Burp MCP Vuln Check
langbyyi/CyberStrikeAI-SRC
Automate low-impact web vulnerability verification through Burp MCP.
Opens a visible Chromium window on a Kali VM so an operator can complete a manual login or CAPTCHA while the agent watches and acts through the chrome-devtools MCP.
$ npx skills add Encod3d-Sec/TORCH --skill chrome-devtools-browser -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install Encod3d-Sec/TORCH chrome-devtools-browser --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/Encod3d-Sec/TORCH.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/workflow/chrome-devtools-browser .claude/skills/chrome-devtools-browser && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "chrome-devtools-browser" agent skill from https://github.com/Encod3d-Sec/TORCH/tree/main/skills/workflow/chrome-devtools-browser into .claude/skills/chrome-devtools-browser/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "chrome-devtools-browser", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/Encod3d-Sec/TORCH/tree/main/skills/workflow/chrome-devtools-browserType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add Encod3d-Sec/TORCH --skill chrome-devtools-browser -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install Encod3d-Sec/TORCH chrome-devtools-browser --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Encod3d-Sec/TORCH.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/workflow/chrome-devtools-browser .agents/skills/chrome-devtools-browser && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "chrome-devtools-browser" agent skill from https://github.com/Encod3d-Sec/TORCH/tree/main/skills/workflow/chrome-devtools-browser into .agents/skills/chrome-devtools-browser/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "chrome-devtools-browser", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Encod3d-Sec/TORCH --skill chrome-devtools-browser -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install Encod3d-Sec/TORCH chrome-devtools-browser --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Encod3d-Sec/TORCH.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/workflow/chrome-devtools-browser .cursor/skills/chrome-devtools-browser && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "chrome-devtools-browser" agent skill from https://github.com/Encod3d-Sec/TORCH/tree/main/skills/workflow/chrome-devtools-browser into .cursor/skills/chrome-devtools-browser/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "chrome-devtools-browser", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/Encod3d-Sec/TORCH.git --path skills/workflow/chrome-devtools-browser--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add Encod3d-Sec/TORCH --skill chrome-devtools-browser -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install Encod3d-Sec/TORCH chrome-devtools-browser --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Encod3d-Sec/TORCH.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/workflow/chrome-devtools-browser .gemini/skills/chrome-devtools-browser && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "chrome-devtools-browser" agent skill from https://github.com/Encod3d-Sec/TORCH/tree/main/skills/workflow/chrome-devtools-browser into .gemini/skills/chrome-devtools-browser/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "chrome-devtools-browser", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install Encod3d-Sec/TORCH chrome-devtools-browserInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add Encod3d-Sec/TORCH --skill chrome-devtools-browser -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/Encod3d-Sec/TORCH.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/workflow/chrome-devtools-browser .github/skills/chrome-devtools-browser && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "chrome-devtools-browser" agent skill from https://github.com/Encod3d-Sec/TORCH/tree/main/skills/workflow/chrome-devtools-browser into .github/skills/chrome-devtools-browser/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "chrome-devtools-browser", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Encod3d-Sec/TORCH --skill chrome-devtools-browser -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install Encod3d-Sec/TORCH chrome-devtools-browser --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Encod3d-Sec/TORCH.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/workflow/chrome-devtools-browser .opencode/skills/chrome-devtools-browser && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "chrome-devtools-browser" agent skill from https://github.com/Encod3d-Sec/TORCH/tree/main/skills/workflow/chrome-devtools-browser into .opencode/skills/chrome-devtools-browser/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "chrome-devtools-browser", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
chrome-devtools-browserOpens a visible Chromium window on a Kali VM so an operator can complete a manual login or CAPTCHA while the agent watches and acts through the chrome-devtools MCP.
This skill solves a specific gap in headless browser automation: a login that needs a human, such as Smart-ID, Mobile-ID, another manual or multi-factor flow, or a CAPTCHA. A script launches a real, on-screen Chromium session on the Kali desktop, tied to a per-engagement browser profile inside a named tmux session, and tunnels its DevTools port back to the agent. The operator signs in on the visible window while the agent stays off the keyboard and mouse during that step, confirming the page with a screenshot and waiting for the operator to say they are logged in.
Once signed in, the agent drives and inspects the same session through the chrome-devtools MCP: listing and selecting tabs, navigating, taking DOM snapshots and screenshots, reading console messages, pulling the network request list (including requests made during the login redirect) and the full detail of any one request, and running scripts in the page to read client state or confirm a DOM-based issue. If the VM has no desktop session, the skill falls back to a headless browser script instead.
