Agent skill

Screenshot Burp

by Encod3d-Sec in Encod3d-Sec/TORCH

Capture a Burp Suite Repeater request/response as a PoC image (targets/<eng/poc/) by driving the Burp MCP + the Kali GUI.

MITAuto-check: notesSecurity

Install Screenshot Burp

skills CLI
$ npx skills add Encod3d-Sec/TORCH --skill screenshot-burp -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Encod3d-Sec/TORCH screenshot-burp --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Encod3d-Sec/TORCH.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/burp/screenshot-burp .claude/skills/screenshot-burp && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
screenshot-burp
GitHub stars
329
Token cost
~1.9k tokens
SKILL.md length
841 words
Files
1
Skills in repo
35
Repo updated
First seen
Licence
MIT

At a glance

Capture a Burp Suite Repeater request/response as a PoC image (targets/<eng/poc/) by driving the Burp MCP + the Kali GUI.

  • Works in 4 steps: Unlock + wake the seat FIRST. A Kali… → Interactivity precheck = mouse… → SELECT by keyboard + oracle. Ctrl+=… → …
  • You want the evidence to come from Burp rather than a curl/terminal card
  • SKILL.md covers One command (use this), Gotchas baked into capture.sh…, Selecting the finding's tab… and Manual fallback (what the…, plus 2 more sections
  • Calls bash

What it does

Screenshot Burp is an agent skill from Encod3d-Sec/TORCH. Capture a Burp Suite Repeater request/response as a PoC image (targets/<eng/poc/) by driving the Burp MCP + the Kali GUI. Replays a request in a Repeater tab, sends it, and grabs the request+response panes - a Burp-native PoC (client report / CTF writeup). Use when you want the evidence to come from Burp rather than a curl/terminal card, or whenever you drive a target through Burp and need the images. Pairs with hunt-burp.

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Penetration testing and Capture the flag. It works with Model Context Protocol and Burp Suite. The repository describes itself as: Karpathy LLM based claude harness for PenetrationTesting / Bugbounty using obsidian. The licence is MIT.

When your agent uses it

  • You want the evidence to come from Burp rather than a curl/terminal card
  • Whenever you drive a target through Burp and need the images

Example prompts

  • “/screenshot-burp”

Requirements

  • Python 3

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Unlock + wake the seat FIRST. A Kali screen LOCK (seat0) routes synthetic input to the locker, so
  2. Interactivity precheck = mouse getmouselocation over Burp returns the Burp WID (not window:0). This is
  3. SELECT by keyboard + oracle. Ctrl+= (go_to_next_tab, it WRAPS) steps sub-tabs; after each step read
  4. Send + grab. Ctrl+Space sends the now-confirmed tab; import -window $WID grabs it. The run prints

What it can do on your machine

Read from SKILL.md and the folder at commit d21b6c9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • bash

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Screenshot Burp loads about 1.9k tokens when it runs. Until then it costs about 111 tokens; SKILL.md has 841 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~111
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:83
    sudo -u "$U" env DISPLAY="$D" XAUTHORITY=/home/$U/.Xauthority bash -c "

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Encod3d-Sec/TORCH at commit d21b6c9, republished under its MIT licence (© Encod3d-Sec). 841 words, ~1,933 tokens.

Download SKILL.mdSave it as .claude/skills/screenshot-burp/SKILL.md (or your agent's skills folder).
name
screenshot-burp
description
Capture a Burp Suite Repeater request/response as a PoC image (targets/<eng>/poc/) by driving the Burp MCP + the Kali GUI. Replays a request in a Repeater tab, sends it, and grabs the request+response panes - a Burp-native PoC (client report / CTF writeup). Use when you want the evidence to come from Burp rather than a curl/terminal card, or whenever you drive a target through Burp and need the images. Pairs with hunt-burp.

Screenshot: Burp Repeater request/response PoC

Turn a Burp Repeater exchange into a report-ready request + response image. This is the Burp-native counterpart to Skill(screenshot) (curl/terminal cards): when you drive a target through Burp, capture the proof FROM Burp. Prereqs are the same as Skill(hunt-burp) (Burp running + the MCP Server BApp, SSE on 127.0.0.1:9876; verify with bash /root/vm.sh 'python3 ~/burp-mcp-cli.py list').

