AgentStack
SKILL verified MIT Self-run

Zscaler Zinsights

skill-secsilab-zscaler-claude-skills-zscaler-zinsights · by secsilab

Use when querying Zscaler analytics — web traffic, firewall stats, cyber incidents, shadow IT, IoT devices, CASB reports, threat intelligence.

No reviews yet
0 installs
0 views
view→install

Install

$ agentstack add skill-secsilab-zscaler-claude-skills-zscaler-zinsights

✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

Are you the author of Zscaler Zinsights? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Zscaler Insights (ZInsights)

Overview

ZInsights provides analytics and reporting across the Zscaler platform. Use for web traffic analysis, firewall statistics, cyber incident tracking, shadow IT discovery, IoT device inventory, and CASB application reports.

MCP Tools

All ZInsights operations are read-only via MCP tools:

| Tool | Description | |------|-------------| | zinsights_get_web_traffic_no_grouping | Web traffic summary without grouping | | zinsights_get_web_traffic_by_location | Web traffic grouped by location | | zinsights_get_web_protocols | Web traffic by protocol (HTTP/HTTPS/etc.) | | zinsights_get_firewall_by_action | Firewall events by action (allow/block) | | zinsights_get_firewall_by_location | Firewall events by location | | zinsights_get_firewall_network_services | Firewall events by network service | | zinsights_get_cyber_incidents | Cyber incident summary | | zinsights_get_cyber_incidents_daily | Daily cyber incident trend | | zinsights_get_cyber_incidents_by_location | Cyber incidents by location | | zinsights_get_cyber_incidents_by_threat_and_app | Cyber incidents by threat type and application | | zinsights_get_threat_class | Threat classification breakdown | | zinsights_get_threat_super_categories | Threat super-category breakdown | | zinsights_get_shadow_it_apps | Shadow IT application list | | zinsights_get_shadow_it_summary | Shadow IT summary statistics | | zinsights_get_iot_device_stats | IoT device inventory and statistics | | zinsights_get_casb_app_report | CASB application security report |

For full API endpoint reference, see ENDPOINTS.md in this skill directory.

Authentication

Uses OneAPI OAuth2 (same as ZIA/ZPA). No separate auth flow.

Common Patterns

  • Daily security briefing: cyber incidents + threat classes + shadow IT summary
  • Location risk assessment: web traffic + firewall blocks + incidents per location
  • Shadow IT review: list unsanctioned apps, check CASB reports
  • IoT inventory: device stats for network segmentation planning

Known Limitations

  • All tools are read-only (analytics/reporting only)
  • No Postman collection available — endpoints only accessible via MCP tools
  • Time range parameters vary by tool — check MCP tool schema
  • Data freshness depends on Zscaler cloud processing (typically 15-30 min delay)

MCP Server

Live analytics queries for ZInsights are available via the zscaler-mcp-server (zinsights_* tools). This skill provides workflow guidance and context; the MCP server executes the GraphQL queries. See the MCP server repository for the full tool list and time range parameters.

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet — be the first.

Versions

  • v0.1.0 Imported from the upstream source.