Agent skill

Burp MCP Vuln Check

by langbyyi in langbyyi/CyberStrikeAI-SRC

Automate low-impact web vulnerability verification through Burp MCP.

Apache-2.0Auto-check passedSecurity

Install Burp MCP Vuln Check

skills CLI
$ npx skills add langbyyi/CyberStrikeAI-SRC --skill burp-mcp-vuln-check -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install langbyyi/CyberStrikeAI-SRC burp-mcp-vuln-check --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/langbyyi/CyberStrikeAI-SRC.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/burp-mcp-vuln-check .claude/skills/burp-mcp-vuln-check && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
burp-mcp-vuln-check
GitHub stars
129
Token cost
~3.1k tokens
SKILL.md length
1,282 words
Files
3 (incl. scripts, references)
Skills in repo
13
Repo updated
First seen
Licence
Apache-2.0

At a glance

Automate low-impact web vulnerability verification through Burp MCP.

  • Works in 6 steps: Query the root/wildcard domain broadly… → For every observed Host, search both… → Use separate regex searches for Host and… → …
  • Codex is asked to check
  • SKILL.md covers QUICK START, Operating Rules, Burp MCP Workflow and Common Check Patterns, plus 6 more sections
  • Runs Python scripts from its folder

What it does

Burp MCP Vuln Check is an agent skill from langbyyi/CyberStrikeAI-SRC. Automate low-impact web vulnerability verification through Burp MCP. Use when Codex is asked to check, reproduce, triage, or write evidence for vulnerabilities using Burp Suite proxy history, Repeater, Collaborator/OOB payloads, HTTP replay, parameter mutation, response diffing, or scanner issues. Also use for mini program/微信小程序 Burp history, wildcard domains like .example.com, root-domain traffic reviews, arbitrary login/任意登录, sessionkey/sessionKey/sessionkey/session-key/session…

Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including scripts and reference files (for example `references/article-rule-template.md` and `scripts/miniapp_burp_preflight.py`).

It sits in Security, covering Messaging and chat bots, MCP servers and Penetration testing. It works with Model Context Protocol, WeChat and Burp Suite. The licence is Apache-2.0.

When your agent uses it

  • Codex is asked to check
  • Write evidence for vulnerabilities using Burp Suite proxy history
  • Collaborator/OOB payloads
  • Parameter mutation

Example prompts

  • “/burp-mcp-vuln-check”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Query the root/wildcard domain broadly and enumerate all observed Host values. Do not only analyze the most obvious API host such as api..
  2. For every observed Host, search both request and response content for
  3. Use separate regex searches for Host and sensitive fields if the Burp history text may not match across request/response lines. Do not…
  4. Treat endpoints named like jscode2Session4Xxx, getOpenId, getWxInfo, getSecretPhone, getPhone, phoneLogin, and bindPhone as login-chain…
  5. Do not say "no session_key leak found" until the host enumeration and session-key variant cross-search have been completed.
  6. If a WeChat session_key/openid/unionid response is found, classify that before pursuing IDOR. IDOR can be a secondary finding, but it must…

What it can do on your machine

Read from SKILL.md and the folder at commit 166ee1c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Burp MCP Vuln Check loads about 3.1k tokens when it runs, and up to ~3.6k if it reads all its reference files. Until then it costs about 214 tokens; SKILL.md has 1,282 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~214
When it runs · the whole SKILL.md, loaded when a task matches
~3.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from langbyyi/CyberStrikeAI-SRC at commit 166ee1c, republished under its Apache-2.0 licence (© langbyyi). 1,282 words, ~3,122 tokens.

Download SKILL.mdSave it as .claude/skills/burp-mcp-vuln-check/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
burp-mcp-vuln-check
description
Automate low-impact web vulnerability verification through Burp MCP. Use when Codex is asked to check, reproduce, triage, or write evidence for vulnerabilities using Burp Suite proxy history, Repeater, Collaborator/OOB payloads, HTTP replay, parameter mutation, response diffing, or scanner issues. Also use for mini program/微信小程序 Burp history, wildcard domains like *.example.com, root-domain traffic reviews, arbitrary login/任意登录, session_key/sessionKey/sessionkey/session-key/session key/sess_key/sessKey/wxSessionKey/wx_session_key/wechatSessionKey/thirdSessionKey/decryptKey/openDataKey, jscode2Session/jscode2session/code2Session, openid/unionid, getPhoneNumber, encryptedData/iv, appSecret, or phone-login checks; in those cases enumerate all Hosts and search response bodies for WeChat session leaks before reporting no issue.

