{"generated_at":"2026-08-13T12:51:35+00:00","item":{"added_at":"2026-07-05","analysis_method":"capability_triage","category":"Web Connector","description":"Zscaler MCP Server is a Model Context Protocol (MCP) server for managing Zscaler products with LLMs (Claude, ChatGPT, Gemini, etc.). It exposes hundreds of tools across nine Zscaler services. Read-onl","did":"ant-dir-zscaler-mcp-server","homepage_url":"","icon":"https://claude.ai/api/dxt/extensions/ant.dir.gh.zscaler.zscaler-mcp-server/versions/0.12.7/icon.png","id":"ant.dir.zscaler.mcp.server","installs":7147,"last_scanned":"2026-07-05","license":"","long_description":"Zscaler MCP Server is a Model Context Protocol (MCP) server for managing Zscaler products with LLMs (Claude, ChatGPT, Gemini, etc.). It exposes hundreds of tools across nine Zscaler services. Read-only operations are available by default; create / update / delete tools require explicit allowlisting via the 'Enable Write Tools' and 'Write Tools Allowlist' settings below, and destructive operations additionally require an in-session HMAC confirmation token.","name":"Zscaler MCP Server","plutonium_url":"https://plutonium.pluto.security/detail.html?planet=claudesec&did=ant-dir-zscaler-mcp-server&utm_source=plutonium_analysis_skill&utm_medium=claude_skill&utm_campaign=connector_risk_assessment","publisher":"","publisher_url":"","repository_url":"","risk":"high","risk_severity":"high","security_risks":[{"description":"The connector can retrieve sensitive security configuration and organizational data (e.g., users, groups, departments, locations, DLP dictionaries/engines), which could expose internal structure and policy details.","risk_type":"reads_private_data","severity":"medium","title":"Reads your private information"},{"description":"Multiple tools can create or activate ZIA configuration and policies (e.g., firewall/SSL inspection/DLP rules, URL categories), which could alter enforcement and impact user traffic and security posture.","risk_type":"modifies_data","severity":"medium","title":"Can change or update your information"},{"description":"Numerous delete tools can remove security policies, objects, and credentials (e.g., rules, tunnels, categories, VPN credentials), potentially causing outages or weakening defenses; destructive actions are highest impact even with confirmations.","risk_type":"deletes_data","severity":"high","title":"Can permanently delete data"},{"description":"To manage Zscaler services, the MCP server typically needs stored API credentials/tokens, increasing risk if the connector host or configuration is compromised.","risk_type":"requires_persistent_credentials","severity":"medium","title":"Stores long-lived access tokens"}],"signature_status":"unknown","source_code_reviewed":false,"tags":["deletes_data","modifies_data","reads_private_data","requires_persistent_credentials"],"tools":[{"description":"Checks whether the MCP server can connect to the Zscaler APIs/services.","name":"zscaler_check_connectivity"},{"description":"Enables a specific toolset/service within the Zscaler MCP server for use.","name":"zscaler_enable_toolset","risk":{"category":"privilege","level":"medium","why":"Enabling additional toolsets expands accessible capabilities and may increase exposure to sensitive or state-changing operations."}},{"description":"Lists which Zscaler services are available through this MCP server.","name":"zscaler_get_available_services"},{"description":"Returns the tools available within a given toolset.","name":"zscaler_get_toolset_tools"},{"description":"Lists configured toolsets/services exposed by the MCP server.","name":"zscaler_list_toolsets"},{"description":"Retrieves ZIA DLP dictionaries configured in the tenant.","name":"get_zia_dlp_dictionaries"},{"description":"Retrieves ZIA DLP engines configured in the tenant.","name":"get_zia_dlp_engines"},{"description":"Lists user departments from ZIA.","name":"get_zia_user_departments"},{"description":"Lists user groups from ZIA.","name":"get_zia_user_groups"},{"description":"Lists users known to ZIA.","name":"get_zia_users"},{"description":"Activates/publishes pending ZIA configuration changes so they take effect.","name":"zia_activate_configuration","risk":{"category":"state_change","level":"medium","why":"Activation pushes policy changes live, which can immediately affect traffic handling and security controls."}},{"description":"Adds URLs to the ZIA ATP malicious URL list.","name":"zia_add_atp_malicious_urls","risk":{"category":"state_change","level":"medium","why":"Modifies threat/policy lists, potentially impacting blocking behavior and user access."}},{"description":"Adds URLs to an authentication-exempt list in ZIA.","name":"zia_add_auth_exempt_urls","risk":{"category":"state_change","level":"medium","why":"Creating auth exemptions can weaken access controls and allow bypass of authentication requirements."