Install
$ agentstack add skill-secsilab-zscaler-claude-skills-zscaler-easm ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
About
External Attack Surface Management (EASM)
Overview
EASM discovers external attack surface: exposed assets, findings, lookalike domains. Use for security posture assessment and shadow IT detection.
MCP Tools
Available: zeasm_list_findings, zeasm_get_finding_details, zeasm_get_finding_evidence, zeasm_get_finding_scan_output, zeasm_list_lookalike_domains, zeasm_get_lookalike_domain, zeasm_list_organizations.
For full API endpoint reference, see ENDPOINTS.md in this skill directory.
Authentication
OneAPI OAuth2. Base URL: https://api.zsapi.net/easm/api/v1
Common Patterns
- List all findings sorted by severity
- Get evidence for a specific finding
- Monitor lookalike domains for brand protection
Known Limitations
- All MCP tools are read-only
- No remediation actions via API (manual follow-up required)
MCP Server
Live read operations for EASM are available via the zscaler-mcp-server (easm_* tools). This skill provides workflow guidance and context; the MCP server executes the API calls. See the MCP server repository for the full tool list and parameters.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: secsilab
- Source: secsilab/zscaler-claude-skills
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.