Search
Burp Suite · For developers
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | 对 Yakit 仓库的代码改动做规范化 code review:按代码逻辑、TS 定义、UI 引用与 Props、CSS 样式、依赖版本、配置项六个维度审查,检查测试用例缺失,强制执行 tsc 类型检查与 vitest 测试验证,输出「结果汇总 / 明细解释 / 合并结论」三块报告,经用户确认后写入文件。当用户要求 review、审查、评审代码改动,或在提交、合并、提 PR… | yaklang/ | 7.8k | — | ~1.5k | Automated safety check: Notes | AGPL-3.0 | yesterday |
| 2 | 为 Yakit 仓库一站式完成提 PR 流程:提交工作区改动、调用 code-review skill 评审、推送远端后在 yaklang/yakit 创建或更新 PR。当用户要求提 PR、提交 PR、创建 PR、发 PR、raise/submit/open PR、"create PR"、更新已有 PR,或使用 /create-pr 时触发。 | yaklang/ | 7.8k | — | ~2.1k | Automated safety check: Pass | AGPL-3.0 | yesterday |
| 3 | 当用户要求审计 Java、.NET 或 PHP 源码/部署产物/反编译产物/安全发现,并需要默认脚本输出目录、报告输出目录、Java/.NET 反编译与反混淆参考、Java 组件 YAML 正则匹配扫描、确认漏洞判定标准、安全 Payload 和 BurpSuite 原始 HTTP 请求包证据时使用。仅用于授权代码审计和防御性安全验证。 | RuoJi6/ | 1k | — | ~447 | Automated safety check: Pass | No licence | 3 mo ago |
| 4 | 为 Yakit 仓库完成一次本地提交:确定提交范围(暂存区优先,空则弹框确认)、基于 diff 按改动类型归纳中文 message(每种类型一行)、commit 前弹窗确认、执行 git commit(不推送)。只要 message 时仅输出文本。用户说「提交」「commit 代码」或输入 /commit-msg,或被 create-pr 等 skill 调用时使用。 | yaklang/ | 7.8k | — | ~833 | Automated safety check: Pass | AGPL-3.0 | yesterday |
| 5 | Burp Suite scanning via MCP tools — passive traffic analysis, active payload testing, OOB verification, and vulnerability reporting using Burp's proxy, HTTP sender, Collaborator, and scanner APIs. | six2dez/ | 1.5k | — | ~6.4k | Automated safety check: Warn | MIT | 2 days ago |
| 6 | Automate low-impact web vulnerability verification through Burp MCP. | langbyyi/ | 129 | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | 4 days ago |
| 7 | This skill should be used when the user asks to "test for insecure direct object references," "find IDOR vulnerabilities," "exploit broken access control," "enumerate user IDs or object references,"… | zebbern/ | 4.7k | 8 repos | ~3.1k | Automated safety check: Pass | MIT | yesterday |
| 8 | Interacting with BurpSuite over the reburp extension that exposes the full Montoya API as a local REST API. | forefy/ | 117 | — | ~883 | Automated safety check: Pass | MIT | 6 days ago |
| 9 | Check reburp's Montoya API coverage and detect when a Burp/Montoya upgrade added or changed APIs. | forefy/ | 117 | — | ~213 | Automated safety check: Pass | MIT | 6 days ago |
| 10 | Detects and exploits race condition (TOCTOU) vulnerabilities in web applications using Burp Suite's Turbo Intruder extension and its single-packet attack technique to fire parallel requests that… | mukul975/ | 34k | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 11 | Tests API rate limiting for bypass vulnerabilities using Python (requests/aiohttp) and Burp Suite Turbo Intruder to manipulate headers (e.g. | mukul975/ | 34k | — | ~4.4k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 12 | Triages web application vulnerability findings from DAST/SAST scanners such as Burp Suite and ZAP, using the OWASP Risk Rating Methodology to confirm true positives, dismiss false positives, and… | mukul975/ | 34k | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 13 | Manually identifies flaws in application business logic - price manipulation, multi-step workflow bypass, and privilege escalation - by intercepting and modifying requests with Burp Suite, going… | mukul975/ | 34k | — | ~3.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 14 | Tests OAuth 2.0 and OpenID Connect implementations for authorization code interception, redirect URI manipulation, CSRF in OAuth flows, token leakage, scope escalation, and PKCE bypass, using Burp… | mukul975/ | 34k | — | ~4.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 15 | Detects and exploits HTTP request smuggling caused by Content-Length/Transfer-Encoding parsing discrepancies between front-end and back-end servers, using Burp Suite Repeater (auto Content-Length… | mukul975/ | 34k | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 16 | Detecting and exploiting SQL injection vulnerabilities using sqlmap to extract database contents during authorized penetration tests. | mukul975/ | 34k | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 17 | This skill should be used when the user asks to "intercept HTTP traffic", "modify web requests", "use Burp Suite for testing", "perform web vulnerability scanning", "test with Burp ... | aiskillstore/ | 433 | 4 repos | ~2.7k | Automated safety check: Pass | No licence | yesterday |
| 18 | Capture a Burp Suite Repeater request/response as a PoC image (targets/<eng/poc/) by driving the Burp MCP + the Kali GUI. | Encod3d-Sec/ | 329 | — | ~1.9k | Automated safety check: Notes | MIT | 1 mo ago |
| 19 | Comprehensive API security testing methodology covering REST, gRPC, and WebSocket attack surfaces. | SnailSploit/ | 7.4k | — | ~5k | Automated safety check: Pass | MIT | 21 days ago |
| 20 | 20.Hunt Burp Drive Burp Suite over its MCP server as an AI triage + attack layer - review proxy history for signals, replay via Repeater/send, OOB-gate blind bugs with Collaborator, fuzz via Intruder (RoE-safe)… | Encod3d-Sec/ | 329 | — | ~3.1k | Automated safety check: Pass | MIT | 1 mo ago |
| 21 | Operate BurpSuite MCP Bridge for professional, authorized web testing. | hashgraph-online/ | 1.3k | — | ~964 | Automated safety check: Pass | Apache-2.0 | yesterday |