Burp Scan
six2dez/burp-ai-agent
Burp Suite scanning via MCP tools — passive traffic analysis, active payload testing, OOB verification, and vulnerability reporting using Burp's proxy, HTTP sender, Collaborator, and scanner APIs.
A skill your agent uses to drive Compose HotSwan from an AI agent (Claude Code, Cursor, any MCP client) so the agent can edit a Kotlin file, trigger a hot reload, capture a device screenshot…
$ npx skills add rosuH/EasyWatermark --skill iterating-with-ai-and-mcp -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install rosuH/EasyWatermark iterating-with-ai-and-mcp --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/rosuH/EasyWatermark.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/iterating-with-ai-and-mcp .claude/skills/iterating-with-ai-and-mcp && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "iterating-with-ai-and-mcp" agent skill from https://github.com/rosuH/EasyWatermark/tree/master/.agents/skills/iterating-with-ai-and-mcp into .claude/skills/iterating-with-ai-and-mcp/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "iterating-with-ai-and-mcp", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/rosuH/EasyWatermark/tree/master/.agents/skills/iterating-with-ai-and-mcpType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add rosuH/EasyWatermark --skill iterating-with-ai-and-mcp -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install rosuH/EasyWatermark iterating-with-ai-and-mcp --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/rosuH/EasyWatermark.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/iterating-with-ai-and-mcp .agents/skills/iterating-with-ai-and-mcp && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "iterating-with-ai-and-mcp" agent skill from https://github.com/rosuH/EasyWatermark/tree/master/.agents/skills/iterating-with-ai-and-mcp into .agents/skills/iterating-with-ai-and-mcp/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "iterating-with-ai-and-mcp", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add rosuH/EasyWatermark --skill iterating-with-ai-and-mcp -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install rosuH/EasyWatermark iterating-with-ai-and-mcp --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/rosuH/EasyWatermark.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/iterating-with-ai-and-mcp .cursor/skills/iterating-with-ai-and-mcp && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "iterating-with-ai-and-mcp" agent skill from https://github.com/rosuH/EasyWatermark/tree/master/.agents/skills/iterating-with-ai-and-mcp into .cursor/skills/iterating-with-ai-and-mcp/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "iterating-with-ai-and-mcp", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/rosuH/EasyWatermark.git --path .agents/skills/iterating-with-ai-and-mcp--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add rosuH/EasyWatermark --skill iterating-with-ai-and-mcp -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install rosuH/EasyWatermark iterating-with-ai-and-mcp --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/rosuH/EasyWatermark.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/iterating-with-ai-and-mcp .gemini/skills/iterating-with-ai-and-mcp && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "iterating-with-ai-and-mcp" agent skill from https://github.com/rosuH/EasyWatermark/tree/master/.agents/skills/iterating-with-ai-and-mcp into .gemini/skills/iterating-with-ai-and-mcp/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "iterating-with-ai-and-mcp", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install rosuH/EasyWatermark iterating-with-ai-and-mcpInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add rosuH/EasyWatermark --skill iterating-with-ai-and-mcp -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/rosuH/EasyWatermark.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/iterating-with-ai-and-mcp .github/skills/iterating-with-ai-and-mcp && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "iterating-with-ai-and-mcp" agent skill from https://github.com/rosuH/EasyWatermark/tree/master/.agents/skills/iterating-with-ai-and-mcp into .github/skills/iterating-with-ai-and-mcp/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "iterating-with-ai-and-mcp", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add rosuH/EasyWatermark --skill iterating-with-ai-and-mcp -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install rosuH/EasyWatermark iterating-with-ai-and-mcp --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/rosuH/EasyWatermark.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/iterating-with-ai-and-mcp .opencode/skills/iterating-with-ai-and-mcp && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "iterating-with-ai-and-mcp" agent skill from https://github.com/rosuH/EasyWatermark/tree/master/.agents/skills/iterating-with-ai-and-mcp into .opencode/skills/iterating-with-ai-and-mcp/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "iterating-with-ai-and-mcp", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
iterating-with-ai-and-mcpA skill your agent uses to drive Compose HotSwan from an AI agent (Claude Code, Cursor, any MCP client) so the agent can edit a Kotlin file, trigger a hot reload, capture a device screenshot…
Iterating With AI And MCP is an agent skill from rosuH/EasyWatermark. Use this skill to drive Compose HotSwan from an AI agent (Claude Code, Cursor, any MCP client) so the agent can edit a Kotlin file, trigger a hot reload, capture a device screenshot, evaluate the result against a design intent, and iterate without a human in the loop. Covers the seven HotSwan MCP tools (hotswangetstatus, hotswanreload, hotswantakescreenshot, hotswanstartsnapshot, hotswanstopsnapshot, hotswanselectvariant, hotswanbuildandinstall), the canonical edit-reload-screenshot loop, snapshot-based rollback…
Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Agent Workflows, covering MCP servers. It works with Model Context Protocol and Kotlin. The repository describes itself as: 🔒 🖼 Securely, easily add a watermark to your sensitive photos. 安全、简单地为你的敏感照片添加水印,防止被人泄露、利用. The licence is Apache-2.0.