One command (use this)

bash
scripts/capture.sh burp <eng> <slug> <host> <port> <https:true|false> <method> <path> [bodyfile] [tabname]
# POST with a body file (forged/complex bodies -> write to a file, avoids shell quoting):
scripts/capture.sh burp thm_x flag1 10.1.1.1 5000 true  POST /login /tmp/login_body.txt "ECorp login"
# simple GET:
scripts/capture.sh burp thm_x flag3 10.1.1.1 3000 false GET  /challenge/solve

It: (1) create_repeater_tab via the MCP with the raw request, (2) activates Burp on the seat display, focuses the request editor, sends with Ctrl+Space (Burp's Repeater Send hotkey), (3) import-grabs the window and pulls targets/<eng>/poc/NN-<slug>.png, printing the ![]() ref. Drop that ref into walkthrough.md so the image actually renders in Obsidian (an un-referenced PNG in poc/ is invisible in the notes - only reachable by opening the folder).

Crypto-forged / signed requests: give the exploit script a --curl-style mode that writes the exact body to a file (e.g. /tmp/login_body.txt), then pass it as bodyfile. The Repeater tab then holds the real forged request, so the PoC is Burp-native and reproducible.

Gotchas baked into capture.sh burp (the burp mode) (why hand-rolling this failed the first time)

  • Grab as the SEAT user, not root. Burp may be root-owned but it DRAWS on the desktop user's X session (the desktop login on :0). who -> the line with a (:N) display gives the user + display; use their ~/.Xauthority. A root-over-SSH grab has no X display.
  • Send = Ctrl+Space (KEYBOARD only); mouse is dead. Java Swing IGNORES synthetic xdotool MOUSE clicks (button/tab/pixel clicks are silent no-ops), but KEYBOARD events land once the window is activated (windowactivate --sync): Ctrl+Shift+R (focus Repeater), Ctrl+= (next sub-tab), Ctrl+Space (Send). Drive everything by keyboard; anything with no hotkey (e.g. the BApp MCP tab) needs a human mouse action.
  • Window offset: getwindowgeometry -> the client area sits at screen (0, ~35); the import -window grab starts at the client top, so screen_y = image_y + 35 (only matters if you ever DO need a click on a WM that accepts synthetic clicks; this one does not).
  • Write the grab to a WORLD-WRITABLE path (/tmp/capture_burp_*.png), never a root-owned -o dir: the sudo-as-seat-user import can't write into /tmp/poc if root created it (silent EACCES = "no PNG").
  • The "SSE wedge" was a MISDIAGNOSIS (corrected 2026-07-24). The only MCP call that ever hung is send_http1_request, and that is the extension's target-approval gate (a non-approved target raises a GUI approval prompt a headless seat cannot answer -> 15s timeout), NOT a per-session wedge. create_repeater_tab, get_active_editor_contents, url_encode, set_proxy_intercept_state all run fine across many back-to-back per-call sessions. capture.sh burp never calls send_http1_request (it Sends in the GUI via Ctrl+Space, human-equivalent, which bypasses the approval gate), so it is unaffected. If create_repeater_tab itself fails, the server is down/unreachable -> check scripts/burp/burp-transport.sh (see [[burp-mcp]]).
Show full SKILL.md (393 more words)Show less

Selecting the finding's tab (SOLVED 2026-07-24, Burp 2026.3.x, verified end-to-end)

create_repeater_tab appends the tab RIGHTMOST but does NOT focus it, so a naive grab caught whatever tab was last active (the old stale-tab PoCs). capture.sh burp now SELECTS the intended tab deterministically and VERIFIES it before Send/grab, so a wrong-tab PoC is impossible. The sequence (all baked into the burp mode):

  1. Unlock + wake the seat FIRST. A Kali screen LOCK (seat0) routes synthetic input to the locker, so getmouselocation over Burp reports window:0 and NO key/click lands -- burpshot then silently caught the wrong tab. loginctl unlock-session <seat0-sid> (root) dismisses the lock; xset dpms force on + xset s off (seat user) wake the display. Without this a locked/idle VM fails the precheck. (shot.py already did this; capture.sh burp now does too.)
  2. Interactivity precheck = mouse getmouselocation over Burp returns the Burp WID (not window:0). This is the RELIABLE check; wmctrl -lG is NOT -- it reports "no managed windows" on this no-WM seat even when input lands, a false negative.
  3. SELECT by keyboard + oracle. Ctrl+= (go_to_next_tab, it WRAPS) steps sub-tabs; after each step read get_active_editor_contents and stop when it shows the created request's METHOD PATH line (cap 16, fail loud if never confirmed). The old "Ctrl+= does not move the tab" finding was from the LOCKED-seat era when no input landed at all -- once unlocked, Ctrl+= selects the tab AND focuses its editor, which the oracle reads. (Marker = the request line; a distinctive path keeps it unambiguous -- identical request-lines across tabs match the first found.)
  4. Send + grab. Ctrl+Space sends the now-confirmed tab; import -window $WID grabs it. The run prints GRAB_OK ... (verified tab: <marker>); a GRAB_FAIL tells you why (locked seat the unlock did not clear, or MCP down -> burp-transport.sh). CAPTURE was never the problem: import -window works headless; flameshot FAILS on this seat ("Unable to capture screen" -- no DBus/portal in the minimal X), so for a tighter crop use import -window $WID -crop WxH+X+Y +repage or maim/scrot -a (pure X11), never flameshot here.

