Orchestrates OWASP ZAP active and passive scans against REST and GraphQL endpoints using ZAP's Python API client. Generates DAST reports with CWE mappings and suggests WAF rule configurations.
Scanned 6/8/2026
Install via CLI
openskills install agentskillexchange/skills---
name: "OWASP ZAP API Security Auditor"
slug: "owasp-zap-api-security-auditor"
description: "Orchestrates OWASP ZAP active and passive scans against REST and GraphQL endpoints using ZAP's Python API client. Generates DAST reports with CWE mappings and suggests WAF rule configurations."
github_stars: 14991
verification: "security_reviewed"
source: "https://github.com/zaproxy/zaproxy"
category: "Security & Verification"
framework: "OpenClaw"
tool_ecosystem:
github_repo: "zaproxy/zaproxy"
github_stars: 14991
---
# OWASP ZAP API Security Auditor
Orchestrates OWASP ZAP active and passive scans against REST and GraphQL endpoints using ZAP's Python API client. Generates DAST reports with CWE mappings and suggests WAF rule configurations.
## Installation
Requirements and caveats from upstream:
- 
Basic usage or getting-started notes:
- 
- Source: https://github.com/zaproxy/zaproxy
- Extracted from upstream docs: https://raw.githubusercontent.com/zaproxy/zaproxy/HEAD/README.md
## Source
- [Agent Skill Exchange](https://agentskillexchange.com/skills/owasp-zap-api-security-auditor/)
No comments yet. Be the first to comment!