# OWASP ZAP API Security Scanner

> Automates OWASP ZAP scans against REST APIs using the ZAP Python API client. Imports OpenAPI/Swagger specs for targeted scanning and generates SARIF-format reports for GitHub Security tab integration.

- Skill: `agentskillexchange/owasp-zap-api-security-scanner` (Agent Skill)
- Install (CLI): `npx skillmds@latest add agentskillexchange/owasp-zap-api-security-scanner`
- Raw SKILL.md: https://api.skillmd.com/api/skills/agentskillexchange/owasp-zap-api-security-scanner/raw
- Safety review: pending (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Security
- Author: agentskillexchange (https://skillmd.com/u/agentskillexchange)
- Updated: 2026-09-08
- Page: https://skillmd.com/skills/agentskillexchange/owasp-zap-api-security-scanner

---


# OWASP ZAP API Security Scanner

Automates OWASP ZAP scans against REST APIs using the ZAP Python API client. Imports OpenAPI/Swagger specs for targeted scanning and generates SARIF-format reports for GitHub Security tab integration.

## Installation

Requirements and caveats from upstream:
- ![Docker Live Release](https://github.com/zaproxy/zaproxy/actions/workflows/release-live-docker.yml/badge.svg)

Basic usage or getting-started notes:
- ![Integration Tests](https://github.com/zaproxy/zaproxy/actions/workflows/run-integration-tests.yml/badge.svg)

- Source: https://github.com/zaproxy/zaproxy
- Extracted from upstream docs: https://raw.githubusercontent.com/zaproxy/zaproxy/HEAD/README.md

## Source

- [Agent Skill Exchange](https://agentskillexchange.com/skills/owasp-zap-api-security-scanner/)