Manual fallback (what the script automates)

bash
# 1) stage the request as a Repeater tab (root, via MCP)
bash /root/vm.sh 'python3 ~/burp-mcp-cli.py call create_repeater_tab "{\"content\":\"GET /x HTTP/1.1\r\nHost: T:80\r\nConnection: close\r\n\r\n\",\"targetHostname\":\"T\",\"targetPort\":80,\"usesHttps\":false}"'
# 2) send + grab as the seat user (detect the desktop user + display from `who`)
bash /root/vm.sh 'U=$(who | awk "/\(:[0-9]/{print \$1;exit}"); D=$(who|grep -oE "\(:[0-9]+"|head -1|tr -d "(")
  sudo -u "$U" env DISPLAY="$D" XAUTHORITY=/home/$U/.Xauthority bash -c "
  WID=\$(xdotool search --name \"Burp Suite Professional\" | head -1)
  xdotool windowactivate --sync \$WID; xdotool mousemove 500 400 click 1; sleep .4
  xdotool key ctrl+space; sleep 4; import -window \$WID /tmp/burp.png"'
# 3) pull it
bash /root/vm.sh 'base64 -w0 /tmp/burp.png' | base64 -d > targets/<eng>/poc/NN-slug.png

Redaction / boundary

Same as Skill(screenshot): images live only under targets/<eng>/ (gitignored); run Skill(evidence) before a client report (Burp responses can carry cookies/PII). Never embed in wiki/.

Output

Report: the poc/NN-slug.png saved + the ![]() ref added to walkthrough.md; note if the MCP wedged (and whether you restarted it or fell back to the proxy).

© Encod3d-Sec, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/burp/screenshot-burp of Encod3d-Sec/TORCH.

Open the folder on GitHubat commit d21b6c9

Compare with similar skills

Screenshot Burp next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Screenshot Burp compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Screenshot Burp this skillEncod3d-Sec/TORCH329—~1.9kAutomated safety check: NotesMIT
Burp Scansix2dez/burp-ai-agent1.5k—~6.4kAutomated safety check: WarnMIT
Burp MCP Vuln Checklangbyyi/CyberStrikeAI-SRC129—~3.1kAutomated safety check: PassApache-2.0
Secknowledge SkillPa55w0rd/secknowledge-skill425—~2.7kAutomated safety check: PassNone
Idor Testingzebbern/claude-code-guide4.7k8 repos~3.1kAutomated safety check: PassMIT
LLM Provider Integrationsamugit83/redamon3k—~1.1kAutomated safety check: PassMIT

Similar skills

  • Burp Scan

    six2dez/burp-ai-agent

    Burp Suite scanning via MCP tools — passive traffic analysis, active payload testing, OOB verification, and vulnerability reporting using Burp's proxy, HTTP sender, Collaborator, and scanner APIs.

    1.5k GitHub stars~6.4k tokensUpdated yesterday
    SecurityAuto-check: warnings
  • Burp MCP Vuln Check

    langbyyi/CyberStrikeAI-SRC

    Automate low-impact web vulnerability verification through Burp MCP.

    129 GitHub stars~3.1k tokensUpdated 3 days ago
    SecurityAuto-check passed
  • Secknowledge Skill

    Pa55w0rd/secknowledge-skill

    Web+AI 安全测试知识库。融合 WooYun 88,636 案例 + 先知 L1-L4 方法论 + GAARM 173 风险 + OWASP Top 10 (LLM/ASI/WSTG)。

    425 GitHub stars~2.7k tokensUpdated 3 mo ago
    SecurityAuto-check passed
  • Idor Testing

    zebbern/claude-code-guide

    This skill should be used when the user asks to "test for insecure direct object references," "find IDOR vulnerabilities," "exploit broken access control," "enumerate user IDs or object references,"…

    4.7k GitHub starsUsed in 8 repos~3.1k tokens
    SecurityAuto-check passed
  • LLM Provider Integration

    samugit83/redamon

    Adding an LLM provider to RedAmon: the credential boundary (keys must never reach scan containers), prefix-routed model ids, and the provider registry.