4 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit d21b6c9. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
bashsshFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use ssh, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Visible Browser for Manual Login Capture loads about 1.2k tokens when it runs. Until then it costs about 181 tokens; SKILL.md has 516 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from Encod3d-Sec/TORCH at commit d21b6c9, republished under its MIT licence (© Encod3d-Sec). 516 words, ~1,228 tokens.
.claude/skills/chrome-devtools-browser/SKILL.md (or your agent's skills folder).Headless browser.sh cannot solve a human login. This skill brings up a visible chromium on the
Kali desktop (:0) the operator can click and type into, with its DevTools port tunnelled back so the
chrome-devtools MCP drives and watches it. Two roles at once: the human authenticates; the agent
observes + acts. The VM holds the VPN/egress path, so it reaches both internet and in-scope targets.
bash scripts/browser-visible.sh <login-url> --profile bbtest-<eng>
# e.g. bash scripts/browser-visible.sh https://target.example/ib --profile bbtest-<eng>It resolves the VM's seat session, unlocks/wakes :0, frees the CDP port, launches chromium as the
seat user on :0 in a named tmux session (a dedicated per-engagement profile, so the operator's own
profile/cookies stay clean), then reuses scripts/browser.sh to forward CDP to http://127.0.0.1:9222.
It prints VISIBLE on :0 when a real on-screen window exists (not merely a listening port). If it prints
a no (:N) desktop session message, the VM has no desktop - fall back to scripts/browser.sh (headless).
http://127.0.0.1:9222. Confirm with list_pages; navigate_page
to the login URL if needed.take_screenshot so they can
confirm the page, then wait for their "logged in" before you drive again. The operator owns credential
entry and the phone approval; the agent never types a personal code / PIN.| Need | MCP tool |
|---|---|
| List/select tabs | list_pages (select the target tab; ignore the operator's other tabs) |
| Go to a page / back / reload | navigate_page |
| Rendered DOM (elements + uids) | take_snapshot |
| Visual PoC / confirm state | take_screenshot -> a web evidence image (hand to Skill(screenshot)/Skill(evidence)) |
| The real API calls the app makes | list_network_requests (add includePreservedRequests:true to span the login redirects); this is the authenticated API map a curl crawl never sees |
| One request's headers/body/cookies | get_network_request <reqid> |
| Console / JS errors | list_console_messages |
| Read client config / globals, confirm DOM-XSS | evaluate_script (e.g. __NEXT_DATA__, window.*, fire a payload in the real DOM) |
Once authenticated, the captured /… API calls feed the hunt skills: Skill(hunt-idor) / Skill(hunt-api)
(BOLA on id-keyed endpoints), Skill(hunt-xss) (DOM-XSS via evaluate_script), business-logic on the
authed flows. Load-bearing requests still go to Burp Repeater when reachable (Skill(hunt-burp)).
200 {"message":"Unable to login"} with NO Set-Cookie = the server rejected at an account/state
check and issued no session -> nothing to pivot (not a bug). A Set-Cookie/JWT issued before such a
check is a real authz-bypass lead - test the gated endpoints with that cookie.dbus/GPU errors in the tmux pane are non-fatal VM noise; judge success by VISIBLE on + list_pages.ssh -L; never bind 0.0.0.0 / expose it to the LAN.cdpbrowser); never tmux kill-server (the VPN/other work may live in tmux).--profile per engagement; the port-free step warns it drops any tabs on that port.bash scripts/browser.sh stop # drop the CDP tunnel
bash /root/vm.sh 'tmux kill-session -t cdpbrowser' # close the VM browserSetup / recipe rationale + the dead-ends that shaped this: scripts/browser.sh, scripts/shot.py
(seat-session resolution), and the engagement failures.md note.
© Encod3d-Sec, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/workflow/chrome-devtools-browser of Encod3d-Sec/TORCH.
Open the folder on GitHubat commit d21b6c9
Visible Browser for Manual Login Capture next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Visible Browser for Manual Login Capture this skillEncod3d-Sec/TORCH | 329 | — | ~1.2k | Automated safety check: Pass | MIT | |
| Burp MCP Vuln Checklangbyyi/CyberStrikeAI-SRC | 133 | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | |
| Dast Automationhardw00t/ai-security-arsenal | 104 | — | ~2.2k | Automated safety check: Pass | None | |
| Moai Ref LLM Securitymodu-ai/moai-adk | 1.2k | — | ~4.5k | Automated safety check: Pass | Apache-2.0 | |
| Securitytelagod/code-abyss | 244 | — | ~907 | Automated safety check: Pass | MIT | |
| Browser Testing with Chrome DevToolsaddyosmani/agent-skills | 102k | 4 repos | ~3.5k | Automated safety check: Warn | MIT |
langbyyi/CyberStrikeAI-SRC
Automate low-impact web vulnerability verification through Burp MCP.
