Burp Scan
six2dez/burp-ai-agent
Burp Suite scanning via MCP tools — passive traffic analysis, active payload testing, OOB verification, and vulnerability reporting using Burp's proxy, HTTP sender, Collaborator, and scanner APIs.
Adding, removing or changing a tool on RedAmon's INBOUND MCP server, where external agents connect in with a personal access token.
$ npx skills add samugit83/redamon --skill mcp-server-tools -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install samugit83/redamon mcp-server-tools --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/samugit83/redamon.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/mcp-server-tools .claude/skills/mcp-server-tools && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "mcp-server-tools" agent skill from https://github.com/samugit83/redamon/tree/master/skills/mcp-server-tools into .claude/skills/mcp-server-tools/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "mcp-server-tools", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/samugit83/redamon/tree/master/skills/mcp-server-toolsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add samugit83/redamon --skill mcp-server-tools -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install samugit83/redamon mcp-server-tools --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/samugit83/redamon.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/mcp-server-tools .agents/skills/mcp-server-tools && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "mcp-server-tools" agent skill from https://github.com/samugit83/redamon/tree/master/skills/mcp-server-tools into .agents/skills/mcp-server-tools/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "mcp-server-tools", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add samugit83/redamon --skill mcp-server-tools -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install samugit83/redamon mcp-server-tools --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/samugit83/redamon.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/mcp-server-tools .cursor/skills/mcp-server-tools && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "mcp-server-tools" agent skill from https://github.com/samugit83/redamon/tree/master/skills/mcp-server-tools into .cursor/skills/mcp-server-tools/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "mcp-server-tools", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/samugit83/redamon.git --path skills/mcp-server-tools--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add samugit83/redamon --skill mcp-server-tools -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install samugit83/redamon mcp-server-tools --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/samugit83/redamon.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/mcp-server-tools .gemini/skills/mcp-server-tools && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "mcp-server-tools" agent skill from https://github.com/samugit83/redamon/tree/master/skills/mcp-server-tools into .gemini/skills/mcp-server-tools/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "mcp-server-tools", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install samugit83/redamon mcp-server-toolsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add samugit83/redamon --skill mcp-server-tools -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/samugit83/redamon.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/mcp-server-tools .github/skills/mcp-server-tools && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "mcp-server-tools" agent skill from https://github.com/samugit83/redamon/tree/master/skills/mcp-server-tools into .github/skills/mcp-server-tools/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "mcp-server-tools", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add samugit83/redamon --skill mcp-server-tools -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install samugit83/redamon mcp-server-tools --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/samugit83/redamon.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/mcp-server-tools .opencode/skills/mcp-server-tools && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "mcp-server-tools" agent skill from https://github.com/samugit83/redamon/tree/master/skills/mcp-server-tools into .opencode/skills/mcp-server-tools/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "mcp-server-tools", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
mcp-server-toolsAdding, removing or changing a tool on RedAmon's INBOUND MCP server, where external agents connect in with a personal access token.
MCP Server Tools is an agent skill from samugit83/redamon. Adding, removing or changing a tool on RedAmon's INBOUND MCP server, where external agents connect in with a personal access token. The wiki API reference is generated from the server's live tools/list and goes stale silently, and each tool's annotations and declared scopes are published to connected clients. Trigger: editing a registerTool call in webapp/src/lib/mcp/server.ts; editing tools.ts, writeTools.ts, scopeCopy.ts or apiReference.ts in webapp/src/lib/mcp/; changing the scope list, default scopes, expiry…
Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering MCP servers and Penetration testing. It works with Model Context Protocol. The repository describes itself as: Open-source, self-hosted AI penetration testing framework: maps your attack surface into a graph, autonomously exploits it from a Kali sandbox with human approval gates, and… The licence is MIT.
Read from SKILL.md and the folder at commit d90c940. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npmgitnpxFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npm, git and npx, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
MCP Server Tools loads about 1.8k tokens when it runs. Until then it costs about 147 tokens; SKILL.md has 747 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from samugit83/redamon at commit d90c940, republished under its MIT licence (© samugit83). 747 words, ~1,758 tokens.
