# OWASP ZAP Automated Scan Orchestrator

> Runs OWASP ZAP active and passive scans against target URLs using the ZAP Docker API. Parses JSON reports to flag XSS, SQLi, and CSRF vulnerabilities with severity scoring.

- Skill: `agentskillexchange/owasp-zap-automated-scan-orchestrator` (Agent Skill)
- Install (CLI): `npx skillmds@latest add agentskillexchange/owasp-zap-automated-scan-orchestrator`
- Raw SKILL.md: https://api.skillmd.com/api/skills/agentskillexchange/owasp-zap-automated-scan-orchestrator/raw
- Safety review: pending (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: DevOps & Infra
- Author: agentskillexchange (https://skillmd.com/u/agentskillexchange)
- Updated: 2026-09-08
- Page: https://skillmd.com/skills/agentskillexchange/owasp-zap-automated-scan-orchestrator

---


# OWASP ZAP Automated Scan Orchestrator

Runs OWASP ZAP active and passive scans against target URLs using the ZAP Docker API. Parses JSON reports to flag XSS, SQLi, and CSRF vulnerabilities with severity scoring.

## Installation

Requirements and caveats from upstream:
- ![Docker Live Release](https://github.com/zaproxy/zaproxy/actions/workflows/release-live-docker.yml/badge.svg)

Basic usage or getting-started notes:
- ![Integration Tests](https://github.com/zaproxy/zaproxy/actions/workflows/run-integration-tests.yml/badge.svg)

- Source: https://github.com/zaproxy/zaproxy
- Extracted from upstream docs: https://raw.githubusercontent.com/zaproxy/zaproxy/HEAD/README.md

## Source

- [Agent Skill Exchange](https://agentskillexchange.com/skills/owasp-zap-automated-scan-orchestrator/)