}},{"description":"Adds URLs to a specified URL category in ZIA.","name":"zia_add_urls_to_category","risk":{"category":"state_change","level":"medium","why":"Changes URL categorization used by filtering policies, which can alter allowed/blocked access."}},{"description":"Performs bulk updates to Shadow IT application settings in ZIA.","name":"zia_bulk_update_shadow_it_apps","risk":{"category":"state_change","level":"medium","why":"Bulk changes can affect many app controls at once, increasing the blast radius of misconfiguration."}},{"description":"Creates a new Cloud App Control rule in ZIA.","name":"zia_create_cloud_app_control_rule","risk":{"category":"state_change","level":"medium","why":"Creating control rules changes enforcement over SaaS/app usage and can block or permit data flows."}},{"description":"Creates a new Cloud Firewall DNS rule in ZIA.","name":"zia_create_cloud_firewall_dns_rule","risk":{"category":"state_change","level":"medium","why":"Firewall DNS rules can block/allow resolution and affect connectivity and security controls."}},{"description":"Creates a new Cloud Firewall IPS rule in ZIA.","name":"zia_create_cloud_firewall_ips_rule","risk":{"category":"state_change","level":"medium","why":"IPS rules impact intrusion prevention behavior and may block legitimate traffic or reduce protections if misconfigured."}},{"description":"Creates a new Cloud Firewall rule in ZIA.","name":"zia_create_cloud_firewall_rule","risk":{"category":"state_change","level":"medium","why":"Firewall rules directly affect network access control and could open or block critical communications."}},{"description":"Creates a file type control rule in ZIA.","name":"zia_create_file_type_control_rule","risk":{"category":"state_change","level":"medium","why":"File type controls affect upload/download restrictions and can alter data loss and productivity outcomes."}},{"description":"Creates a GRE tunnel configuration in ZIA.","name":"zia_create_gre_tunnel","risk":{"category":"state_change","level":"medium","why":"Tunnel configuration changes can reroute traffic and cause outages or security gaps if incorrect."}},{"description":"Creates an IP destination group object in ZIA.","name":"zia_create_ip_destination_group","risk":{"category":"state_change","level":"medium","why":"New destination groups can be referenced by policies, changing the scope of enforcement."}},{"description":"Creates an IP source group object in ZIA.","name":"zia_create_ip_source_group","risk":{"category":"state_change","level":"medium","why":"New source groups can change which users/networks policies apply to, affecting enforcement boundaries."}},{"description":"Creates an IPS signature rule in ZIA.","name":"zia_create_ips_signature_rule","risk":{"category":"state_change","level":"medium","why":"Signature rule changes can increase false positives or reduce detection if misapplied."}},{"description":"Creates a new location in ZIA.","name":"zia_create_location","risk":{"category":"state_change","level":"medium","why":"Locations are used for policy scoping and traffic forwarding; incorrect creation can impact routing and enforcement."}},{"description":"Creates a network application group in ZIA.","name":"zia_create_network_app_group","risk":{"category":"state_change","level":"medium","why":"Application grouping affects firewall/app policies and could unintentionally broaden access."}},{"description":"Creates a network service object in ZIA.","name":"zia_create_network_service","risk":{"category":"state_change","level":"medium","why":"Network services define ports/protocols used by policies; misconfiguration can open unwanted traffic."}},{"description":"Creates a network service group in ZIA.","name":"zia_create_network_svc_group","risk":{"category":"state_change","level":"medium","why":"Service groups can be widely referenced, so changes can have broad policy impact."}},{"description":"Creates a rule label/tag used to organize policies in ZIA.","name":"zia_create_rule_label","risk":{"category":"state_change","level":"medium","why":"Labeling can affect policy management workflows and automated processes that rely on tags."}},{"description":"Creates a sandboxing rule in ZIA.","name":"zia_create_sandbox_rule","risk":{"category":"state_change","level":"medium","why":"Sandboxing rules change malware analysis behavior and can affect security and latency."}},{"description":"Creates an SSL inspection rule in ZIA.","name":"zia_create_ssl_inspection_rule","risk":{"category":"state_change","level":"medium","why":"SSL inspection changes can impact privacy, compliance, and connectivity due to certificate/inspection behavior."