zscaler-mcp-server
Manage and audit Zscaler Zero Trust security policies
All Skills in This Repository (25)
Pure Emerald Level Indicatorszia-check-user-url-access
Evaluate ZIA policies in priority order to determine user or group URL access.
zia-onboard-location
Coordinate static IP, VPN credentials, and location records to onboard a ZIA location.
zia-audit-ssl-inspection-bypass
Audit ZIA SSL inspection rules to identify decryption and bypass risks.
zia-investigate-sandbox
Diagnose ZIA Sandbox file analyses and policy enforcement events via API endpoints.
zia-investigate-url-category
Identify URL category references across ZIA filtering, SSL, DLP, and firewall rules.
easm-review-attack-surface
Query EASM findings and lookalike domains to generate prioritized risk reports.
zins-audit-shadow-it
Identify and quantify shadow IT and unsanctioned SaaS usage via Zscaler Analytics.
zins-investigate-security-incident
Correlate Zscaler Z-Insights security data sources into a structured incident timeline.
zins-analyze-web-traffic
Query Zscaler Analytics to summarize web traffic by location, protocol, and threats.
zins-assess-network-security
Analyze Zscaler Analytics firewall data to assess policy effectiveness and detect blocking gaps.
zms-troubleshoot-agent-deployment
Troubleshoot ZMS agent deployment and connectivity issues via MCP GraphQL operations.
zms-audit-microsegmentation-posture
Audit ZMS deployment posture across agent health, coverage, groups, policies, app zones, and tags.
Frequently Asked Questions
FAQPage SchemaHow to install zscaler-mcp-server?βΌ
Run `npx skills add zscaler/zscaler-mcp-server --all -g -y` in your terminal to install all skills globally. You will also need Zscaler OneAPI credentials set as environment variables.
What can I do with the Zscaler MCP server?βΌ
You can create security policy rules, onboard applications and locations, audit SSL inspection and microsegmentation posture, troubleshoot user connectivity, and analyze web traffic across ZPA, ZIA, ZDX, and other Zscaler services.
Is the Zscaler MCP server read-only?βΌ
Yes, by default only list and get operations are available. Write operations that create, update, or delete resources require explicit opt-in with an allowlist flag.
Does it work with Claude Desktop and Cursor?βΌ
Yes. It follows the MCP standard and works with Claude Desktop, Cursor, VS Code, Gemini CLI, and other MCP-compatible clients.
Can I troubleshoot why a user cannot access an application?βΌ
Yes. The cross-product troubleshooting skill correlates ZCC client status, ZDX experience metrics, ZPA access policies, and ZIA filtering rules to pinpoint the root cause.
Related Repositories in Software Engineering
View All in Software Engineeringβopenclaw
Run a personal AI assistant across your devices and chat apps
superpowers
Gives coding agents a disciplined workflow from idea to merged code
react
AI agent skills for building, testing, and porting React core