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 61223db. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
github.complugins.jetbrains.commodelcontextprotocol.ioFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Iterating With AI And MCP loads about 2.7k tokens when it runs. Until then it costs about 221 tokens; SKILL.md has 1,122 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from rosuH/EasyWatermark at commit 61223db, republished under its Apache-2.0 licence (© rosuH). 1,122 words, ~2,725 tokens.
.claude/skills/iterating-with-ai-and-mcp/SKILL.md (or your agent's skills folder).Compose HotSwan ships an embedded HTTP MCP server inside the IntelliJ plugin. Any MCP-compatible AI client (Claude Code, Cursor, any tool that speaks Model Context Protocol) can call its tools to drive the iteration loop. The agent edits a Kotlin file, calls hotswan_reload, captures a screenshot of the running device, evaluates the result against the design intent, and decides the next change. Cycle time is comparable to the human loop, a few seconds per iteration, so the agent can converge on a UI tweak without a human steering each step.
This skill teaches the canonical agent loop, the seven MCP tools (verbatim names), and the safety habits (status check first, snapshot wrapping for rollback, fallback to full install for schema changes) that keep the loop reliable.
../../measurement/generating-baseline-profiles/SKILL.md.../understanding-hot-reload-limits/SKILL.md first to classify the edit before reaching for the MCP loop.../preserving-state-across-reloads/SKILL.md before adding an autonomous loop on top.../setting-up-compose-hotswan/SKILL.md.WATCHING.The HotSwan MCP server exposes exactly these seven tools. The agent MUST NOT invent additional tool names.
hotswan_get_status(): returns device, app, and watcher state. Call once at the start of every loop to confirm the agent has a connected target and that the watcher is WATCHING.hotswan_reload(filePaths): explicit reload trigger for the listed file paths. Returns the tier (1 / 2 / 3) that ran. The agent reads the tier to decide whether the previous edit kept the loop fast.hotswan_take_screenshot(): capture the current device screen. Returns image bytes or a path the agent can read back and inspect.hotswan_start_snapshot(): begin a snapshot session. After this call, HotSwan auto-captures a screenshot and source state after every reload, so the agent can roll back to any intermediate variant.hotswan_stop_snapshot(): end the current snapshot session and finalise the history.hotswan_select_variant(): pick a preferred snapshot from the recorded history. Used to roll the source code back to the chosen variant when the agent decides an earlier iteration was the best one.hotswan_build_and_install(): fall back to a full install. Used when the agent detects a schema change (new parameter, constructor change, new resource ID) that the hot reload pipeline cannot handle. Treat this as a fallback, not a default.The canonical agent loop:
Call hotswan_get_status(). If watcher is not WATCHING, surface the issue back to the human and stop. The reload tool will silently no-op if the watcher is not running and the agent will burn cycles wondering why nothing changed on screen.
Call hotswan_start_snapshot() so the loop has a visual record. Each reload inside the session auto-captures, which lets the agent (or the human reviewing afterwards) compare iterations and roll back to any variant.
Edit the Kotlin file using whatever file-edit tool the agent has. Keep the change inside one composable scope when possible so the reload stays in tier 1 (cross-link ../preserving-state-across-reloads/SKILL.md).
Call hotswan_reload(["app/src/main/kotlin/com/example/Foo.kt"]). Read the returned tier. Tier 1 means the loop stayed fast; tier 2 or tier 3 means state was likely lost and the agent should expect to re-establish navigation or transient UI state before the next screenshot.
Call hotswan_take_screenshot(). Compare the returned image to the design intent. If acceptable, exit the loop. If not, return to step 3 with a refined edit.