}},{"description":"Creates a static IP object/configuration in ZIA.","name":"zia_create_static_ip","risk":{"category":"state_change","level":"medium","why":"Static IP settings can affect traffic identification and policy application for locations."}},{"description":"Creates a time interval object used for scheduling ZIA policies.","name":"zia_create_time_interval","risk":{"category":"state_change","level":"medium","why":"Time schedules can change when policies apply, potentially creating unintended enforcement windows."}},{"description":"Creates a custom URL category in ZIA.","name":"zia_create_url_category","risk":{"category":"state_change","level":"medium","why":"Custom categories influence URL filtering and can enable/disable access based on categorization."}},{"description":"Creates a URL filtering rule in ZIA.","name":"zia_create_url_filtering_rule","risk":{"category":"state_change","level":"medium","why":"URL filtering rules directly change what web content is allowed or blocked."}},{"description":"Creates VPN credentials used for ZIA integrations/tunnels.","name":"zia_create_vpn_credential","risk":{"category":"privilege","level":"medium","why":"Creating credentials introduces new authentication material that could be abused if exposed or mis-scoped."}},{"description":"Creates a web DLP rule in ZIA.","name":"zia_create_web_dlp_rule","risk":{"category":"state_change","level":"medium","why":"DLP rules affect inspection/blocking of sensitive data and can cause data exposure or business disruption if misconfigured."}},{"description":"Removes URLs from the ZIA ATP malicious URL list.","name":"zia_delete_atp_malicious_urls","risk":{"category":"destructive","level":"high","why":"Deleting malicious URL entries can reduce protections and is difficult to audit/undo if done incorrectly."}},{"description":"Removes URLs from the authentication-exempt list in ZIA.","name":"zia_delete_auth_exempt_urls","risk":{"category":"destructive","level":"high","why":"Deleting exemptions changes access behavior and could break intended workflows or access paths."}},{"description":"Deletes a Cloud App Control rule in ZIA.","name":"zia_delete_cloud_app_control_rule","risk":{"category":"destructive","level":"high","why":"Removing a control rule can immediately change SaaS enforcement and create data exposure or compliance gaps."}},{"description":"Deletes a Cloud Firewall DNS rule in ZIA.","name":"zia_delete_cloud_firewall_dns_rule","risk":{"category":"destructive","level":"high","why":"Removing DNS firewall rules can reopen blocked domains or disrupt intended protections."}},{"description":"Deletes a Cloud Firewall IPS rule in ZIA.","name":"zia_delete_cloud_firewall_ips_rule","risk":{"category":"destructive","level":"high","why":"Deleting IPS rules can reduce intrusion prevention coverage and weaken defenses."}},{"description":"Deletes a Cloud Firewall rule in ZIA.","name":"zia_delete_cloud_firewall_rule","risk":{"category":"destructive","level":"high","why":"Removing firewall rules can unexpectedly open network access or break connectivity controls."}},{"description":"Deletes a file type control rule in ZIA.","name":"zia_delete_file_type_control_rule","risk":{"category":"destructive","level":"high","why":"Deleting file type controls can remove restrictions that prevent risky file transfers."}},{"description":"Deletes a GRE tunnel configuration in ZIA.","name":"zia_delete_gre_tunnel","risk":{"category":"destructive","level":"high","why":"Deleting a tunnel can break traffic forwarding and cause outages for routed locations."}},{"description":"Deletes an IP destination group in ZIA.","name":"zia_delete_ip_destination_group","risk":{"category":"destructive","level":"high","why":"Deleting shared objects can break multiple dependent policies and change enforcement scope."}},{"description":"Deletes an IP source group in ZIA.","name":"zia_delete_ip_source_group","risk":{"category":"destructive","level":"high","why":"Removing source groups can invalidate policies and disrupt segmentation or enforcement."}},{"description":"Deletes an IPS signature rule in ZIA.","name":"zia_delete_ips_signature_rule","risk":{"category":"destructive","level":"high","why":"Deleting signature rules can reduce detection/prevention coverage against threats."}},{"description":"Deletes a location in ZIA.","name":"zia_delete_location","risk":{"category":"destructive","level":"high","why":"Deleting a location can disrupt policy assignments and traffic forwarding for that site."}},{"description":"Deletes a network application group in ZIA.","name":"zia_delete_network_app_group","risk":{"category":"destructive","level":"high","why":"Deleting app groups can break policies that reference them and alter access control."