Burp MCP Vulnerability Check

AI LOAD INSTRUCTION: Low-impact vulnerability verification through Burp MCP proxy history and HTTP replay. Covers baseline preservation, single-variable mutation, differential evidence (two independent indicators), Collaborator/OOB blind detection, mini program/WeChat session_key preflight, and article-derived targeted checks. Base models often jump to mass scanning — this skill enforces methodical one-variable-at-a-time verification with conservative reporting.

QUICK START

First-pass probes
SignalProbeWhy
Target in proxy history?get_proxy_http_history_regex to scope host/endpointsEstablish what is in scope
Baseline captured?Replay one unmodified request with send_http1_requestRecord normal response fingerprint
One variable mutated?Change only the suspected param, compare vs baselineSingle-variable causality
Responses differ?Confirm with two independent indicatorsReduce false positives
No visible difference?Inject Collaborator payload for blind detectionOOB callback confirms blind vuln
bash
# Quick test — baseline then mutate one parameter
# 1. Replay original request → record status/length/body markers
# 2. Change one parameter → compare response
# 3. If blind: inject Collaborator hostname, poll for interactions

Operating Rules

Treat every check as authorized testing against the user's target. Keep probes low impact: prefer safe markers, benign arithmetic, DNS-only OOB payloads, timeout caps, and read-only requests. Do not mass exploit, persist shells, dump secrets, or run destructive payloads unless the user explicitly authorizes that exact action.

If the task is based on a writeup, first extract the vulnerability class, affected paths, required headers/cookies, trigger parameters, positive/negative indicators, and any OOB behavior. If article-specific details are missing, use the generic workflow below and ask for the missing PoC only when a targeted check cannot be inferred.

For article-derived checks, read references/article-rule-template.md and fill the relevant fields mentally or in notes before probing.

If the user asks broad website/SRC triage such as "help me check xx website vulnerabilities" (帮我排查 xx 网站漏洞), "check if a domain has vulnerabilities" (看看某域名有没有漏洞), wildcard/root-domain review, or wants multi-step investigation around Burp findings, use cairn-collaborative-exploration as the coordination/state layer first and keep this skill focused on HTTP evidence collection and low-impact verification.

Burp MCP Workflow

Mandatory Mini Program Preflight

When the user mentions a mini program, WeChat mini program (微信小程序), mini program vulnerability (小程序漏洞), arbitrary login (任意登录), phone login, session_key, jscode2Session, openid, unionid, or asks to review Burp history for a wildcard/root domain such as *.anjia.com, do this before any other vulnerability conclusion:

Run scripts/miniapp_burp_preflight.py <root-domain> when a local Burp MCP proxy is available. Use its host list and sensitive matches as the initial evidence map, then continue with manual validation. If not running the script, perform the same steps manually with Burp MCP regex history searches.

  1. Query the root/wildcard domain broadly and enumerate all observed Host values. Do not only analyze the most obvious API host such as api.<root>.
  2. For every observed Host, search both request and response content for: session-key variants (session_key, sessionKey, sessionkey, session-key, session key, sess_key, sessKey, wxSessionKey, wx_session_key, wechatSessionKey, weChatSessionKey, weixin_session_key, thirdSessionKey, 3rd_session_key, decryptKey, decryptionKey, phoneDecryptKey, openDataKey), plus jscode2Session, jscode2session, code2Session, openid, unionid, getPhoneNumber, encryptedData, iv, phone, mobile, appSecret, api.weixin.qq.com.
  3. Use separate regex searches for Host and sensitive fields if the Burp history text may not match across request/response lines. Do not rely on host.*session_key.
  4. Treat endpoints named like jscode2Session4Xxx, getOpenId, getWxInfo, getSecretPhone, getPhone, phoneLogin, and bindPhone as login-chain candidates even if they are not under /api or /gateway.
  5. Do not say "no session_key leak found" until the host enumeration and session-key variant cross-search have been completed.
  6. If a WeChat session_key/openid/unionid response is found, classify that before pursuing IDOR. IDOR can be a secondary finding, but it must not displace the login-key leak.

Concrete failure case to avoid: for *.anjia.com, api.anjia.com/gateway/... had IDOR-like signals, but the primary issue was on ajia.anjia.com/Mini/FlagshipStore/jscode2Session4FlagShipStore, whose response returned session_key, openid, and unionid. Missing this means the preflight was not done.