If the planned next edit changes a function signature, constructor, interface, or adds a new resource ID, call hotswan_build_and_install() to do a full install before continuing. Do not hammer hotswan_reload on a schema-violating edit; the reload tool will report failure and the loop will stall.
When the iteration is acceptable, call hotswan_stop_snapshot(). Optionally call hotswan_select_variant() to roll the source back to a preferred intermediate variant if the final state was not the best one.
// WRONG
1. Edit file
2. Call hotswan_reload
3. Wonder why nothing happened
// WRONG because: HotSwan needs the app running and the watcher in WATCHING state. If neither is true the reload silently no-ops. Always call hotswan_get_status first.// RIGHT
1. status = hotswan_get_status()
2. require(status.watcher == "WATCHING")
3. edit, reload, screenshot, iterate// WRONG (for visual iteration)
edit -> reload -> screenshot -> discard -> repeat
// WRONG because: the agent loses the ability to roll back to a previous variant. Always wrap visual iteration loops in hotswan_start_snapshot / hotswan_stop_snapshot.// RIGHT
hotswan_start_snapshot()
repeat { edit; hotswan_reload([target]); hotswan_take_screenshot() }
hotswan_stop_snapshot()// WRONG
Edit a composable to add a new parameter, then call hotswan_reload.
// WRONG because: parameter additions are a class-schema change. ART rejects the swap and hotswan_reload reports failure. The agent must detect the schema change first and call hotswan_build_and_install instead.// RIGHT
if (editChangesSchema(plannedEdit)) {
applyEdit(target)
hotswan_build_and_install()
} else {
applyEdit(target)
hotswan_reload([target])
}Cross-link ../understanding-hot-reload-limits/SKILL.md for the full list of schema-violating edits.
// RIGHT
status = hotswan_get_status()
require(status.watcher == "WATCHING")
hotswan_start_snapshot()
repeat {
edit_file(target)
result = hotswan_reload([target])
screenshot = hotswan_take_screenshot()
if (accepts(screenshot, intent)) break
}
hotswan_stop_snapshot()The loop has exactly four moving parts: edit, reload, screenshot, evaluate. Everything else is bookkeeping (status check, snapshot wrapping, optional rollback).
hotswan_get_status() at the start of every loop and confirm the watcher state before issuing edits.hotswan_start_snapshot() and hotswan_stop_snapshot() so the agent can revert.hotswan_get_status, hotswan_reload, hotswan_take_screenshot, hotswan_start_snapshot, hotswan_stop_snapshot, hotswan_select_variant, hotswan_build_and_install.hotswan_build_and_install() inside a tight inner loop. It is a fallback for schema changes, not a default; using it as the default destroys the speed advantage of HotSwan.../understanding-hot-reload-limits/SKILL.md so the agent classifies the planned edit before reaching for hotswan_reload.../preserving-state-across-reloads/SKILL.md so the agent recognises when a reload escalated to tier 2 or tier 3 and loses transient UI state.hotswan_get_status() returns WATCHING before the loop runshotswan_reload call reports the tier (1, 2, or 3)hotswan_take_screenshot() returns image bytes the agent can inspecthotswan_stop_snapshot() finalises the sessionhotswan_build_and_install() instead of hotswan_reload/docs/mcp-server)/docs/agent-skill/docs/snapshot© rosuH, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .agents/skills/iterating-with-ai-and-mcp of rosuH/EasyWatermark.
Open the folder on GitHubat commit 61223db
We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in rosuH/EasyWatermark, which our catalogue first saw on October 7, 2026.
Iterating With AI And MCP next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Iterating With AI And MCP this skillrosuH/EasyWatermark | 1.9k | 1 repos | ~2.7k | Automated safety check: Pass | Apache-2.0 | |
| Burp Scansix2dez/burp-ai-agent | 1.5k | — | ~6.4k | Automated safety check: Warn | MIT | |
| Healthmd CLI QACodyBontecou/health-md | 230 | — | ~4k | Automated safety check: Pass | AGPL-3.0 | |
| Kotlin MCP Server Generatorgithub/awesome-copilot | 40k | 1 repos | ~2.7k | Automated safety check: Pass | MIT | |
| MCP Server Builderanthropics/skills | 180k | 63 repos | ~2.3k | Automated safety check: Pass | Apache-2.0 | |
| MCP Server BuildershareAI-lab/learn-claude-code | 78k | 4 repos | ~1.2k | Automated safety check: Pass | MIT |
six2dez/burp-ai-agent
Burp Suite scanning via MCP tools — passive traffic analysis, active payload testing, OOB verification, and vulnerability reporting using Burp's proxy, HTTP sender, Collaborator, and scanner APIs.