}},{"description":"Deletes a network service object in ZIA.","name":"zia_delete_network_service","risk":{"category":"destructive","level":"high","why":"Deleting service definitions can break firewall rules and unintentionally change allowed traffic."}},{"description":"Deletes a network service group in ZIA.","name":"zia_delete_network_svc_group","risk":{"category":"destructive","level":"high","why":"Removing a shared service group can have broad downstream impact across multiple policies."}},{"description":"Deletes a rule label/tag in ZIA.","name":"zia_delete_rule_label","risk":{"category":"destructive","level":"high","why":"Deleting labels can disrupt governance/automation and policy organization relying on those tags."}},{"description":"Deletes a sandboxing rule in ZIA.","name":"zia_delete_sandbox_rule","risk":{"category":"destructive","level":"high","why":"Removing sandbox rules can reduce malware analysis coverage and change security posture."}},{"description":"Deletes an SSL inspection rule in ZIA.","name":"zia_delete_ssl_inspection_rule","risk":{"category":"destructive","level":"high","why":"Deleting SSL inspection rules can remove visibility/control over encrypted traffic or break intended inspection."}},{"description":"Deletes a static IP configuration/object in ZIA.","name":"zia_delete_static_ip","risk":{"category":"destructive","level":"high","why":"Removing static IP mappings can break location identification and policy application."}},{"description":"Deletes a time interval scheduling object in ZIA.","name":"zia_delete_time_interval","risk":{"category":"destructive","level":"high","why":"Deleting schedule objects can change when policies apply and break dependent rules."}},{"description":"Deletes a custom URL category in ZIA.","name":"zia_delete_url_category","risk":{"category":"destructive","level":"high","why":"Deleting categories can break URL filtering rules and change access control behavior."}},{"description":"Deletes a URL filtering rule in ZIA.","name":"zia_delete_url_filtering_rule","risk":{"category":"destructive","level":"high","why":"Removing a filtering rule can immediately allow previously blocked content or disrupt intended access."}},{"description":"Deletes a VPN credential in ZIA.","name":"zia_delete_vpn_credential","risk":{"category":"destructive","level":"high","why":"Deleting credentials can break integrations/tunnels and force reconfiguration while potentially impacting connectivity."}},{"description":"Deletes a web DLP rule in ZIA.","name":"zia_delete_web_dlp_rule","risk":{"category":"destructive","level":"high","why":"Deleting DLP rules can remove protections against sensitive data exfiltration."}},{"description":"Searches for geographic/location-related information in ZIA (e.g., geo metadata).","name":"zia_geo_search"},{"description":"Retrieves the current activation/publish status of ZIA configuration changes.","name":"zia_get_activation_status"},{"description":"Retrieves advanced ZIA configuration settings.","name":"zia_get_advanced_settings"},{"description":"Retrieves ZIA ATP malware inspection settings.","name":"zia_get_atp_malware_inspection"},{"description":"Retrieves ZIA ATP malware policy configuration.","name":"zia_get_atp_malware_policy"},{"description":"Retrieves protocol settings related to ZIA ATP malware protections.","name":"zia_get_atp_malware_protocols"},{"description":"Retrieves ZIA ATP security exception configurations.","name":"zia_get_atp_security_exceptions"},{"description":"Retrieves general ZIA ATP settings.","name":"zia_get_atp_settings"},{"description":"Retrieves a specific Cloud App Control rule from ZIA.","name":"zia_get_cloud_app_control_rule"},{"description":"Retrieves a specific Cloud Firewall DNS rule from ZIA.","name":"zia_get_cloud_firewall_dns_rule"},{"description":"Retrieves a specific Cloud Firewall IPS rule from ZIA.","name":"zia_get_cloud_firewall_ips_rule"},{"description":"Retrieves a specific Cloud Firewall rule from ZIA.","name":"zia_get_cloud_firewall_rule"},{"description":"Retrieves a specific file type control rule from ZIA.","name":"zia_get_file_type_control_rule"},{"description":"Retrieves a specific GRE tunnel configuration from ZIA.","name":"zia_get_gre_tunnel"},{"description":"Retrieves a specific IP destination group from ZIA.","name":"zia_get_ip_destination_group"},{"description":"Retrieves a specific IP source group from ZIA.","name":"zia_get_ip_source_group"},{"description":"Retrieves a specific IPS signature rule from ZIA.","name":"zia_get_ips_signature_rule"},{"description":"Retrieves details of a specific ZIA location.","name":"zia_get_location"},{"description":"Retrieves details of a specific ZIA location group.","name":"zia_get_location_group"}],"tools_count":80,"type":"web_connector","url":"","uuid":"ant.dir.gh.zscaler.zscaler-mcp-server","version":""},"query_key":"zscaler mcp server","schema_version":1,"status":"match"}
