Developer tool
Burp Suite agent skills for Claude Code, Codex and other agents.
- skills
- 22
- official
- 1
- Type
- Developer tool
- Website
- portswigger.net
- Official GitHub
- PortSwigger
Burp Suite skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
Official (1 skill)
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Searches and extracts data from Burp Suite project files on the command line: regex searches over responses, audit findings, proxy history and site map data. | trailofbits/ | 7.4k | 3 repos | ~4.2k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
Community
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 2 | 对 Yakit 仓库的代码改动做规范化 code review:按代码逻辑、TS 定义、UI 引用与 Props、CSS 样式、依赖版本、配置项六个维度审查,检查测试用例缺失,强制执行 tsc 类型检查与 vitest 测试验证,输出「结果汇总 / 明细解释 / 合并结论」三块报告,经用户确认后写入文件。当用户要求 review、审查、评审代码改动,或在提交、合并、提 PR… | yaklang/ | 7.8k | — | ~1.4k | Automated safety check: Notes | AGPL-3.0 | 7 days ago |
| 3 | 为 Yakit 仓库一站式完成提 PR 流程:提交工作区改动、调用 code-review skill 评审、推送远端后在 yaklang/yakit 创建或更新 PR。当用户要求提 PR、提交 PR、创建 PR、发 PR、raise/submit/open PR、"create PR"、更新已有 PR,或使用 /create-pr 时触发。 | yaklang/ | 7.8k | — | ~1.6k | Automated safety check: Pass | AGPL-3.0 | 7 days ago |
| 4 | 当用户要求审计 Java、.NET 或 PHP 源码/部署产物/反编译产物/安全发现,并需要默认脚本输出目录、报告输出目录、Java/.NET 反编译与反混淆参考、Java 组件 YAML 正则匹配扫描、确认漏洞判定标准、安全 Payload 和 BurpSuite 原始 HTTP 请求包证据时使用。仅用于授权代码审计和防御性安全验证。 | RuoJi6/ | 1k | — | ~447 | Automated safety check: Pass | No licence | 3 mo ago |
| 5 | 为 Yakit 仓库完成一次本地提交:确定提交范围(暂存区优先,空则弹框确认)、基于 diff 归纳一行符合仓库风格的 message、commit 前弹窗确认、执行 git commit(不推送)。只要 message 时仅输出文本。用户说「提交」「commit 代码」或输入 /commit-msg,或被 create-pr 等 skill 调用时使用。 | yaklang/ | 7.8k | — | ~559 | Automated safety check: Pass | AGPL-3.0 | 7 days ago |
| 6 | Burp Suite scanning via MCP tools — passive traffic analysis, active payload testing, OOB verification, and vulnerability reporting using Burp's proxy, HTTP sender, Collaborator, and scanner APIs. | six2dez/ | 1.5k | — | ~6.4k | Automated safety check: Warn | MIT | 1 mo ago |
| 7 | Automate low-impact web vulnerability verification through Burp MCP. | langbyyi/ | 133 | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | 10 days ago |
| 8 | Interacting with BurpSuite over the reburp extension that exposes the full Montoya API as a local REST API. | forefy/ | 116 | — | ~883 | Automated safety check: Pass | MIT | 2 days ago |
| 9 | This skill should be used when the user asks to "test for insecure direct object references," "find IDOR vulnerabilities," "exploit broken access control," "enumerate user IDs or object references,"… | zebbern/ | 4.6k | 7 repos | ~3.1k | Automated safety check: Pass | MIT | today |
| 10 | Check reburp's Montoya API coverage and detect when a Burp/Montoya upgrade added or changed APIs. | forefy/ | 116 | — | ~213 | Automated safety check: Pass | MIT | 2 days ago |
| 11 | Detects and exploits race condition (TOCTOU) vulnerabilities in web applications using Burp Suite's Turbo Intruder extension and its single-packet attack technique to fire parallel requests that… | mukul975/ | 34k | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 12 | Tests API rate limiting for bypass vulnerabilities using Python (requests/aiohttp) and Burp Suite Turbo Intruder to manipulate headers (e.g. | mukul975/ | 34k | — | ~4.4k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 13 | Triages web application vulnerability findings from DAST/SAST scanners such as Burp Suite and ZAP, using the OWASP Risk Rating Methodology to confirm true positives, dismiss false positives, and… | mukul975/ | 34k | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 14 | Manually identifies flaws in application business logic - price manipulation, multi-step workflow bypass, and privilege escalation - by intercepting and modifying requests with Burp Suite, going… | mukul975/ | 34k | — | ~3.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 15 | Tests OAuth 2.0 and OpenID Connect implementations for authorization code interception, redirect URI manipulation, CSRF in OAuth flows, token leakage, scope escalation, and PKCE bypass, using Burp… | mukul975/ | 34k | — | ~4.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 16 | Detects and exploits HTTP request smuggling caused by Content-Length/Transfer-Encoding parsing discrepancies between front-end and back-end servers, using Burp Suite Repeater (auto Content-Length… | mukul975/ | 34k | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 17 | Detecting and exploiting SQL injection vulnerabilities using sqlmap to extract database contents during authorized penetration tests. | mukul975/ | 34k | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 18 | This skill should be used when the user asks to "intercept HTTP traffic", "modify web requests", "use Burp Suite for testing", "perform web vulnerability scanning", "test with Burp ... | aiskillstore/ | 430 | 4 repos | ~2.7k | Automated safety check: Pass | No licence | today |
| 19 | Capture a Burp Suite Repeater request/response as a PoC image (targets/<eng/poc/) by driving the Burp MCP + the Kali GUI. | Encod3d-Sec/ | 329 | — | ~1.9k | Automated safety check: Notes | MIT | 1 mo ago |
| 20 | Comprehensive API security testing methodology covering REST, gRPC, and WebSocket attack surfaces. | SnailSploit/ | 7.3k | — | ~5k | Automated safety check: Pass | MIT | 17 days ago |
| 21 | 21.Hunt Burp Drive Burp Suite over its MCP server as an AI triage + attack layer - review proxy history for signals, replay via Repeater/send, OOB-gate blind bugs with Collaborator, fuzz via Intruder (RoE-safe)… | Encod3d-Sec/ | 329 | — | ~3.1k | Automated safety check: Pass | MIT | 1 mo ago |
| 22 | Operate BurpSuite MCP Bridge for professional, authorized web testing. | hashgraph-online/ | 1.2k | — | ~964 | Automated safety check: Pass | Apache-2.0 | today |
Questions, answered from the data.
What is the best Burp Suite skill?
Burp Suite Project Parser (official) from trailofbits/skills ranks first of the 22 Burp Suite skills listed here, with the highest score: its repository has 7.4k GitHub stars, 3 other GitHub owners carry a copy, its SKILL.md loads about 4.2k tokens and it has informational notes only in the automated safety check. Next come Code Review and Create PR.
Is there an official Burp Suite skill?
1 of the 22 Burp Suite skills are official, published by the vendor's own GitHub organization: Burp Suite Project Parser.
How are these skills ranked?
By Skill Navigator score, which combines the GitHub stars of the skill's repository (shared across that repo's skills and discounted for large collections), how many other GitHub owners carry a copy of the skill, and automated SKILL.md quality checks, minus penalties for safety-check warnings and for each further skill from the same repository. Skills that fail the safety check are not listed.