CodyBontecou/health-md
Test the standalone Health.md CLI, portable healthmd-mcp server, and direct mobile paths.
github/awesome-copilot
Generate a complete Kotlin MCP server project with proper structure, dependencies, and implementation using the official io.modelcontextprotocol:kotlin-sdk library.
anthropics/skills
Guides the design and implementation of Model Context Protocol servers in TypeScript or Python, from tool naming and error messages to evaluation.
shareAI-lab/learn-claude-code
Walks through building MCP servers in Python or TypeScript that expose tools, resources and prompts to Claude, with templates, registration and testing.
anthropics/claude-plugins-official
Explains how to bundle Model Context Protocol servers in a Claude Code plugin, covering config files, stdio, SSE, HTTP and WebSocket server types, and authentication.
rosuH/EasyWatermark
A skill your agent uses to push frequently-changing Jetpack Compose state reads (scroll position, animation values, drag offsets) out of the Composition phase and down into Layout or Draw using…
rosuH/EasyWatermark
A skill your agent uses to diagnose Jetpack Compose stability problems by enabling and reading the Compose Compiler Reports (classes.txt, composables.txt, composables.csv, module.json).
rosuH/EasyWatermark
A skill your agent uses to generate and measure Jetpack Compose Baseline Profiles end-to-end with the AGP 8.2+ Baseline Profile Generator module and the Macrobenchmark harness.
rosuH/EasyWatermark
A skill your agent uses to author new custom Jetpack Compose modifiers and migrate legacy ones from Modifier.composed { } to Modifier.Node + ModifierNodeElement<T.
rosuH/EasyWatermark
A skill your agent uses to fix unstable Jetpack Compose types once a stability diagnosis has identified them.
rosuH/EasyWatermark
A skill your agent uses to explain why the Compose compiler classified a class or composable parameter as stable, runtime, unknown, or unstable.
Works with
Categories
A skill your agent uses to drive Compose HotSwan from an AI agent (Claude Code, Cursor, any MCP client) so the agent can edit a Kotlin file, trigger a hot reload, capture a device screenshot…. Iterating With AI And MCP is an agent skill from rosuH/EasyWatermark. Use this skill to drive Compose HotSwan from an AI agent (Claude Code, Cursor, any MCP client) so the agent can edit a Kotlin file, trigger a hot reload, capture a device screenshot, evaluate the result against a design intent, and iterate without a human in the loop.
Iterating With AI And MCP fits situations like: drive Compose HotSwan from an AI agent (Claude Code; any MCP client) so the agent can edit a Kotlin file; trigger a hot reload; capture a device screenshot.
Run `npx skills add rosuH/EasyWatermark --skill iterating-with-ai-and-mcp -a claude-code`. Or copy the skill folder (.agents/skills/iterating-with-ai-and-mcp in rosuH/EasyWatermark) into .claude/skills/iterating-with-ai-and-mcp in your project. Claude Code loads it when a task matches its description.
Run `npx skills add rosuH/EasyWatermark --skill iterating-with-ai-and-mcp -a codex`. Or copy the skill folder (.agents/skills/iterating-with-ai-and-mcp in rosuH/EasyWatermark) into .agents/skills/iterating-with-ai-and-mcp in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add rosuH/EasyWatermark --skill iterating-with-ai-and-mcp -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/iterating-with-ai-and-mcp, .gemini/skills/iterating-with-ai-and-mcp, .github/skills/iterating-with-ai-and-mcp and .opencode/skills/iterating-with-ai-and-mcp in your project.
SKILL.md names no scripts, command-line tools or credentials: Iterating With AI And MCP is instructions for the agent only.
SKILL.md names 3 domains. As links in the text: github.com, plugins.jetbrains.com and modelcontextprotocol.io. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Iterating With AI And MCP is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Iterating With AI And MCP: Burp Scan (six2dez/burp-ai-agent, 1.5k stars), Healthmd CLI QA (CodyBontecou/health-md, 230 stars), Kotlin MCP Server Generator (github/awesome-copilot, 40k stars) and MCP Server Builder (anthropics/skills, 180k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
rosuH (a GitHub user) maintains it in rosuH/EasyWatermark, which has 1,895 GitHub stars. The repository holds 28 skills in this directory. The repository was last updated on October 10, 2026.
Source: rosuH/EasyWatermark on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.