Burp Scan
six2dez/burp-ai-agent
Burp Suite scanning via MCP tools — passive traffic analysis, active payload testing, OOB verification, and vulnerability reporting using Burp's proxy, HTTP sender, Collaborator, and scanner APIs.
Capture a Burp Suite Repeater request/response as a PoC image (targets/<eng/poc/) by driving the Burp MCP + the Kali GUI.
$ npx skills add Encod3d-Sec/TORCH --skill screenshot-burp -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install Encod3d-Sec/TORCH screenshot-burp --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/Encod3d-Sec/TORCH.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/burp/screenshot-burp .claude/skills/screenshot-burp && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "screenshot-burp" agent skill from https://github.com/Encod3d-Sec/TORCH/tree/main/skills/burp/screenshot-burp into .claude/skills/screenshot-burp/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "screenshot-burp", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/Encod3d-Sec/TORCH/tree/main/skills/burp/screenshot-burpType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add Encod3d-Sec/TORCH --skill screenshot-burp -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install Encod3d-Sec/TORCH screenshot-burp --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Encod3d-Sec/TORCH.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/burp/screenshot-burp .agents/skills/screenshot-burp && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "screenshot-burp" agent skill from https://github.com/Encod3d-Sec/TORCH/tree/main/skills/burp/screenshot-burp into .agents/skills/screenshot-burp/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "screenshot-burp", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Encod3d-Sec/TORCH --skill screenshot-burp -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install Encod3d-Sec/TORCH screenshot-burp --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Encod3d-Sec/TORCH.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/burp/screenshot-burp .cursor/skills/screenshot-burp && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "screenshot-burp" agent skill from https://github.com/Encod3d-Sec/TORCH/tree/main/skills/burp/screenshot-burp into .cursor/skills/screenshot-burp/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "screenshot-burp", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/Encod3d-Sec/TORCH.git --path skills/burp/screenshot-burp--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add Encod3d-Sec/TORCH --skill screenshot-burp -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install Encod3d-Sec/TORCH screenshot-burp --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Encod3d-Sec/TORCH.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/burp/screenshot-burp .gemini/skills/screenshot-burp && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "screenshot-burp" agent skill from https://github.com/Encod3d-Sec/TORCH/tree/main/skills/burp/screenshot-burp into .gemini/skills/screenshot-burp/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "screenshot-burp", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install Encod3d-Sec/TORCH screenshot-burpInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add Encod3d-Sec/TORCH --skill screenshot-burp -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/Encod3d-Sec/TORCH.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/burp/screenshot-burp .github/skills/screenshot-burp && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "screenshot-burp" agent skill from https://github.com/Encod3d-Sec/TORCH/tree/main/skills/burp/screenshot-burp into .github/skills/screenshot-burp/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "screenshot-burp", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Encod3d-Sec/TORCH --skill screenshot-burp -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install Encod3d-Sec/TORCH screenshot-burp --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Encod3d-Sec/TORCH.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/burp/screenshot-burp .opencode/skills/screenshot-burp && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "screenshot-burp" agent skill from https://github.com/Encod3d-Sec/TORCH/tree/main/skills/burp/screenshot-burp into .opencode/skills/screenshot-burp/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "screenshot-burp", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
screenshot-burpCapture a Burp Suite Repeater request/response as a PoC image (targets/<eng/poc/) by driving the Burp MCP + the Kali GUI.
Screenshot Burp is an agent skill from Encod3d-Sec/TORCH. Capture a Burp Suite Repeater request/response as a PoC image (targets/<eng/poc/) by driving the Burp MCP + the Kali GUI. Replays a request in a Repeater tab, sends it, and grabs the request+response panes - a Burp-native PoC (client report / CTF writeup). Use when you want the evidence to come from Burp rather than a curl/terminal card, or whenever you drive a target through Burp and need the images. Pairs with hunt-burp.
Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Penetration testing and Capture the flag. It works with Model Context Protocol and Burp Suite. The repository describes itself as: Karpathy LLM based claude harness for PenetrationTesting / Bugbounty using obsidian. The licence is MIT.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit d21b6c9. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
bashFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Screenshot Burp loads about 1.9k tokens when it runs. Until then it costs about 111 tokens; SKILL.md has 841 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
sudo -u "$U" env DISPLAY="$D" XAUTHORITY=/home/$U/.Xauthority bash -c "Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from Encod3d-Sec/TORCH at commit d21b6c9, republished under its MIT licence (© Encod3d-Sec). 841 words, ~1,933 tokens.
.claude/skills/screenshot-burp/SKILL.md (or your agent's skills folder).Turn a Burp Repeater exchange into a report-ready request + response image. This is the Burp-native
counterpart to Skill(screenshot) (curl/terminal cards): when you drive a target through Burp, capture
the proof FROM Burp. Prereqs are the same as Skill(hunt-burp) (Burp running + the MCP Server BApp, SSE
on 127.0.0.1:9876; verify with bash /root/vm.sh 'python3 ~/burp-mcp-cli.py list').
scripts/capture.sh burp <eng> <slug> <host> <port> <https:true|false> <method> <path> [bodyfile] [tabname]
# POST with a body file (forged/complex bodies -> write to a file, avoids shell quoting):
scripts/capture.sh burp thm_x flag1 10.1.1.1 5000 true POST /login /tmp/login_body.txt "ECorp login"
# simple GET:
scripts/capture.sh burp thm_x flag3 10.1.1.1 3000 false GET /challenge/solveIt: (1) create_repeater_tab via the MCP with the raw request, (2) activates Burp on the seat display,
focuses the request editor, sends with Ctrl+Space (Burp's Repeater Send hotkey), (3) import-grabs
the window and pulls targets/<eng>/poc/NN-<slug>.png, printing the ![]() ref. Drop that ref into
walkthrough.md so the image actually renders in Obsidian (an un-referenced PNG in poc/ is invisible
in the notes - only reachable by opening the folder).
Crypto-forged / signed requests: give the exploit script a --curl-style mode that writes the exact
body to a file (e.g. /tmp/login_body.txt), then pass it as bodyfile. The Repeater tab then holds the
real forged request, so the PoC is Burp-native and reproducible.
capture.sh burp (the burp mode) (why hand-rolling this failed the first time):0). who -> the line with a (:N) display gives the user + display; use their
~/.Xauthority. A root-over-SSH grab has no X display.xdotool MOUSE clicks
(button/tab/pixel clicks are silent no-ops), but KEYBOARD events land once the window is activated
(windowactivate --sync): Ctrl+Shift+R (focus Repeater), Ctrl+= (next sub-tab), Ctrl+Space (Send).
Drive everything by keyboard; anything with no hotkey (e.g. the BApp MCP tab) needs a human mouse action.getwindowgeometry -> the client area sits at screen (0, ~35); the import -window
grab starts at the client top, so screen_y = image_y + 35 (only matters if you ever DO need a click on a
WM that accepts synthetic clicks; this one does not)./tmp/capture_burp_*.png), never a root-owned -o dir: the
sudo-as-seat-user import can't write into /tmp/poc if root created it (silent EACCES = "no PNG").send_http1_request, and that is the extension's target-approval gate (a non-approved target raises a
GUI approval prompt a headless seat cannot answer -> 15s timeout), NOT a per-session wedge. create_repeater_tab,
get_active_editor_contents, url_encode, set_proxy_intercept_state all run fine across many back-to-back
per-call sessions. capture.sh burp never calls send_http1_request (it Sends in the GUI via Ctrl+Space,
human-equivalent, which bypasses the approval gate), so it is unaffected. If create_repeater_tab itself
fails, the server is down/unreachable -> check scripts/burp/burp-transport.sh (see [[burp-mcp]]).create_repeater_tab appends the tab RIGHTMOST but does NOT focus it, so a naive grab caught whatever tab was
last active (the old stale-tab PoCs). capture.sh burp now SELECTS the intended tab deterministically and
VERIFIES it before Send/grab, so a wrong-tab PoC is impossible. The sequence (all baked into the burp mode):
getmouselocation over Burp reports window:0 and NO key/click lands -- burpshot then silently caught the
wrong tab. loginctl unlock-session <seat0-sid> (root) dismisses the lock; xset dpms force on + xset s off
(seat user) wake the display. Without this a locked/idle VM fails the precheck. (shot.py already did this;
capture.sh burp now does too.)getmouselocation over Burp returns the Burp WID (not window:0). This is
the RELIABLE check; wmctrl -lG is NOT -- it reports "no managed windows" on this no-WM seat even when input
lands, a false negative.Ctrl+= (go_to_next_tab, it WRAPS) steps sub-tabs; after each step read
get_active_editor_contents and stop when it shows the created request's METHOD PATH line (cap 16, fail loud
if never confirmed). The old "Ctrl+= does not move the tab" finding was from the LOCKED-seat era when no input
landed at all -- once unlocked, Ctrl+= selects the tab AND focuses its editor, which the oracle reads. (Marker
= the request line; a distinctive path keeps it unambiguous -- identical request-lines across tabs match the
first found.)Ctrl+Space sends the now-confirmed tab; import -window $WID grabs it. The run prints
GRAB_OK ... (verified tab: <marker>); a GRAB_FAIL tells you why (locked seat the unlock did not clear, or
MCP down -> burp-transport.sh).
