Automates OWASP ZAP active and passive scanning against web applications, parsing alerts into structured vulnerability reports. Integrates with the ZAP API daemon to manage contexts, spider targets, and export SARIF-formatted findings.
Scanned 6/8/2026
Install via CLI
openskills install agentskillexchange/skills---
name: "OWASP ZAP Security Scanner Agent"
slug: "owasp-zap-security-scanner-agent"
description: "Automates OWASP ZAP active and passive scanning against web applications, parsing alerts into structured vulnerability reports. Integrates with the ZAP API daemon to manage contexts, spider targets, and export SARIF-formatted findings."
github_stars: 14991
verification: "security_reviewed"
source: "https://github.com/zaproxy/zaproxy"
category: "Security & Verification"
framework: "OpenClaw"
tool_ecosystem:
github_repo: "zaproxy/zaproxy"
github_stars: 14991
---
# OWASP ZAP Security Scanner Agent
Automates OWASP ZAP active and passive scanning against web applications, parsing alerts into structured vulnerability reports. Integrates with the ZAP API daemon to manage contexts, spider targets, and export SARIF-formatted findings.
## Installation
Requirements and caveats from upstream:
- 
Basic usage or getting-started notes:
- 
- Source: https://github.com/zaproxy/zaproxy
- Extracted from upstream docs: https://raw.githubusercontent.com/zaproxy/zaproxy/HEAD/README.md
## Source
- [Agent Skill Exchange](https://agentskillexchange.com/skills/owasp-zap-security-scanner-agent/)
No comments yet. Be the first to comment!