Having /etc/zabbix as --- for all makes administration harder, and it doesn't seem like there's any secret stuff in there. Can we just make it world-readable (and -executable for the directory)?
Actually -- files in /etc/zabbix can contain db passwords and private snmp community strings. So, there does seem to be good reasons for it to be limited to the zabbix user.