Burp Scan
six2dez/burp-ai-agent
Burp Suite scanning via MCP tools — passive traffic analysis, active payload testing, OOB verification, and vulnerability reporting using Burp's proxy, HTTP sender, Collaborator, and scanner APIs.
Automate low-impact web vulnerability verification through Burp MCP.
$ npx skills add langbyyi/CyberStrikeAI-SRC --skill burp-mcp-vuln-check -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install langbyyi/CyberStrikeAI-SRC burp-mcp-vuln-check --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/langbyyi/CyberStrikeAI-SRC.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/burp-mcp-vuln-check .claude/skills/burp-mcp-vuln-check && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "burp-mcp-vuln-check" agent skill from https://github.com/langbyyi/CyberStrikeAI-SRC/tree/master/skills/burp-mcp-vuln-check into .claude/skills/burp-mcp-vuln-check/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "burp-mcp-vuln-check", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/langbyyi/CyberStrikeAI-SRC/tree/master/skills/burp-mcp-vuln-checkType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add langbyyi/CyberStrikeAI-SRC --skill burp-mcp-vuln-check -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install langbyyi/CyberStrikeAI-SRC burp-mcp-vuln-check --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/langbyyi/CyberStrikeAI-SRC.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/burp-mcp-vuln-check .agents/skills/burp-mcp-vuln-check && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "burp-mcp-vuln-check" agent skill from https://github.com/langbyyi/CyberStrikeAI-SRC/tree/master/skills/burp-mcp-vuln-check into .agents/skills/burp-mcp-vuln-check/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "burp-mcp-vuln-check", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add langbyyi/CyberStrikeAI-SRC --skill burp-mcp-vuln-check -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install langbyyi/CyberStrikeAI-SRC burp-mcp-vuln-check --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/langbyyi/CyberStrikeAI-SRC.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/burp-mcp-vuln-check .cursor/skills/burp-mcp-vuln-check && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "burp-mcp-vuln-check" agent skill from https://github.com/langbyyi/CyberStrikeAI-SRC/tree/master/skills/burp-mcp-vuln-check into .cursor/skills/burp-mcp-vuln-check/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "burp-mcp-vuln-check", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/langbyyi/CyberStrikeAI-SRC.git --path skills/burp-mcp-vuln-check--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add langbyyi/CyberStrikeAI-SRC --skill burp-mcp-vuln-check -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install langbyyi/CyberStrikeAI-SRC burp-mcp-vuln-check --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/langbyyi/CyberStrikeAI-SRC.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/burp-mcp-vuln-check .gemini/skills/burp-mcp-vuln-check && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "burp-mcp-vuln-check" agent skill from https://github.com/langbyyi/CyberStrikeAI-SRC/tree/master/skills/burp-mcp-vuln-check into .gemini/skills/burp-mcp-vuln-check/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "burp-mcp-vuln-check", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install langbyyi/CyberStrikeAI-SRC burp-mcp-vuln-checkInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add langbyyi/CyberStrikeAI-SRC --skill burp-mcp-vuln-check -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/langbyyi/CyberStrikeAI-SRC.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/burp-mcp-vuln-check .github/skills/burp-mcp-vuln-check && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "burp-mcp-vuln-check" agent skill from https://github.com/langbyyi/CyberStrikeAI-SRC/tree/master/skills/burp-mcp-vuln-check into .github/skills/burp-mcp-vuln-check/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "burp-mcp-vuln-check", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add langbyyi/CyberStrikeAI-SRC --skill burp-mcp-vuln-check -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install langbyyi/CyberStrikeAI-SRC burp-mcp-vuln-check --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/langbyyi/CyberStrikeAI-SRC.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/burp-mcp-vuln-check .opencode/skills/burp-mcp-vuln-check && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "burp-mcp-vuln-check" agent skill from https://github.com/langbyyi/CyberStrikeAI-SRC/tree/master/skills/burp-mcp-vuln-check into .opencode/skills/burp-mcp-vuln-check/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "burp-mcp-vuln-check", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
burp-mcp-vuln-checkAutomate low-impact web vulnerability verification through Burp MCP.
