Developer tool

Burp Suite agent skills for Claude Code, Codex and other agents.

Web application security testing toolkit from PortSwigger.
skills
22
official
1
Type
Developer tool
Website
portswigger.net
Official GitHub
PortSwigger

Burp Suite skills, ranked

Ranked by score. Sort bymost stars,trending,newest,recently updated

Official (1 skill)

Official Burp Suite skills
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
1

Searches and extracts data from Burp Suite project files on the command line: regex searches over responses, audit findings, proxy history and site map data.

trailofbits/skills7.4k3 repos~4.2kAutomated safety check: NotesCC-BY-SA-4.05 days ago

Community

Community Burp Suite skills
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
2

对 Yakit 仓库的代码改动做规范化 code review:按代码逻辑、TS 定义、UI 引用与 Props、CSS 样式、依赖版本、配置项六个维度审查,检查测试用例缺失,强制执行 tsc 类型检查与 vitest 测试验证,输出「结果汇总 / 明细解释 / 合并结论」三块报告,经用户确认后写入文件。当用户要求 review、审查、评审代码改动,或在提交、合并、提 PR…

yaklang/yakit7.8k—~1.4kAutomated safety check: NotesAGPL-3.07 days ago
3

为 Yakit 仓库一站式完成提 PR 流程:提交工作区改动、调用 code-review skill 评审、推送远端后在 yaklang/yakit 创建或更新 PR。当用户要求提 PR、提交 PR、创建 PR、发 PR、raise/submit/open PR、"create PR"、更新已有 PR,或使用 /create-pr 时触发。

yaklang/yakit7.8k—~1.6kAutomated safety check: PassAGPL-3.07 days ago
4

当用户要求审计 Java、.NET 或 PHP 源码/部署产物/反编译产物/安全发现,并需要默认脚本输出目录、报告输出目录、Java/.NET 反编译与反混淆参考、Java 组件 YAML 正则匹配扫描、确认漏洞判定标准、安全 Payload 和 BurpSuite 原始 HTTP 请求包证据时使用。仅用于授权代码审计和防御性安全验证。

RuoJi6/audit-skills1k—~447Automated safety check: PassNo licence3 mo ago
5

为 Yakit 仓库完成一次本地提交:确定提交范围(暂存区优先,空则弹框确认)、基于 diff 归纳一行符合仓库风格的 message、commit 前弹窗确认、执行 git commit(不推送)。只要 message 时仅输出文本。用户说「提交」「commit 代码」或输入 /commit-msg,或被 create-pr 等 skill 调用时使用。

yaklang/yakit7.8k—~559Automated safety check: PassAGPL-3.07 days ago
6

Burp Suite scanning via MCP tools — passive traffic analysis, active payload testing, OOB verification, and vulnerability reporting using Burp's proxy, HTTP sender, Collaborator, and scanner APIs.

six2dez/burp-ai-agent1.5k—~6.4kAutomated safety check: WarnMIT1 mo ago
7

Automate low-impact web vulnerability verification through Burp MCP.

langbyyi/CyberStrikeAI-SRC133—~3.1kAutomated safety check: PassApache-2.010 days ago
8

Interacting with BurpSuite over the reburp extension that exposes the full Montoya API as a local REST API.

forefy/reburp116—~883Automated safety check: PassMIT2 days ago
9

This skill should be used when the user asks to "test for insecure direct object references," "find IDOR vulnerabilities," "exploit broken access control," "enumerate user IDs or object references,"…

zebbern/claude-code-guide4.6k7 repos~3.1kAutomated safety check: PassMITtoday
10

Check reburp's Montoya API coverage and detect when a Burp/Montoya upgrade added or changed APIs.

forefy/reburp116—~213Automated safety check: PassMIT2 days ago
11

Detects and exploits race condition (TOCTOU) vulnerabilities in web applications using Burp Suite's Turbo Intruder extension and its single-packet attack technique to fire parallel requests that…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.3kAutomated safety check: PassApache-2.01 mo ago
12

Tests API rate limiting for bypass vulnerabilities using Python (requests/aiohttp) and Burp Suite Turbo Intruder to manipulate headers (e.g.

mukul975/Anthropic-Cybersecurity-Skills34k—~4.4kAutomated safety check: PassApache-2.01 mo ago
13

Triages web application vulnerability findings from DAST/SAST scanners such as Burp Suite and ZAP, using the OWASP Risk Rating Methodology to confirm true positives, dismiss false positives, and…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.2kAutomated safety check: PassApache-2.01 mo ago
14

Manually identifies flaws in application business logic - price manipulation, multi-step workflow bypass, and privilege escalation - by intercepting and modifying requests with Burp Suite, going…

mukul975/Anthropic-Cybersecurity-Skills34k—~3.3kAutomated safety check: PassApache-2.01 mo ago
15

Tests OAuth 2.0 and OpenID Connect implementations for authorization code interception, redirect URI manipulation, CSRF in OAuth flows, token leakage, scope escalation, and PKCE bypass, using Burp…

mukul975/Anthropic-Cybersecurity-Skills34k—~4.3kAutomated safety check: PassApache-2.01 mo ago
16

Detects and exploits HTTP request smuggling caused by Content-Length/Transfer-Encoding parsing discrepancies between front-end and back-end servers, using Burp Suite Repeater (auto Content-Length…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.8kAutomated safety check: PassApache-2.01 mo ago
17

Detecting and exploiting SQL injection vulnerabilities using sqlmap to extract database contents during authorized penetration tests.

mukul975/Anthropic-Cybersecurity-Skills34k—~2.3kAutomated safety check: PassApache-2.01 mo ago
18

This skill should be used when the user asks to "intercept HTTP traffic", "modify web requests", "use Burp Suite for testing", "perform web vulnerability scanning", "test with Burp ...

aiskillstore/marketplace4304 repos~2.7kAutomated safety check: PassNo licencetoday
19

Capture a Burp Suite Repeater request/response as a PoC image (targets/<eng/poc/) by driving the Burp MCP + the Kali GUI.

Encod3d-Sec/TORCH329—~1.9kAutomated safety check: NotesMIT1 mo ago
20

Comprehensive API security testing methodology covering REST, gRPC, and WebSocket attack surfaces.

SnailSploit/Claude-Red7.3k—~5kAutomated safety check: PassMIT17 days ago
21

Drive Burp Suite over its MCP server as an AI triage + attack layer - review proxy history for signals, replay via Repeater/send, OOB-gate blind bugs with Collaborator, fuzz via Intruder (RoE-safe)…

Encod3d-Sec/TORCH329—~3.1kAutomated safety check: PassMIT1 mo ago
22

Operate BurpSuite MCP Bridge for professional, authorized web testing.

hashgraph-online/awesome-codex-plugins1.2k—~964Automated safety check: PassApache-2.0today

Questions, answered from the data.

What is the best Burp Suite skill?

Burp Suite Project Parser (official) from trailofbits/skills ranks first of the 22 Burp Suite skills listed here, with the highest score: its repository has 7.4k GitHub stars, 3 other GitHub owners carry a copy, its SKILL.md loads about 4.2k tokens and it has informational notes only in the automated safety check. Next come Code Review and Create PR.

Is there an official Burp Suite skill?

1 of the 22 Burp Suite skills are official, published by the vendor's own GitHub organization: Burp Suite Project Parser.

How are these skills ranked?

By Skill Navigator score, which combines the GitHub stars of the skill's repository (shared across that repo's skills and discounted for large collections), how many other GitHub owners carry a copy of the skill, and automated SKILL.md quality checks, minus penalties for safety-check warnings and for each further skill from the same repository. Skills that fail the safety check are not listed.