CAPTURE was never the problem: import -window works headless; flameshot FAILS on this seat ("Unable to
capture screen" -- no DBus/portal in the minimal X), so for a tighter crop use import -window $WID -crop WxH+X+Y +repage or maim/scrot -a (pure X11), never flameshot here.# 1) stage the request as a Repeater tab (root, via MCP)
bash /root/vm.sh 'python3 ~/burp-mcp-cli.py call create_repeater_tab "{\"content\":\"GET /x HTTP/1.1\r\nHost: T:80\r\nConnection: close\r\n\r\n\",\"targetHostname\":\"T\",\"targetPort\":80,\"usesHttps\":false}"'
# 2) send + grab as the seat user (detect the desktop user + display from `who`)
bash /root/vm.sh 'U=$(who | awk "/\(:[0-9]/{print \$1;exit}"); D=$(who|grep -oE "\(:[0-9]+"|head -1|tr -d "(")
sudo -u "$U" env DISPLAY="$D" XAUTHORITY=/home/$U/.Xauthority bash -c "
WID=\$(xdotool search --name \"Burp Suite Professional\" | head -1)
xdotool windowactivate --sync \$WID; xdotool mousemove 500 400 click 1; sleep .4
xdotool key ctrl+space; sleep 4; import -window \$WID /tmp/burp.png"'
# 3) pull it
bash /root/vm.sh 'base64 -w0 /tmp/burp.png' | base64 -d > targets/<eng>/poc/NN-slug.pngSame as Skill(screenshot): images live only under targets/<eng>/ (gitignored); run Skill(evidence)
before a client report (Burp responses can carry cookies/PII). Never embed in wiki/.
Report: the poc/NN-slug.png saved + the ![]() ref added to walkthrough.md; note if the MCP wedged
(and whether you restarted it or fell back to the proxy).
© Encod3d-Sec, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/burp/screenshot-burp of Encod3d-Sec/TORCH.
Open the folder on GitHubat commit d21b6c9
Screenshot Burp next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Screenshot Burp this skillEncod3d-Sec/TORCH | 329 | — | ~1.9k | Automated safety check: Notes | MIT | |
| Burp Scansix2dez/burp-ai-agent | 1.5k | — | ~6.4k | Automated safety check: Warn | MIT | |
| Burp MCP Vuln Checklangbyyi/CyberStrikeAI-SRC | 129 | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | |
| Secknowledge SkillPa55w0rd/secknowledge-skill | 425 | — | ~2.7k | Automated safety check: Pass | None | |
| Idor Testingzebbern/claude-code-guide | 4.7k | 8 repos | ~3.1k | Automated safety check: Pass | MIT | |
| LLM Provider Integrationsamugit83/redamon | 3k | — | ~1.1k | Automated safety check: Pass | MIT |
six2dez/burp-ai-agent
Burp Suite scanning via MCP tools — passive traffic analysis, active payload testing, OOB verification, and vulnerability reporting using Burp's proxy, HTTP sender, Collaborator, and scanner APIs.
langbyyi/CyberStrikeAI-SRC
Automate low-impact web vulnerability verification through Burp MCP.