Burp MCP Vuln Check is an agent skill from langbyyi/CyberStrikeAI-SRC. Automate low-impact web vulnerability verification through Burp MCP. Use when Codex is asked to check, reproduce, triage, or write evidence for vulnerabilities using Burp Suite proxy history, Repeater, Collaborator/OOB payloads, HTTP replay, parameter mutation, response diffing, or scanner issues. Also use for mini program/微信小程序 Burp history, wildcard domains like .example.com, root-domain traffic reviews, arbitrary login/任意登录, sessionkey/sessionKey/sessionkey/session-key/session…
Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including scripts and reference files (for example `references/article-rule-template.md` and `scripts/miniapp_burp_preflight.py`).
It sits in Security, covering Messaging and chat bots, MCP servers and Penetration testing. It works with Model Context Protocol, WeChat and Burp Suite. The licence is Apache-2.0.
6 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 166ee1c. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Burp MCP Vuln Check loads about 3.1k tokens when it runs, and up to ~3.6k if it reads all its reference files. Until then it costs about 214 tokens; SKILL.md has 1,282 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from langbyyi/CyberStrikeAI-SRC at commit 166ee1c, republished under its Apache-2.0 licence (© langbyyi). 1,282 words, ~3,122 tokens.
.claude/skills/burp-mcp-vuln-check/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.AI LOAD INSTRUCTION: Low-impact vulnerability verification through Burp MCP proxy history and HTTP replay. Covers baseline preservation, single-variable mutation, differential evidence (two independent indicators), Collaborator/OOB blind detection, mini program/WeChat session_key preflight, and article-derived targeted checks. Base models often jump to mass scanning — this skill enforces methodical one-variable-at-a-time verification with conservative reporting.
| Signal | Probe | Why |
|---|---|---|
| Target in proxy history? | get_proxy_http_history_regex to scope host/endpoints | Establish what is in scope |
| Baseline captured? | Replay one unmodified request with send_http1_request | Record normal response fingerprint |
| One variable mutated? | Change only the suspected param, compare vs baseline | Single-variable causality |
| Responses differ? | Confirm with two independent indicators | Reduce false positives |
| No visible difference? | Inject Collaborator payload for blind detection | OOB callback confirms blind vuln |
# Quick test — baseline then mutate one parameter
# 1. Replay original request → record status/length/body markers
# 2. Change one parameter → compare response
# 3. If blind: inject Collaborator hostname, poll for interactionsTreat every check as authorized testing against the user's target. Keep probes low impact: prefer safe markers, benign arithmetic, DNS-only OOB payloads, timeout caps, and read-only requests. Do not mass exploit, persist shells, dump secrets, or run destructive payloads unless the user explicitly authorizes that exact action.
If the task is based on a writeup, first extract the vulnerability class, affected paths, required headers/cookies, trigger parameters, positive/negative indicators, and any OOB behavior. If article-specific details are missing, use the generic workflow below and ask for the missing PoC only when a targeted check cannot be inferred.
For article-derived checks, read references/article-rule-template.md and fill the relevant fields mentally or in notes before probing.
If the user asks broad website/SRC triage such as "help me check xx website vulnerabilities" (帮我排查 xx 网站漏洞), "check if a domain has vulnerabilities" (看看某域名有没有漏洞), wildcard/root-domain review, or wants multi-step investigation around Burp findings, use cairn-collaborative-exploration as the coordination/state layer first and keep this skill focused on HTTP evidence collection and low-impact verification.
When the user mentions a mini program, WeChat mini program (微信小程序), mini program vulnerability (小程序漏洞), arbitrary login (任意登录), phone login, session_key, jscode2Session, openid, unionid, or asks to review Burp history for a wildcard/root domain such as *.anjia.com, do this before any other vulnerability conclusion:
Run scripts/miniapp_burp_preflight.py <root-domain> when a local Burp MCP proxy is available. Use its host list and sensitive matches as the initial evidence map, then continue with manual validation. If not running the script, perform the same steps manually with Burp MCP regex history searches.
