zscaler
PluginManage Zscaler cloud security platform including ZPA (private access), ZIA (internet access), ZDX (digital experience), ZCC (client connector), EASM (attack surface), and Z-Insights (analytics). Create and manage policies, troubleshoot connectivity, audit security configurations, and investigate inc
Install
claude plugin install zscaler@claude-plugins-officialWhat is zscaler?
Manage Zscaler cloud security platform including ZPA (private access), ZIA (internet access), ZDX (digital experience), ZCC (client connector), EASM (attack surface), and Z-Insights (analytics). Create and manage policies, troubleshoot connectivity, audit security configurations, and investigate incidents across the full Zscaler ecosystem.
What's inside
20 bundled components — installing the plugin installs all of them.
Commands (20)
app-health
/app-healthAnalyze application health across the organization using ZDX scores and metrics.
audit-software
/audit-softwareAudit software inventory across devices using ZDX data for compliance and vulnerability assessment.
audit-ssl
/audit-sslAudit ZIA SSL inspection rules -- list rules by action (INSPECT, DO_NOT_INSPECT, DO_NOT_DECRYPT, BLOCK), identify bypasses, and assess risk.
check-access
/check-accessCheck whether a user or group can access a specific URL via ZIA policies.
compare-locations
/compare-locationsCompare digital experience across locations, departments, or geolocations using ZDX.
create-access-rule
/create-access-ruleCreate a ZPA access policy rule with v2 conditions for application access control.
create-forwarding-rule
/create-forwarding-ruleCreate a ZPA client forwarding policy rule to bypass or intercept traffic.
create-server-group
/create-server-groupCreate a ZPA server group with required app connector group dependency.
create-timeout-rule
/create-timeout-ruleCreate a ZPA timeout policy rule for session re-authentication and idle timeout.
diagnose-deeptrace
/diagnose-deeptraceRun a ZDX deep trace diagnostics session — start, analyze, or clean up deep traces for a user's device.
investigate-alerts
/investigate-alertsInvestigate active and historical ZDX alerts to understand scope, root cause, and impact.
investigate-incident
/investigate-incidentInvestigate security incidents using Z-Insights analytics -- threats, firewall actions, shadow IT, and web traffic.
investigate-sandbox
/investigate-sandboxInvestigate ZIA Sandbox file analysis -- check sandbox reports, quota, SSL prerequisite, and diagnose file block/quarantine issues.
investigate-url
/investigate-urlInvestigate where a URL or URL category is referenced across ZIA policy rules.
onboard-app
/onboard-appEnd-to-end onboarding of a new application in ZPA with full dependency chain.
onboard-location
/onboard-locationEnd-to-end onboarding of a new ZIA location with traffic forwarding dependencies.
review-attack-surface
/review-attack-surfaceReview external attack surface using Zscaler EASM findings, exposed services, and lookalike domains.
troubleshoot-connector
/troubleshoot-connectorTroubleshoot ZPA App Connector issues -- enrollment, connectivity, upgrades, and resource utilization.
troubleshoot-experience
/troubleshoot-experienceTroubleshoot a user's digital experience using ZDX scores, metrics, and network path data.
troubleshoot-user
/troubleshoot-userCross-product troubleshooting of user connectivity across ZCC, ZDX, ZPA, and ZIA.
What this can do
Capabilities declared by the plugin's own components — read straight from their frontmatter, not inferred.
Inherit all session tools
20 components declare no tool restrictions
~458 tokens of context used while enabled, before you invoke anything
Trust
83/100 · Excellent2 factors scored below maximum
Documentation
README · ~39 min readReviews
Log in to leave a review.
No reviews yet — be the first.
Explore related
Other things in this space — across every part of the ecosystem, not just plugins.
Pluginssimilar to this one
All plugins →chrome-devtools-mcp
Control and inspect a live Chrome browser from your coding agent. Record performance traces, analyze network requests, check console messages with source-mapped stack traces, and automate browser actions with Puppeteer.
47.9K stars
claude-security
Deep vulnerability scanning of your own code, run entirely inside your Claude Code session at a chosen effort tier, with every finding challenged before it is reported and the verification tally computed in code. Turns surviving findings into targeted patches, each verified by a panel of agents, tha
32.9K stars
claude-md-management
Tools to maintain and improve CLAUDE.md files - audit quality, capture session learnings, and keep project memory current.
32.9K stars
Commands
All commands →modernize-harden
Security vulnerability scan with a reviewable remediation patch — OWASP, CWE, CVE, secrets, injection
32.8K stars
modernize-status
Where am I in the modernization workflow — artifact inventory, staleness, secrets hygiene, next step
32.8K stars
help
Get help with FiftyOne skills, understand available workflows, and troubleshoot setup issues
32.8K stars
Skills
All skills →ECC
The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond.
235.3K stars
cardputer-buddy
Iterate on the Cardputer-Adv MicroPython app bundle (Claude Buddy, Snake, Hello) after the device is already provisioned via m5-onboard. Use when the user wants to add a new app, push a single changed .py without re-flashing, watch device serial logs, or run a one-shot REPL command. Trigger on "add
32.8K stars
claude-md-improver
Audit and improve CLAUDE.md files in repositories. Use when user asks to check, audit, update, improve, or fix CLAUDE.md files. Scans for all CLAUDE.md files, evaluates quality against templates, outputs quality report, then makes targeted updates. Also use when the user mentions "CLAUDE.md maintena
32.8K stars
Subagents
All subagents →ECC
The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond.
235.3K stars
claude-security
The dedicated Claude Security orchestrator. Hand it an unattended job — "fully scan this repository and patch what you find; I understand it will use a lot of tokens" — and it runs the whole thing itself: capturing the revision, driving the multi-agent scan through the claude-security:scan workflow,
32.8K stars
scan-verifier
Restricted read-only verifier dispatched by the Claude Security scan workflow to vote on one candidate finding; not for direct invocation.
32.8K stars