ClaudeSuperPower

zscaler

Plugin

Manage Zscaler cloud security platform including ZPA (private access), ZIA (internet access), ZDX (digital experience), ZCC (client connector), EASM (attack surface), and Z-Insights (analytics). Create and manage policies, troubleshoot connectivity, audit security configurations, and investigate inc

Install

claude plugin install zscaler@claude-plugins-official

What is zscaler?

Manage Zscaler cloud security platform including ZPA (private access), ZIA (internet access), ZDX (digital experience), ZCC (client connector), EASM (attack surface), and Z-Insights (analytics). Create and manage policies, troubleshoot connectivity, audit security configurations, and investigate incidents across the full Zscaler ecosystem.

What's inside

20 bundled components — installing the plugin installs all of them.

Commands (20)

app-health

/app-health

Analyze application health across the organization using ZDX scores and metrics.

audit-software

/audit-software

Audit software inventory across devices using ZDX data for compliance and vulnerability assessment.

audit-ssl

/audit-ssl

Audit ZIA SSL inspection rules -- list rules by action (INSPECT, DO_NOT_INSPECT, DO_NOT_DECRYPT, BLOCK), identify bypasses, and assess risk.

check-access

/check-access

Check whether a user or group can access a specific URL via ZIA policies.

compare-locations

/compare-locations

Compare digital experience across locations, departments, or geolocations using ZDX.

create-access-rule

/create-access-rule

Create a ZPA access policy rule with v2 conditions for application access control.

create-forwarding-rule

/create-forwarding-rule

Create a ZPA client forwarding policy rule to bypass or intercept traffic.

create-server-group

/create-server-group

Create a ZPA server group with required app connector group dependency.

create-timeout-rule

/create-timeout-rule

Create a ZPA timeout policy rule for session re-authentication and idle timeout.

diagnose-deeptrace

/diagnose-deeptrace

Run a ZDX deep trace diagnostics session — start, analyze, or clean up deep traces for a user's device.

investigate-alerts

/investigate-alerts

Investigate active and historical ZDX alerts to understand scope, root cause, and impact.

investigate-incident

/investigate-incident

Investigate security incidents using Z-Insights analytics -- threats, firewall actions, shadow IT, and web traffic.

investigate-sandbox

/investigate-sandbox

Investigate ZIA Sandbox file analysis -- check sandbox reports, quota, SSL prerequisite, and diagnose file block/quarantine issues.

investigate-url

/investigate-url

Investigate where a URL or URL category is referenced across ZIA policy rules.

onboard-app

/onboard-app

End-to-end onboarding of a new application in ZPA with full dependency chain.

onboard-location

/onboard-location

End-to-end onboarding of a new ZIA location with traffic forwarding dependencies.

review-attack-surface

/review-attack-surface

Review external attack surface using Zscaler EASM findings, exposed services, and lookalike domains.

troubleshoot-connector

/troubleshoot-connector

Troubleshoot ZPA App Connector issues -- enrollment, connectivity, upgrades, and resource utilization.

troubleshoot-experience

/troubleshoot-experience

Troubleshoot a user's digital experience using ZDX scores, metrics, and network path data.

troubleshoot-user

/troubleshoot-user

Cross-product troubleshooting of user connectivity across ZCC, ZDX, ZPA, and ZIA.

What this can do

Capabilities declared by the plugin's own components — read straight from their frontmatter, not inferred.

Inherit all session tools

20 components declare no tool restrictions

~458 tokens of context used while enabled, before you invoke anything

Trust

83/100 · Excellent

2 factors scored below maximum

Unscoped tools

Documentation

README · ~39 min read

Zscaler MCP

PyPI version PyPI - Python Version Documentation codecov GitHub commit activity License Automation Hub Zscaler Community

zscaler-mcp-server is a Model Context Protocol (MCP) server that connects AI agents with the Zscaler Zero Trust Exchange platform. By default, the server operates in read-only mode for security, requiring explicit opt-in to enable write operations.

Support Disclaimer

Reviews

Log in to leave a review.

No reviews yet — be the first.

Explore related

Other things in this space — across every part of the ecosystem, not just plugins.