Reload Window
{
  "mcpServers": {
    "mcp-zap-server": {
      "command": "docker",
      "args": [
        "run",
        "-i",
        "--rm",
        "ghcr.io/dtkmn/mcp-zap-server:v0.14.0"
      ],
      "env": {
        "ZAP_API_KEY": "<ZAP_API_KEY>",
        "MCP_API_KEY": "<MCP_API_KEY>"
      }
    }
  }
}

VS Code — .vscode/mcp.json (local)

  1. Install GitHub Copilot in VS Code with MCP support
  2. Open or create .vscode/mcp.json in your project root
  3. Click Copy config and paste; merge only this mcpServers entry if others exist
  4. Replace <placeholders> in env with real secrets
  5. Save and Developer: Reload Window
{
  "mcpServers": {
    "mcp-zap-server": {
      "command": "docker",
      "args": [
        "run",
        "-i",
        "--rm",
        "ghcr.io/dtkmn/mcp-zap-server:v0.14.0"
      ],
      "env": {
        "ZAP_API_KEY": "<ZAP_API_KEY>",
        "MCP_API_KEY": "<MCP_API_KEY>"
      }
    }
  }
}

Claude Desktop — claude_desktop_config.json (local)

  1. Open Claude Desktop claude_desktop_config.json (see remote guide for paths)
  2. Click Copy config and merge under mcpServers
  3. Replace <placeholders> in env with real secrets
  4. Fully quit and restart Claude Desktop
{
  "mcpServers": {
    "mcp-zap-server": {
      "command": "docker",
      "args": [
        "run",
        "-i",
        "--rm",
        "ghcr.io/dtkmn/mcp-zap-server:v0.14.0"
      ],
      "env": {
        "ZAP_API_KEY": "<ZAP_API_KEY>",
        "MCP_API_KEY": "<MCP_API_KEY>"
      }
    }
  }
}

Trae — .trae/mcp.json (local)

  1. Trae → Settings → MCP, or edit .trae/mcp.json / global mcp.json
  2. Click Copy config and merge mcpServers
  3. Replace <placeholders> in env with real secrets
  4. Save and reload Trae
{
  "mcpServers": {
    "mcp-zap-server": {
      "command": "docker",
      "args": [
        "run",
        "-i",
        "--rm",
        "ghcr.io/dtkmn/mcp-zap-server:v0.14.0"
      ],
      "env": {
        "ZAP_API_KEY": "<ZAP_API_KEY>",
        "MCP_API_KEY": "<MCP_API_KEY>"
      }
    }
  }
}

Cherry Studio — MCP settings (local)

  1. Cherry Studio → Settings → MCP Servers → Add (STDIO)
  2. Or import JSON: click Copy config and merge mcpServers
  3. Replace <placeholders> in env; ensure Node.js / uv (npx, uvx) are installed
  4. Enable the server and check tools load
{
  "mcpServers": {
    "mcp-zap-server": {
      "command": "docker",
      "args": [
        "run",
        "-i",
        "--rm",
        "ghcr.io/dtkmn/mcp-zap-server:v0.14.0"
      ],
      "env": {
        "ZAP_API_KEY": "<ZAP_API_KEY>",
        "MCP_API_KEY": "<MCP_API_KEY>"
      }
    }
  }
}

Tongyi Lingma — MCP config (local)

  1. Lingma Settings → MCP → + → STDIO or config file
  2. Click Copy config and merge mcpServers
  3. Replace <placeholders> in env; need Node.js 18+ (npx) or uv (uvx)
  4. Confirm connected before using tools in agent chat
{
  "mcpServers": {
    "mcp-zap-server": {
      "command": "docker",
      "args": [
        "run",
        "-i",
        "--rm",
        "ghcr.io/dtkmn/mcp-zap-server:v0.14.0"
      ],
      "env": {
        "ZAP_API_KEY": "<ZAP_API_KEY>",
        "MCP_API_KEY": "<MCP_API_KEY>"
      }
    }
  }
}

Windsurf — mcp_config.json (local)

  1. Edit ~/.codeium/windsurf/mcp_config.json
  2. Click Copy config and merge mcpServers (stdio same as Cursor)
  3. Replace <placeholders> in env, save, refresh Cascade
{
  "mcpServers": {
    "mcp-zap-server": {
      "command": "docker",
      "args": [
        "run",
        "-i",
        "--rm",
        "ghcr.io/dtkmn/mcp-zap-server:v0.14.0"
      ],
      "env": {
        "ZAP_API_KEY": "<ZAP_API_KEY>",
        "MCP_API_KEY": "<MCP_API_KEY>"
      }
    }
  }
}

