# OWASP ZAP API Security Auditor

> Orchestrates OWASP ZAP active and passive scans against REST and GraphQL endpoints using ZAP's Python API client. Generates DAST reports with CWE mappings and suggests WAF rule configurations.

- Skill: `agentskillexchange/owasp-zap-api-security-auditor` (Agent Skill)
- Install (CLI): `npx skillmds@latest add agentskillexchange/owasp-zap-api-security-auditor`
- Raw SKILL.md: https://api.skillmd.com/api/skills/agentskillexchange/owasp-zap-api-security-auditor/raw
- Safety review: pending (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Security
- Author: agentskillexchange (https://skillmd.com/u/agentskillexchange)
- Updated: 2026-09-08
- Page: https://skillmd.com/skills/agentskillexchange/owasp-zap-api-security-auditor

---


# OWASP ZAP API Security Auditor

Orchestrates OWASP ZAP active and passive scans against REST and GraphQL endpoints using ZAP's Python API client. Generates DAST reports with CWE mappings and suggests WAF rule configurations.

## Installation

Requirements and caveats from upstream:
- ![Docker Live Release](https://github.com/zaproxy/zaproxy/actions/workflows/release-live-docker.yml/badge.svg)

Basic usage or getting-started notes:
- ![Integration Tests](https://github.com/zaproxy/zaproxy/actions/workflows/run-integration-tests.yml/badge.svg)

- Source: https://github.com/zaproxy/zaproxy
- Extracted from upstream docs: https://raw.githubusercontent.com/zaproxy/zaproxy/HEAD/README.md

## Source

- [Agent Skill Exchange](https://agentskillexchange.com/skills/owasp-zap-api-security-auditor/)