    3k GitHub stars~1.1k tokensUpdated 2 days ago
    SecurityAuto-check passed
  • Dast Automation

    hardw00t/ai-security-arsenal

    Automated Dynamic Application Security Testing (DAST) using Playwright MCP plus standard OS pentest tooling.

    105 GitHub stars~2.2k tokensUpdated 5 mo ago
    SecurityAuto-check passed

More from Encod3d-Sec/TORCH

All 35 skills in this repo
  • Runs a bug-bounty engagement through a script that tracks the current pass, builds a board of rows from recon and prints the next required action each turn.

    329 GitHub stars~1.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Checks that the bb, pt and ctf workflow driver is set up correctly on a machine: vault content, skill symlinks, hooks, imports and a live smoke test, with fixes for failures.

    329 GitHub stars~611 tokensUpdated 1 mo ago
    Auto-check passed
  • Opens a visible Chromium window on a Kali VM so an operator can complete a manual login or CAPTCHA while the agent watches and acts through the chrome-devtools MCP.

    329 GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • CTF Campaign Driver

    Encod3d-Sec/TORCH

    Runs a capture-the-flag box from first scan to root with a driver script that tracks progress and prints the next action each turn.

    329 GitHub stars~1.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Decides when a main pentesting agent should hand a fully-specified, mechanical exploit-compile or privilege-escalation step to a cheaper sub-agent, and how to specify that handoff safely.

    329 GitHub stars~1.6k tokensUpdated 1 mo ago
    Auto-check: notes
  • Adaptive Web Fuzzing

    Encod3d-Sec/TORCH

    Adaptive web fuzzing for pentests, bug bounty and CTF work: picks the smallest suitable SecLists wordlist per target surface and calibrates filters against soft-404 responses.

    329 GitHub stars~1.3k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Screenshot Burp

What does Screenshot Burp do?

Capture a Burp Suite Repeater request/response as a PoC image (targets/<eng/poc/) by driving the Burp MCP + the Kali GUI. Screenshot Burp is an agent skill from Encod3d-Sec/TORCH. Capture a Burp Suite Repeater request/response as a PoC image (targets/<eng/poc/) by driving the Burp MCP + the Kali GUI.

When should I use Screenshot Burp?

Screenshot Burp fits situations like: you want the evidence to come from Burp rather than a curl/terminal card; whenever you drive a target through Burp and need the images.

How do I install Screenshot Burp in Claude Code?

Run `npx skills add Encod3d-Sec/TORCH --skill screenshot-burp -a claude-code`. Or copy the skill folder (skills/burp/screenshot-burp in Encod3d-Sec/TORCH) into .claude/skills/screenshot-burp in your project. Claude Code loads it when a task matches its description.

How do I install Screenshot Burp in Codex?

Run `npx skills add Encod3d-Sec/TORCH --skill screenshot-burp -a codex`. Or copy the skill folder (skills/burp/screenshot-burp in Encod3d-Sec/TORCH) into .agents/skills/screenshot-burp in your project. Codex loads it when a task matches its description.

Can I use Screenshot Burp in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Encod3d-Sec/TORCH --skill screenshot-burp -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/screenshot-burp, .gemini/skills/screenshot-burp, .github/skills/screenshot-burp and .opencode/skills/screenshot-burp in your project.

What does Screenshot Burp need to run?

Going by SKILL.md and its folder, Screenshot Burp needs the command-line tools its instructions call (bash). Our summary lists: Python 3.

Does Screenshot Burp access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Screenshot Burp safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Screenshot Burp use?

Screenshot Burp is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Screenshot Burp use?

About 1.9k tokens (SKILL.md is roughly 7.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Screenshot Burp?

Skills that share tags, products or a category with Screenshot Burp: Burp Scan (six2dez/burp-ai-agent, 1.5k stars), Burp MCP Vuln Check (langbyyi/CyberStrikeAI-SRC, 129 stars), Secknowledge Skill (Pa55w0rd/secknowledge-skill, 425 stars) and Idor Testing (zebbern/claude-code-guide, 4.7k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Screenshot Burp?

Encod3d-Sec (a GitHub user) maintains it in Encod3d-Sec/TORCH, which has 329 GitHub stars. The repository holds 35 skills in this directory. The repository was last updated on September 1, 2026.

Source: Encod3d-Sec/TORCH on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.