Cline — MCP Servers (local)

  1. Cline panel → Settings → MCP Servers
  2. Click Copy config and merge
  3. Replace <placeholders> in env, then save
{
  "mcpServers": {
    "mcp-zap-server": {
      "command": "docker",
      "args": [
        "run",
        "-i",
        "--rm",
        "ghcr.io/dtkmn/mcp-zap-server:v0.14.0"
      ],
      "env": {
        "ZAP_API_KEY": "<ZAP_API_KEY>",
        "MCP_API_KEY": "<MCP_API_KEY>"
      }
    }
  }
}

WorkBuddy — .workbuddy/mcp.json (local)

  1. Edit ~/.workbuddy/mcp.json (user) or project .workbuddy/mcp.json
  2. Or Plugins → MCP Servers → Configure MCP and paste the JSON below
  3. Replace <placeholders> in env; on Windows prefer absolute paths for command/scripts
  4. Save, restart WorkBuddy, confirm connector status is green
{
  "mcpServers": {
    "mcp-zap-server": {
      "command": "docker",
      "args": [
        "run",
        "-i",
        "--rm",
        "ghcr.io/dtkmn/mcp-zap-server:v0.14.0"
      ],
      "env": {
        "ZAP_API_KEY": "<ZAP_API_KEY>",
        "MCP_API_KEY": "<MCP_API_KEY>"
      }
    }
  }
}

Troubleshooting & Common ErrorsFAQ

Common connection errors and verified fixes for MCP ZAP Server

Getting 'connection closed' or exit code 1 in Cursor / Claude Code for MCP ZAP Server?

Usually caused by missing runtime paths or IDE environment inheritance. Fix steps: 1. Verify Node.js 18+ (npx) or Python 3.10+ (uvx) is installed; 2. Run 'which npx' or 'which uvx' in terminal, and replace 'command' with absolute path; 3. Reload or restart the client window after modifying config.

Fix Snippet
# Check binary path in terminal:
which npx
node -v
Getting 'spawn npx ENOENT' or 'command not found'?

The editor background process does not inherit your full terminal PATH. Solution: Globally install the package, or set the absolute binary path (e.g. C:\Program Files\nodejs\npx.cmd on Windows, or /usr/local/bin/npx on macOS).

Missing required environment variable or authentication failure?

MCP ZAP Server requires environment variables (ZAP_API_KEY、MCP_API_KEY、ZAP_API_KEY、MCP_API_KEY). Ensure you have added valid keys under the 'env' object in your config file without trailing whitespace.

Fix Snippet
// .cursor/mcp.json 或 claude_desktop_config.json
{
  "env": {
    "ZAP_API_KEY": "your_actual_key_here"
  }
}

Tool Mock Playground

Sandbox

MCP ZAP Server Tool Interface Simulation · Preview tool schema & outputs without local runtime

Sandbox Ready
fn: mcp_zap_serverExecute the core tool interface of MCP ZAP Server
Request ArgumentsJSON Schema
{
  "target": "MCP ZAP Server",
  "action": "execute",
  "options": {
    "mode": "standard",
    "timeoutMs": 5000
  }
}
💡Parameters generated dynamically by Agent runtime
Agent Tool Output

Click 'Run Mock' above

to preview the raw response returned to the LLM

Env: AgentHub Virtual SandboxJSON-RPC 2.0

Decision Guide: Why & When to Use

Assess suitability before installing to save trial-and-error time

Best Suited For
  • PR review
  • Changelog generation
  • Cross-repo issue search
When NOT to Use
  • Replacing human security audit
  • Unauthorized repo access
Recommended Workflow Pairing:View Scenario →

MCP ZAP Server + Scenario Prompt → Complete Agent Automation

MCP hands-on: install to visible results

Follow the full lab (expected UI/output + contrast checks). After installing this item, verify with the tutorial prompts.

Open tutorial →

Related resources

Often paired with

Keep exploring AgentHub

Most people compare similar tools or check scenario guides before installing—start here.

Listing badge: put AgentHub on your site

Copy either snippet into your project homepage, docs, or GitHub README. The badge is a hotlinked SVG — nothing to host — and it links back to this page so visitors can find the install steps.

