# OWASP ZAP API Fuzzer

> Automates REST API security testing using the OWASP ZAP Python SDK, running active scans, SQL injection probes, and XSS tests against OpenAPI specs with structured vulnerability reports.

- Skill: `agentskillexchange/owasp-zap-api-fuzzer` (Agent Skill)
- Install (CLI): `npx skillmds add agentskillexchange/owasp-zap-api-fuzzer`
- Raw SKILL.md: https://api.skillmd.com/api/skills/agentskillexchange/owasp-zap-api-fuzzer/raw
- Safety review: CAUTION (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Security, Penetration Testing, Vulnerability Scanning
- Tags: Active Scan, Api Security, Openapi, Owasp Zap, Python Sdk, Rest Api, Sql Injection, Xss
- Author: agentskillexchange (https://skillmd.com/u/agentskillexchange)
- Updated: 2026-08-22
- Page: https://skillmd.com/skills/agentskillexchange/owasp-zap-api-fuzzer

---


# OWASP ZAP API Fuzzer

Automates REST API security testing using the OWASP ZAP Python SDK. Runs active scans, SQL injection probes, and XSS tests against OpenAPI specs with structured vulnerability reports.

## Installation

Requirements and caveats from upstream:
- ![Docker Live Release](https://github.com/zaproxy/zaproxy/actions/workflows/release-live-docker.yml/badge.svg)

Basic usage or getting-started notes:
- ![Integration Tests](https://github.com/zaproxy/zaproxy/actions/workflows/run-integration-tests.yml/badge.svg)

- Source: https://github.com/zaproxy/zaproxy
- Extracted from upstream docs: https://raw.githubusercontent.com/zaproxy/zaproxy/HEAD/README.md

## Source

- [Agent Skill Exchange](https://agentskillexchange.com/skills/owasp-zap-api-fuzzer/)