.claude/skills/mcp-server-tools/SKILL.md (or your agent's skills folder).For a tool RedAmon's OWN agent calls (outbound, mcp/servers/), use
agentic-tool-integration. For making a recon setting writable over MCP, use
project-settings-cascade. The tools that exist are listed by the server itself and by
the generated reference page, never by this skill.
npm run docs:mcp in webapp/ after any change this skill's trigger
names, and commit MCP-API-Reference.md inside the redamon.wiki repo. A main-repo
commit moves only the submodule pointer. The page is rendered by
apiReference.ts; a hand edit is overwritten
by the next run.destructiveHint: false on a tool that overwrites or aborts existing
state. In the MCP spec false means only additive updates, and clients use it to
decide when to ask the user first. No test checks this.EXAMPLE_EXTRA_ARGS entry in
apiReference.ts when a tool's body requires
an argument its JSON Schema marks optional. The generated example sends only
schema-required arguments, and the test calls every example.ONBOARDING_PLAYBOOK entry and a capability area in
playbook.ts. The Agent Onboarding pack is
generated from the live tools/list, and a coverage test in
onboarding.test.ts fails the moment a
tool ships without whenToUse + gotchas, or sits in zero or two capability areas. Also
decide whether any profile in profiles.ts should
leansOn it; that half is editorial and is not enforced.BACKEND_FREE_TOOLS in
apiReference.test.ts. That file proves a
tool's declared scopes are enough by calling it and expecting the generic database failure,
because every Prisma model is mocked away. A tool derived purely from constants
(describe_recon_settings, list_recon_presets) SUCCEEDS instead, and would otherwise read
as a failure. Do not relax the assertion; name the tool.STALE_CLAIMS in
toolNameDrift.test.ts, and make sure
every file carrying agent-facing strings is in its AGENT_FACING list: the "nothing here
can mute" lines outlived the feature in server.ts and profiles.ts, which were outside it.TOOL_SHAPED only knows the verbs it
lists, so a new tool's verb goes there; an op literal such as list_muted or mute_many
in an agent-facing file then reads as an unknown tool. Wrap ops in
triageGraph.ts helpers instead.write bucket headroom. apiReference.test.ts
calls every tool with ONE token inside one test, against the write limit (10/min by
default). A new write tool that overflows it must raise that test's limit, not drop a call.EXAMPLE_EXTRA_ARGS entry. placeholderFor has no
array branch, so the generated example would name no item (mute_findings' findingIds).ScopeAccess in
scopeCopy.ts is read or write except kali:exec,
the one read-write scope. A tool that only reads what a write needs (get_finding_evidence
for submit_finding_review) belongs under the read scope, so a read-only token can see
what an agent would act on.requireScope first, then no McpToolError before the first
backend read. The apiReference test proves declared scopes by calling each example and
expecting the mocked database failure; a refusal on the example's placeholder arguments
ahead of that read looks like a scope gap. A tool that STARTS something checks access (and
its own caps) before it spends a rate token, so a refused start costs the caller nothing.UNAUDITED_ARGS in
server.ts. auditDetail copies every other string
argument into the audit row, which also prints as a console line; a quote is target text,
and a reason is recorded, better, by the tool that owns it.Copy the shape of an existing registerTool call in
server.ts: annotations,
_meta: scopesMeta({ required, conditional }) naming exactly the scopes the tool body
enforces with requireScope, and inputSchema. A scope that applies only to a
particular argument goes under conditional, and the arguments that trigger it need a
CONDITIONAL_TRIGGERS entry in
apiReference.test.ts.
cd webapp
npm run docs:mcp # rewrites ../redamon.wiki/MCP-API-Reference.md
npx vitest run src/lib/mcp/ # scope, example-call, onboarding-coverage and stale-page checks
cd ../redamon.wiki
git add MCP-API-Reference.md
git commit -m "docs: regenerate MCP API reference"agentic-tool-integration, project-settings-cascade, redamon-testing© samugit83, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/mcp-server-tools of samugit83/redamon.
