Claude security directory
Zscaler MCP Server
High risk
Zscaler MCP Server is a Model Context Protocol (MCP) server for managing Zscaler products with LLMs (Claude, ChatGPT, Gemini, etc.). It exposes hundreds of tools across nine Zscaler services. Read-only operations are available by default; create / update / delete tools require explicit allowlisting via the 'Enable Write Tools' and 'Write Tools Allowlist' settings below, and destructive operations additionally require an in-session HMAC confirmation token.
Security assessment
Plutonium assessed this web connector for permissions, capabilities, and security-relevant behavior.
- Reads your private information: The connector can retrieve sensitive security configuration and organizational data (e.g., users, groups, departments, locations, DLP dictionaries/engines), which could expose internal structure and policy details.
- Can change or update your information: Multiple tools can create or activate ZIA configuration and policies (e.g., firewall/SSL inspection/DLP rules, URL categories), which could alter enforcement and impact user traffic and security posture.
- Can permanently delete data: Numerous delete tools can remove security policies, objects, and credentials (e.g., rules, tunnels, categories, VPN credentials), potentially causing outages or weakening defenses; destructive actions are highest impact even with confirmations.
- Stores long-lived access tokens: To manage Zscaler services, the MCP server typically needs stored API credentials/tokens, increasing risk if the connector host or configuration is compromised.
Available capabilities
This add-on exposes 80 tools or capabilities.
- zscaler_check_connectivity
- zscaler_enable_toolset
- zscaler_get_available_services
- zscaler_get_toolset_tools
- zscaler_list_toolsets
- get_zia_dlp_dictionaries
- get_zia_dlp_engines
- get_zia_user_departments
- get_zia_user_groups
- get_zia_users
- zia_activate_configuration
- zia_add_atp_malicious_urls
- zia_add_auth_exempt_urls
- zia_add_urls_to_category
- zia_bulk_update_shadow_it_apps
- zia_create_cloud_app_control_rule
- zia_create_cloud_firewall_dns_rule
- zia_create_cloud_firewall_ips_rule
- zia_create_cloud_firewall_rule
- zia_create_file_type_control_rule
- zia_create_gre_tunnel
- zia_create_ip_destination_group
- zia_create_ip_source_group
- zia_create_ips_signature_rule
The interactive security report will load automatically.