Pa55w0rd/secknowledge-skill
Web+AI 安全测试知识库。融合 WooYun 88,636 案例 + 先知 L1-L4 方法论 + GAARM 173 风险 + OWASP Top 10 (LLM/ASI/WSTG)。
zebbern/claude-code-guide
This skill should be used when the user asks to "test for insecure direct object references," "find IDOR vulnerabilities," "exploit broken access control," "enumerate user IDs or object references,"…
samugit83/redamon
Adding an LLM provider to RedAmon: the credential boundary (keys must never reach scan containers), prefix-routed model ids, and the provider registry.
hardw00t/ai-security-arsenal
Automated Dynamic Application Security Testing (DAST) using Playwright MCP plus standard OS pentest tooling.
Encod3d-Sec/TORCH
Runs a bug-bounty engagement through a script that tracks the current pass, builds a board of rows from recon and prints the next required action each turn.
Encod3d-Sec/TORCH
Checks that the bb, pt and ctf workflow driver is set up correctly on a machine: vault content, skill symlinks, hooks, imports and a live smoke test, with fixes for failures.
Encod3d-Sec/TORCH
Opens a visible Chromium window on a Kali VM so an operator can complete a manual login or CAPTCHA while the agent watches and acts through the chrome-devtools MCP.
Encod3d-Sec/TORCH
Runs a capture-the-flag box from first scan to root with a driver script that tracks progress and prints the next action each turn.
Encod3d-Sec/TORCH
Decides when a main pentesting agent should hand a fully-specified, mechanical exploit-compile or privilege-escalation step to a cheaper sub-agent, and how to specify that handoff safely.
Encod3d-Sec/TORCH
Adaptive web fuzzing for pentests, bug bounty and CTF work: picks the smallest suitable SecLists wordlist per target surface and calibrates filters against soft-404 responses.
Works with
Categories
Capture a Burp Suite Repeater request/response as a PoC image (targets/<eng/poc/) by driving the Burp MCP + the Kali GUI. Screenshot Burp is an agent skill from Encod3d-Sec/TORCH. Capture a Burp Suite Repeater request/response as a PoC image (targets/<eng/poc/) by driving the Burp MCP + the Kali GUI.
Screenshot Burp fits situations like: you want the evidence to come from Burp rather than a curl/terminal card; whenever you drive a target through Burp and need the images.
Run `npx skills add Encod3d-Sec/TORCH --skill screenshot-burp -a claude-code`. Or copy the skill folder (skills/burp/screenshot-burp in Encod3d-Sec/TORCH) into .claude/skills/screenshot-burp in your project. Claude Code loads it when a task matches its description.
Run `npx skills add Encod3d-Sec/TORCH --skill screenshot-burp -a codex`. Or copy the skill folder (skills/burp/screenshot-burp in Encod3d-Sec/TORCH) into .agents/skills/screenshot-burp in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Encod3d-Sec/TORCH --skill screenshot-burp -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/screenshot-burp, .gemini/skills/screenshot-burp, .github/skills/screenshot-burp and .opencode/skills/screenshot-burp in your project.
Going by SKILL.md and its folder, Screenshot Burp needs the command-line tools its instructions call (bash). Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Screenshot Burp is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.9k tokens (SKILL.md is roughly 7.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Screenshot Burp: Burp Scan (six2dez/burp-ai-agent, 1.5k stars), Burp MCP Vuln Check (langbyyi/CyberStrikeAI-SRC, 129 stars), Secknowledge Skill (Pa55w0rd/secknowledge-skill, 425 stars) and Idor Testing (zebbern/claude-code-guide, 4.7k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Encod3d-Sec (a GitHub user) maintains it in Encod3d-Sec/TORCH, which has 329 GitHub stars. The repository holds 35 skills in this directory. The repository was last updated on September 1, 2026.
Source: Encod3d-Sec/TORCH on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.