Host values. Do not only analyze the most obvious API host such as api.<root>.session_key, sessionKey, sessionkey, session-key, session key, sess_key, sessKey, wxSessionKey, wx_session_key, wechatSessionKey, weChatSessionKey, weixin_session_key, thirdSessionKey, 3rd_session_key, decryptKey, decryptionKey, phoneDecryptKey, openDataKey), plus jscode2Session, jscode2session, code2Session, openid, unionid, getPhoneNumber, encryptedData, iv, phone, mobile, appSecret, api.weixin.qq.com.host.*session_key.jscode2Session4Xxx, getOpenId, getWxInfo, getSecretPhone, getPhone, phoneLogin, and bindPhone as login-chain candidates even if they are not under /api or /gateway.session_key/openid/unionid response is found, classify that before pursuing IDOR. IDOR can be a secondary finding, but it must not displace the login-key leak.Concrete failure case to avoid: for *.anjia.com, api.anjia.com/gateway/... had IDOR-like signals, but the primary issue was on ajia.anjia.com/Mini/FlagshipStore/jscode2Session4FlagShipStore, whose response returned session_key, openid, and unionid. Missing this means the preflight was not done.
Scope the target
mcp__burp__get_proxy_http_history or regex-filter it with mcp__burp__get_proxy_http_history_regex.mcp__burp__get_scanner_issues when the user asks for triage or prioritization.Preserve a baseline
mcp__burp__send_http1_request or mcp__burp__send_http2_request.mcp__burp__create_repeater_tab when manual follow-up would help the user.Mutate one variable at a time
mcp__burp__url_encode, url_decode, base64_encode, and base64_decode instead of hand-encoding.Verify by differential evidence
mcp__burp__generate_collaborator_payload, inject it in the suspected sink, then poll mcp__burp__get_collaborator_interactions.Report conservatively
confirmed, likely, inconclusive, or not reproduced.Use these as starting points only; adapt them to the article's indicators.
send_http1_request for raw HTTP/1.1 requests copied from proxy history. Preserve Host, cookies, content length semantics, and CRLF formatting.send_http2_request only when the original request is HTTP/2 or pseudo-headers matter.HTTP endpoint in Burp proxy history?
├── Target is mini program / WeChat session flow?
│ └── Run mini program preflight: enumerate hosts, search session_key variants
├── Vulnerability writeup provided?
│ └── Extract class, paths, indicators → craft targeted probes
├── General endpoint triage needed?
│ ├── Intercept baseline request
│ ├── Scan with safe markers and OOB payloads
│ ├── Verify via differential evidence (two independent indicators)
│ └── Report: confirmed / likely / inconclusive / not reproduced
└── No target identified?
└── Scope target from proxy history or scanner issues first....//....//etc/passwd, c:\windows\win.ini)When Burp MCP is connected and visible, use it only for scoped history inspection and low-impact replay. Otherwise use visible http-framework-test for baseline/probe differentials and nuclei only with a narrowly selected relevant template. Never invent Burp, repeater, browser-agent, or alternative-scanner calls.
Return findings in this shape:
Status: confirmed | likely | inconclusive | not reproduced
Target: https://host/path
Vulnerability class:
Mutated input:
Baseline:
Probe:
Evidence:
Impact:
Limitations:
Recommended fix:© langbyyi, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 2 other files (scripts, references) in skills/burp-mcp-vuln-check of langbyyi/CyberStrikeAI-SRC.
Open the folder on GitHubat commit 166ee1c
Burp MCP Vuln Check next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Burp MCP Vuln Check this skilllangbyyi/CyberStrikeAI-SRC | 129 | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | |
| Burp Scansix2dez/burp-ai-agent | 1.5k | — | ~6.4k | Automated safety check: Warn | MIT | |
| Hunt BurpEncod3d-Sec/TORCH | 329 | — | ~3.1k | Automated safety check: Pass | MIT | |
| Linkdigest Social Link Readersickn33/agentic-awesome-skills | 47k | — | ~3.4k | Automated safety check: Pass | MIT | |
| MCP Server Toolssamugit83/redamon | 3k | — | ~1.8k | Automated safety check: Pass | MIT | |
| MCP Server Security Auditawarexone/Agentic-Bug-Hunter | 5.3k | — | ~1.9k | Automated safety check: Warn | MIT |
six2dez/burp-ai-agent
Burp Suite scanning via MCP tools — passive traffic analysis, active payload testing, OOB verification, and vulnerability reporting using Burp's proxy, HTTP sender, Collaborator, and scanner APIs.
