Claude security directory

Zscaler MCP Server

High risk

Zscaler MCP Server is a Model Context Protocol (MCP) server for managing Zscaler products with LLMs (Claude, ChatGPT, Gemini, etc.). It exposes hundreds of tools across nine Zscaler services. Read-only operations are available by default; create / update / delete tools require explicit allowlisting via the 'Enable Write Tools' and 'Write Tools Allowlist' settings below, and destructive operations additionally require an in-session HMAC confirmation token.

Security assessment

Plutonium assessed this web connector for permissions, capabilities, and security-relevant behavior.

  • Reads your private information: The connector can retrieve sensitive security configuration and organizational data (e.g., users, groups, departments, locations, DLP dictionaries/engines), which could expose internal structure and policy details.
  • Can change or update your information: Multiple tools can create or activate ZIA configuration and policies (e.g., firewall/SSL inspection/DLP rules, URL categories), which could alter enforcement and impact user traffic and security posture.
  • Can permanently delete data: Numerous delete tools can remove security policies, objects, and credentials (e.g., rules, tunnels, categories, VPN credentials), potentially causing outages or weakening defenses; destructive actions are highest impact even with confirmations.
  • Stores long-lived access tokens: To manage Zscaler services, the MCP server typically needs stored API credentials/tokens, increasing risk if the connector host or configuration is compromised.

Available capabilities

This add-on exposes 80 tools or capabilities.

  • zscaler_check_connectivity
  • zscaler_enable_toolset
  • zscaler_get_available_services
  • zscaler_get_toolset_tools
  • zscaler_list_toolsets
  • get_zia_dlp_dictionaries
  • get_zia_dlp_engines
  • get_zia_user_departments
  • get_zia_user_groups
  • get_zia_users
  • zia_activate_configuration
  • zia_add_atp_malicious_urls
  • zia_add_auth_exempt_urls
  • zia_add_urls_to_category
  • zia_bulk_update_shadow_it_apps
  • zia_create_cloud_app_control_rule
  • zia_create_cloud_firewall_dns_rule
  • zia_create_cloud_firewall_ips_rule
  • zia_create_cloud_firewall_rule
  • zia_create_file_type_control_rule
  • zia_create_gre_tunnel
  • zia_create_ip_destination_group
  • zia_create_ip_source_group
  • zia_create_ips_signature_rule

The interactive security report will load automatically.