  1. Scope the target

    • Get recent proxy history with mcp__burp__get_proxy_http_history or regex-filter it with mcp__burp__get_proxy_http_history_regex.
    • Identify host, scheme, candidate endpoints, auth state, content type, CSRF tokens, and reflection points.
    • Check scanner context with mcp__burp__get_scanner_issues when the user asks for triage or prioritization.
  2. Preserve a baseline

    • Replay one unmodified candidate request with mcp__burp__send_http1_request or mcp__burp__send_http2_request.
    • Record status code, response length, key headers, stable body markers, timing, redirects, and errors.
    • Create a Repeater tab with mcp__burp__create_repeater_tab when manual follow-up would help the user.
  3. Mutate one variable at a time

    • Change only the suspected path segment, query parameter, body field, header, cookie, or JSON key.
    • Keep a negative control that should not trigger the bug.
    • For encoded vectors, use mcp__burp__url_encode, url_decode, base64_encode, and base64_decode instead of hand-encoding.
  4. Verify by differential evidence

    • Compare mutated vs baseline response code, length, body markers, error messages, redirects, and timing.
    • Prefer two independent indicators before calling a finding confirmed.
    • For blind vulnerabilities, generate a Burp Collaborator payload with mcp__burp__generate_collaborator_payload, inject it in the suspected sink, then poll mcp__burp__get_collaborator_interactions.
  5. Report conservatively

    • Classify as confirmed, likely, inconclusive, or not reproduced.
    • Include exact request target, mutation, evidence, confidence, and why the probe is low impact.
    • Mention missing prerequisites, blocked auth, anti-CSRF, WAF interference, or environment limits.
Show full SKILL.md (487 more words)Show less

Common Check Patterns

Use these as starting points only; adapt them to the article's indicators.

  • Path traversal / arbitrary file read: mutate filename/path parameters with safe reads such as known public files or application config names that should not expose secrets. Confirm with body markers and avoid dumping sensitive contents.
  • SSRF / blind callback: place a Collaborator hostname in URL-like parameters, headers, import/fetch fields, webhook settings, XML/JSON URLs, or image/document fetchers. Confirm via DNS/HTTP interaction.
  • SQL injection: use boolean/time-safe probes with short delays and negative controls. Avoid data extraction. Confirm through response differences or bounded timing deltas across repeated requests.
  • Command/template/code injection: use harmless arithmetic or DNS-only OOB markers where possible. Avoid shell-spawning or file writes.
  • Access control / IDOR: replay the same endpoint with changed object identifiers and current auth only. Confirm by stable object ownership markers; do not enumerate.
  • Deserialization / framework gadget issues: prefer version/banner evidence and harmless callback probes. Do not send weaponized gadget chains unless explicitly authorized.
  • File upload / parser bugs: upload inert marker files or polyglot probes only when the workflow already supports upload. Confirm storage path, transformation behavior, or callback without executing payloads.

Burp MCP Tool Notes

  • Use send_http1_request for raw HTTP/1.1 requests copied from proxy history. Preserve Host, cookies, content length semantics, and CRLF formatting.
  • Use send_http2_request only when the original request is HTTP/2 or pseudo-headers matter.
  • Use regex history search for article-specific paths, parameter names, file extensions, framework banners, or error keywords.
  • Use Collaborator sparingly and poll more than once when the target may process jobs asynchronously.
  • Use Intruder only for a small, user-approved candidate set; keep payload count minimal.

DECISION TREE

HTTP endpoint in Burp proxy history?
├── Target is mini program / WeChat session flow?
│   └── Run mini program preflight: enumerate hosts, search session_key variants
├── Vulnerability writeup provided?
│   └── Extract class, paths, indicators → craft targeted probes
├── General endpoint triage needed?
│   ├── Intercept baseline request
│   ├── Scan with safe markers and OOB payloads
│   ├── Verify via differential evidence (two independent indicators)
│   └── Report: confirmed / likely / inconclusive / not reproduced
└── No target identified?
    └── Scope target from proxy history or scanner issues first
  • recon-and-methodology — general recon and asset discovery before Burp-based verification
  • api-security — API testing flow for endpoints found in Burp proxy history
  • sqli — SQL injection evidence collection and verification via Burp
  • xss — XSS evidence collection and response diffing via Burp