Encod3d-Sec/TORCH
Drive Burp Suite over its MCP server as an AI triage + attack layer - review proxy history for signals, replay via Repeater/send, OOB-gate blind bugs with Collaborator, fuzz via Intruder (RoE-safe)…
sickn33/agentic-awesome-skills
Read one public Xiaohongshu, Douyin, TikTok, YouTube, X or WeChat article link into text an agent can use (transcript, image text, key points) via the LinkDigest API or MCP server.
samugit83/redamon
Adding, removing or changing a tool on RedAmon's INBOUND MCP server, where external agents connect in with a personal access token.
awarexone/Agentic-Bug-Hunter
Audits MCP servers and their client configs for tool poisoning, prompt injection, over-privileged tools, injection bugs, secret leaks and missing approval gates.
TencentCloudBase/CloudBase-AI-Toolkit
Fast path for a minimal CloudBase Web + database demo (最小前后端 / 最小可用 fullstack / Lovable-like BaaS).
langbyyi/CyberStrikeAI-SRC
Authentication bypass testing playbook. An agent skill from langbyyi/CyberStrikeAI-SRC.
langbyyi/CyberStrikeAI-SRC
HTTP Parameter Pollution (HPP): duplicate query/body keys parsed differently by servers, proxies, WAFs, and app frameworks.
langbyyi/CyberStrikeAI-SRC
Source control and artifact exposure (.git, .svn, .hg, backups, .env).
langbyyi/CyberStrikeAI-SRC
PHP type juggling and weak comparison (==) bypass. An agent skill from langbyyi/CyberStrikeAI-SRC.
langbyyi/CyberStrikeAI-SRC
WebSocket handshake, CSWSH, tooling (wsrepl, ws-harness, Burp), and common flaws.
langbyyi/CyberStrikeAI-SRC
XSLT injection testing: processor fingerprinting, XXE and document() SSRF, EXSLT write primitives, PHP/Java/.NET extension RCE surfaces.
Works with
Categories
Automate low-impact web vulnerability verification through Burp MCP. Burp MCP Vuln Check is an agent skill from langbyyi/CyberStrikeAI-SRC. Automate low-impact web vulnerability verification through Burp MCP.
Burp MCP Vuln Check fits situations like: Codex is asked to check; write evidence for vulnerabilities using Burp Suite proxy history; collaborator/OOB payloads; parameter mutation.
Run `npx skills add langbyyi/CyberStrikeAI-SRC --skill burp-mcp-vuln-check -a claude-code`. Or copy the skill folder (skills/burp-mcp-vuln-check in langbyyi/CyberStrikeAI-SRC) into .claude/skills/burp-mcp-vuln-check in your project. Claude Code loads it when a task matches its description.
Run `npx skills add langbyyi/CyberStrikeAI-SRC --skill burp-mcp-vuln-check -a codex`. Or copy the skill folder (skills/burp-mcp-vuln-check in langbyyi/CyberStrikeAI-SRC) into .agents/skills/burp-mcp-vuln-check in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add langbyyi/CyberStrikeAI-SRC --skill burp-mcp-vuln-check -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/burp-mcp-vuln-check, .gemini/skills/burp-mcp-vuln-check, .github/skills/burp-mcp-vuln-check and .opencode/skills/burp-mcp-vuln-check in your project.
Going by SKILL.md and its folder, Burp MCP Vuln Check needs Python for the scripts in its folder. Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Burp MCP Vuln Check is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.1k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 437 tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Burp MCP Vuln Check: Burp Scan (six2dez/burp-ai-agent, 1.5k stars), Hunt Burp (Encod3d-Sec/TORCH, 329 stars), Linkdigest Social Link Reader (sickn33/agentic-awesome-skills, 47k stars) and MCP Server Tools (samugit83/redamon, 3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
langbyyi (a GitHub user) maintains it in langbyyi/CyberStrikeAI-SRC, which has 129 GitHub stars. The repository holds 13 skills in this directory. The repository was last updated on October 7, 2026.
Source: langbyyi/CyberStrikeAI-SRC on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.