PreviewListed on AgentHub: MCP ZAP Server
HTML
<a href="https://myagenthub.cn/p/io.github.dtkmn/mcp-zap-server" title="Listed on AgentHub: MCP ZAP Server" target="_blank" rel="noopener">
  <img src="https://myagenthub.cn/badge/io.github.dtkmn/mcp-zap-server?lang=en" alt="Listed on AgentHub: MCP ZAP Server" height="20" style="border:0"/>
</a>
Markdown (GitHub README)
[![Listed on AgentHub: MCP ZAP Server](https://myagenthub.cn/badge/io.github.dtkmn/mcp-zap-server?lang=en)](https://myagenthub.cn/p/io.github.dtkmn/mcp-zap-server)

Badges are generated on the fly from /badge/<package-id>, so name and listing changes propagate automatically. Keep the link target unchanged — it is what counts as the referral.

Unified Manifest

{
  "id": "io.github.dtkmn/mcp-zap-server",
  "type": "mcp-server",
  "version": "0.14.0",
  "displayName": "MCP ZAP Server",
  "description": "Safe, self-hosted ZAP operator for guided AI security scans and reports.",
  "repository": {
    "url": "https://github.com/dtkmn/mcp-zap-server",
    "source": "github"
  },
  "homepage": "https://danieltse.org/mcp-zap-server/",
  "distribution": {
    "packages": [
      {
        "registryType": "oci",
        "identifier": "ghcr.io/dtkmn/mcp-zap-server:v0.14.0",
        "runtimeHint": "docker",
        "transport": "streamable-http",
        "environmentVariables": [
          {
            "name": "ZAP_API_URL",
            "description": "Hostname or URL of a separately running ZAP daemon reachable from this container."
          },
          {
            "name": "ZAP_API_PORT",
            "description": "ZAP API port."
          },
          {
            "name": "ZAP_API_KEY",
            "description": "API key configured on the ZAP daemon.",
            "isRequired": true,
            "isSecret": true
          },
          {
            "name": "MCP_API_KEY",
            "description": "API key clients must send as X-API-Key.",
            "isRequired": true,
            "isSecret": true
          },
          {
            "name": "MCP_SERVER_TOOLS_SURFACE",
            "description": "Tool surface to expose. Use guided for the safer default workflow, including report readback. Use expert only when clients need raw ZAP tools outside the guided surface."
          },
          {
            "name": "MCP_SECURITY_MODE"
          },
          {
            "name": "MCP_SECURITY_ENABLED"
          },
          {
            "name": "MCP_SECURITY_ALLOW_PLACEHOLDER_API_KEY"
          }
        ]
      },
      {
        "registryType": "oci",
        "identifier": "docker.io/dtkmn/mcp-zap-server:v0.14.0",
        "runtimeHint": "docker",
        "transport": "streamable-http",
        "environmentVariables": [
          {
            "name": "ZAP_API_URL",
            "description": "Hostname or URL of a separately running ZAP daemon reachable from this container."
          },
          {
            "name": "ZAP_API_PORT",
            "description": "ZAP API port."
          },
          {
            "name": "ZAP_API_KEY",
            "description": "API key configured on the ZAP daemon.",
            "isRequired": true,
            "isSecret": true
          },
          {
            "name": "MCP_API_KEY",
            "description": "API key clients must send as X-API-Key.",
            "isRequired": true,
            "isSecret": true
          },
          {
            "name": "MCP_SERVER_TOOLS_SURFACE",
            "description": "Tool surface to expose. Use guided for the safer default workflow, including report readback. Use expert only when clients need raw ZAP tools outside the guided surface."
          },
          {
            "name": "MCP_SECURITY_MODE"
          },
          {
            "name": "MCP_SECURITY_ENABLED"
          },
          {
            "name": "MCP_SECURITY_ALLOW_PLACEHOLDER_API_KEY"
          }
        ]
      }
    ],
    "remotes": []
  },
  "dependencies": [],
  "installTargets": [
    "claude-code",
    "claude-desktop",
    "cursor",
    "vscode",
    "trae",
    "cherry-studio",
    "lingma",
    "windsurf",
    "cline",
    "workbuddy"
  ],
  "keywords": [],
  "provenance": {
    "origin": "official-mcp-registry",
    "originalId": "io.github.dtkmn/mcp-zap-server",
    "originalUrl": "https://registry.modelcontextprotocol.io/v0.1/servers/io.github.dtkmn%2Fmcp-zap-server/versions/latest",
    "isOfficial": true,
    "status": "active"
  }
}