Open the folder on GitHubat commit d90c940
MCP Server Tools next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| MCP Server Tools this skillsamugit83/redamon | 3k | — | ~1.8k | Automated safety check: Pass | MIT | |
| Burp Scansix2dez/burp-ai-agent | 1.5k | — | ~6.4k | Automated safety check: Warn | MIT | |
| Burp MCP Vuln Checklangbyyi/CyberStrikeAI-SRC | 134 | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | |
| Hunt BurpEncod3d-Sec/TORCH | 329 | 1 repos | ~3.1k | Automated safety check: Pass | MIT | |
| Golang Pkg Go Devcontext-labs/whip | 1.1k | 2 repos | ~3k | Automated safety check: Pass | MIT | |
| Forensifyalexgreensh/repo-forensics | 188 | — | ~2.5k | Automated safety check: Notes | Custom licence |
six2dez/burp-ai-agent
Burp Suite scanning via MCP tools — passive traffic analysis, active payload testing, OOB verification, and vulnerability reporting using Burp's proxy, HTTP sender, Collaborator, and scanner APIs.
langbyyi/CyberStrikeAI-SRC
Automate low-impact web vulnerability verification through Burp MCP.
Encod3d-Sec/TORCH
Drive Burp Suite over its MCP server as an AI triage + attack layer - review proxy history for signals, replay via Repeater/send, OOB-gate blind bugs with Collaborator, fuzz via Intruder (RoE-safe)…
context-labs/whip
Golang package/module docs via godig, a pkg.go.dev API client (CLI + MCP) — APIs, symbols, versions, importers, licenses, vulnerabilities.
alexgreensh/repo-forensics
Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.
PrefectHQ/fastmcp
Review FastMCP vulnerability reports before accepting, rejecting, patching, scoring, or publishing them.
samugit83/redamon
Adding a Community Agent Skill: a Markdown attack-workflow file that users import from the catalog, which then competes in the Intent Router and is injected into the agent's system prompt.
samugit83/redamon
Adding partial-recon support for a tool: running a single pipeline phase on demand from the workflow graph, reading its inputs from the existing Neo4j graph and merging results back.
samugit83/redamon
Wiring a new tool the AI agent can call (not the recon pipeline): the tool registry, the phase map, the hardcoded dispatch chokepoint, and the duplicated execution paths that make a tool work in…
samugit83/redamon
Adding a built-in Agent Skill (an attack technique like ssrf, xxe, rce) that ships hardcoded in RedAmon: classified by the Intent Router, injected into the agent prompt, toggled per project, badged…
samugit83/redamon
Writing to the Neo4j attack-surface graph in RedAmon: the tenant-isolation MERGE key every entity node must carry, where graph methods live (mixins, not the client), and the schema places that must…
samugit83/redamon
Adding an LLM provider to RedAmon: the credential boundary (keys must never reach scan containers), prefix-routed model ids, and the provider registry.
Works with
Categories
Adding, removing or changing a tool on RedAmon's INBOUND MCP server, where external agents connect in with a personal access token. MCP Server Tools is an agent skill from samugit83/redamon. Adding, removing or changing a tool on RedAmon's INBOUND MCP server, where external agents connect in with a personal access token.
MCP Server Tools fits situations like: tasks that involve MCP servers; tasks that involve Penetration testing.
Run `npx skills add samugit83/redamon --skill mcp-server-tools -a claude-code`. Or copy the skill folder (skills/mcp-server-tools in samugit83/redamon) into .claude/skills/mcp-server-tools in your project. Claude Code loads it when a task matches its description.
Run `npx skills add samugit83/redamon --skill mcp-server-tools -a codex`. Or copy the skill folder (skills/mcp-server-tools in samugit83/redamon) into .agents/skills/mcp-server-tools in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add samugit83/redamon --skill mcp-server-tools -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/mcp-server-tools, .gemini/skills/mcp-server-tools, .github/skills/mcp-server-tools and .opencode/skills/mcp-server-tools in your project.
Going by SKILL.md and its folder, MCP Server Tools needs the command-line tools its instructions call (npm, git and npx). Our summary lists: Node.js.
SKILL.md contains no URLs. Its commands use npm, git and npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
MCP Server Tools is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.8k tokens (SKILL.md is roughly 7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with MCP Server Tools: Burp Scan (six2dez/burp-ai-agent, 1.5k stars), Burp MCP Vuln Check (langbyyi/CyberStrikeAI-SRC, 134 stars), Hunt Burp (Encod3d-Sec/TORCH, 329 stars) and Golang Pkg Go Dev (context-labs/whip, 1.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
samugit83 (a GitHub user) maintains it in samugit83/redamon, which has 2,961 GitHub stars. The repository holds 15 skills in this directory. The repository was last updated on October 7, 2026.
Source: samugit83/redamon on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.