hardw00t/ai-security-arsenal
Automated Dynamic Application Security Testing (DAST) using Playwright MCP plus standard OS pentest tooling.
modu-ai/moai-adk
AI/LLM defensive security reference: prompt-injection defense, OWASP LLM Top 10 defensive mapping, MCP and agentic tool-call hardening, training-data poisoning detection, model-output validation and…
telagod/code-abyss
Defensive security engineering judgment, distilled from a stronger model - invoke when THREAT MODELING a system or feature; making security-relevant design decisions (auth, crypto, trust boundaries…
addyosmani/agent-skills
Connects an agent to a real Chrome instance through the Chrome DevTools MCP server, so it can inspect the DOM, read console errors and profile performance directly.
Atmosphere/atmosphere
Run the pre-release end-to-end sweep of every user-facing surface — the 33 samples under samples/ (booted from their packaged artifacts and driven in a real browser via chrome-devtools MCP), the…
Encod3d-Sec/TORCH
Runs a bug-bounty engagement through a script that tracks the current pass, builds a board of rows from recon and prints the next required action each turn.
Encod3d-Sec/TORCH
Adaptive web fuzzing for pentests, bug bounty and CTF work: picks the smallest suitable SecLists wordlist per target surface and calibrates filters against soft-404 responses.
Encod3d-Sec/TORCH
IDOR / BOLA hunting - two-account methodology, identifier discovery and UUID leak chaining, the trusted-identifier test, GraphQL node and nested-object IDOR, cross-tenant escalation, write and…
Encod3d-Sec/TORCH
Checks that the bb, pt and ctf workflow driver is set up correctly on a machine: vault content, skill symlinks, hooks, imports and a live smoke test, with fixes for failures.
Encod3d-Sec/TORCH
Runs a capture-the-flag box from first scan to root with a driver script that tracks progress and prints the next action each turn.
Encod3d-Sec/TORCH
Decides when a main pentesting agent should hand a fully-specified, mechanical exploit-compile or privilege-escalation step to a cheaper sub-agent, and how to specify that handoff safely.
Works with
Categories
Opens a visible Chromium window on a Kali VM so an operator can complete a manual login or CAPTCHA while the agent watches and acts through the chrome-devtools MCP. This skill solves a specific gap in headless browser automation: a login that needs a human, such as Smart-ID, Mobile-ID, another manual or multi-factor flow, or a CAPTCHA. A script launches a real, on-screen Chromium session on the Kali desktop, tied to a per-engagement browser profile inside a named tmux session, and tunnels its DevTools port back to the agent.
Visible Browser for Manual Login Capture fits situations like: A target login needs a human to enter a code, passkey or CAPTCHA; capturing the authenticated API calls a web app makes after login; confirming and screenshotting a DOM-based issue in a live page.
Run `npx skills add Encod3d-Sec/TORCH --skill chrome-devtools-browser -a claude-code`. Or copy the skill folder (skills/workflow/chrome-devtools-browser in Encod3d-Sec/TORCH) into .claude/skills/chrome-devtools-browser in your project. Claude Code loads it when a task matches its description.
Run `npx skills add Encod3d-Sec/TORCH --skill chrome-devtools-browser -a codex`. Or copy the skill folder (skills/workflow/chrome-devtools-browser in Encod3d-Sec/TORCH) into .agents/skills/chrome-devtools-browser in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Encod3d-Sec/TORCH --skill chrome-devtools-browser -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/chrome-devtools-browser, .gemini/skills/chrome-devtools-browser, .github/skills/chrome-devtools-browser and .opencode/skills/chrome-devtools-browser in your project.
Going by SKILL.md and its folder, Visible Browser for Manual Login Capture needs the command-line tools its instructions call (bash and ssh). Our summary lists: A Kali VM with an active desktop session; The chrome-devtools MCP connected to the tunnelled DevTools port; tmux.
SKILL.md contains no URLs. Its commands use ssh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Visible Browser for Manual Login Capture is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.2k tokens (SKILL.md is roughly 4.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Visible Browser for Manual Login Capture: Burp MCP Vuln Check (langbyyi/CyberStrikeAI-SRC, 133 stars), Dast Automation (hardw00t/ai-security-arsenal, 104 stars), Moai Ref LLM Security (modu-ai/moai-adk, 1.2k stars) and Security (telagod/code-abyss, 244 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Encod3d-Sec (a GitHub user) maintains it in Encod3d-Sec/TORCH, which has 329 GitHub stars. The repository holds 35 skills in this directory. The repository was last updated on September 1, 2026.
Source: Encod3d-Sec/TORCH on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.