TESTING CHECKLIST

  • Scope the target: identify host, scheme, candidate endpoints, auth state, and content type from proxy history
  • Preserve a baseline: replay one unmodified request and record status code, response length, headers, body markers, timing
  • Test path traversal: mutate filename/path parameters with safe reads (....//....//etc/passwd, c:\windows\win.ini)
  • Test SSRF: inject Collaborator/callback hostname in URL-like parameters, headers, webhook fields, XML/JSON URLs
  • Test SQL injection: use boolean/time-safe probes with negative controls; avoid data extraction
  • Test command/template/code injection: use harmless arithmetic or DNS-only OOB markers
  • Test access control / IDOR: replay endpoint with changed object identifiers using current auth only
  • Test deserialization: prefer version/banner evidence and harmless callback probes
  • Test file upload: upload inert marker files only when the workflow supports uploads
  • Compare mutated vs baseline with two independent indicators before confirming a finding

TARGET TOOL ADAPTATION

When Burp MCP is connected and visible, use it only for scoped history inspection and low-impact replay. Otherwise use visible http-framework-test for baseline/probe differentials and nuclei only with a narrowly selected relevant template. Never invent Burp, repeater, browser-agent, or alternative-scanner calls.

Evidence Format

Return findings in this shape:

text
Status: confirmed | likely | inconclusive | not reproduced
Target: https://host/path
Vulnerability class:
Mutated input:
Baseline:
Probe:
Evidence:
Impact:
Limitations:
Recommended fix:

© langbyyi, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (scripts, references) in skills/burp-mcp-vuln-check of langbyyi/CyberStrikeAI-SRC.

  • SKILL.md
  • references/article-rule-template.md
  • scripts/miniapp_burp_preflight.py

Open the folder on GitHubat commit 166ee1c

Compare with similar skills

Burp MCP Vuln Check next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Burp MCP Vuln Check compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Burp MCP Vuln Check this skilllangbyyi/CyberStrikeAI-SRC129—~3.1kAutomated safety check: PassApache-2.0
Burp Scansix2dez/burp-ai-agent1.5k—~6.4kAutomated safety check: WarnMIT
Hunt BurpEncod3d-Sec/TORCH329—~3.1kAutomated safety check: PassMIT
Linkdigest Social Link Readersickn33/agentic-awesome-skills47k—~3.4kAutomated safety check: PassMIT
MCP Server Toolssamugit83/redamon3k—~1.8kAutomated safety check: PassMIT
MCP Server Security Auditawarexone/Agentic-Bug-Hunter5.3k—~1.9kAutomated safety check: WarnMIT

Similar skills

  • Burp Scan

    six2dez/burp-ai-agent

    Burp Suite scanning via MCP tools — passive traffic analysis, active payload testing, OOB verification, and vulnerability reporting using Burp's proxy, HTTP sender, Collaborator, and scanner APIs.

    1.5k GitHub stars~6.4k tokensUpdated yesterday
    SecurityAuto-check: warnings
  • Hunt Burp

    Encod3d-Sec/TORCH

    Drive Burp Suite over its MCP server as an AI triage + attack layer - review proxy history for signals, replay via Repeater/send, OOB-gate blind bugs with Collaborator, fuzz via Intruder (RoE-safe)…

    329 GitHub stars~3.1k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Linkdigest Social Link Reader

    sickn33/agentic-awesome-skills

    Read one public Xiaohongshu, Douyin, TikTok, YouTube, X or WeChat article link into text an agent can use (transcript, image text, key points) via the LinkDigest API or MCP server.

    47k GitHub stars~3.4k tokensUpdated 2 days ago
    Agent WorkflowsAuto-check passed
  • MCP Server Tools

    samugit83/redamon

    Adding, removing or changing a tool on RedAmon's INBOUND MCP server, where external agents connect in with a personal access token.

    3k GitHub stars~1.8k tokensUpdated 2 days ago
    SecurityAuto-check passed
  • MCP Server Security Audit

    awarexone/Agentic-Bug-Hunter

    Audits MCP servers and their client configs for tool poisoning, prompt injection, over-privileged tools, injection bugs, secret leaks and missing approval gates.

    5.3k GitHub stars~1.9k tokensUpdated yesterday
    SecurityAuto-check: warnings
  • Minimal Web Baas Demo

    TencentCloudBase/CloudBase-AI-Toolkit

    Fast path for a minimal CloudBase Web + database demo (最小前后端 / 最小可用 fullstack / Lovable-like BaaS).

    1.1k GitHub starsUsed in 1 repo~2.3k tokens
    Productivity & AutomationAuto-check passed

More from langbyyi/CyberStrikeAI-SRC

All 13 skills in this repo
  • Authbypass Authentication Flaws

    langbyyi/CyberStrikeAI-SRC

    Authentication bypass testing playbook. An agent skill from langbyyi/CyberStrikeAI-SRC.

    129 GitHub starsUsed in 1 repo~3.9k tokens
    Auto-check passed
  • HTTP Parameter Pollution

    langbyyi/CyberStrikeAI-SRC

    HTTP Parameter Pollution (HPP): duplicate query/body keys parsed differently by servers, proxies, WAFs, and app frameworks.

    129 GitHub starsUsed in 1 repo~2.2k tokens
    Auto-check passed
  • Insecure Source Code Management

    langbyyi/CyberStrikeAI-SRC

    Source control and artifact exposure (.git, .svn, .hg, backups, .env).

    129 GitHub starsUsed in 1 repo~1.3k tokens
    Auto-check: notes
  • Type Juggling

    langbyyi/CyberStrikeAI-SRC

    PHP type juggling and weak comparison (==) bypass. An agent skill from langbyyi/CyberStrikeAI-SRC.

    129 GitHub starsUsed in 1 repo~2.9k tokens
    Auto-check passed
  • Websocket Security

    langbyyi/CyberStrikeAI-SRC

    WebSocket handshake, CSWSH, tooling (wsrepl, ws-harness, Burp), and common flaws.

    129 GitHub starsUsed in 1 repo~1.8k tokens
    Auto-check passed
  • Xslt Injection

    langbyyi/CyberStrikeAI-SRC

    XSLT injection testing: processor fingerprinting, XXE and document() SSRF, EXSLT write primitives, PHP/Java/.NET extension RCE surfaces.

    129 GitHub starsUsed in 1 repo~3k tokens
    Auto-check passed

Questions about Burp MCP Vuln Check

What does Burp MCP Vuln Check do?

Automate low-impact web vulnerability verification through Burp MCP. Burp MCP Vuln Check is an agent skill from langbyyi/CyberStrikeAI-SRC. Automate low-impact web vulnerability verification through Burp MCP.

When should I use Burp MCP Vuln Check?

Burp MCP Vuln Check fits situations like: Codex is asked to check; write evidence for vulnerabilities using Burp Suite proxy history; collaborator/OOB payloads; parameter mutation.

How do I install Burp MCP Vuln Check in Claude Code?

Run `npx skills add langbyyi/CyberStrikeAI-SRC --skill burp-mcp-vuln-check -a claude-code`. Or copy the skill folder (skills/burp-mcp-vuln-check in langbyyi/CyberStrikeAI-SRC) into .claude/skills/burp-mcp-vuln-check in your project. Claude Code loads it when a task matches its description.

How do I install Burp MCP Vuln Check in Codex?

Run `npx skills add langbyyi/CyberStrikeAI-SRC --skill burp-mcp-vuln-check -a codex`. Or copy the skill folder (skills/burp-mcp-vuln-check in langbyyi/CyberStrikeAI-SRC) into .agents/skills/burp-mcp-vuln-check in your project. Codex loads it when a task matches its description.

Can I use Burp MCP Vuln Check in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add langbyyi/CyberStrikeAI-SRC --skill burp-mcp-vuln-check -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/burp-mcp-vuln-check, .gemini/skills/burp-mcp-vuln-check, .github/skills/burp-mcp-vuln-check and .opencode/skills/burp-mcp-vuln-check in your project.

What does Burp MCP Vuln Check need to run?

Going by SKILL.md and its folder, Burp MCP Vuln Check needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Burp MCP Vuln Check access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Burp MCP Vuln Check safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Burp MCP Vuln Check use?

Burp MCP Vuln Check is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Burp MCP Vuln Check use?

About 3.1k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 437 tokens, read only when the agent opens those files.

What are the alternatives to Burp MCP Vuln Check?

Skills that share tags, products or a category with Burp MCP Vuln Check: Burp Scan (six2dez/burp-ai-agent, 1.5k stars), Hunt Burp (Encod3d-Sec/TORCH, 329 stars), Linkdigest Social Link Reader (sickn33/agentic-awesome-skills, 47k stars) and MCP Server Tools (samugit83/redamon, 3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Burp MCP Vuln Check?

langbyyi (a GitHub user) maintains it in langbyyi/CyberStrikeAI-SRC, which has 129 GitHub stars. The repository holds 13 skills in this directory. The repository was last updated on October 7, 2026.

Source: langbyyi/CyberStrikeAI-SRC on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.