What problem does it solve?
This Skill eliminates the risk of false positives and destructive payloads during web vulnerability verification by enforcing a methodical, low-impact testing workflow using Burp MCP proxy history, ensuring authorized security testers can safely triage and confirm vulnerabilities without mass scanning.
Core Features & Use Cases
- Methodical Differential Verification: Enforces single-variable mutation and two independent indicator confirmation to reduce false positives for common web vulnerabilities like path traversal, SSRF, SQLi, and IDOR.
- WeChat Mini Program Preflight: Automatically enumerates hosts and scans for session_key leaks in mini program Burp history before pursuing other vulnerability classes, preventing missed critical findings.
- Article-Derived Check Support: Includes a structured template to extract vulnerability details from writeups and craft targeted, safe probes for specific disclosed issues.
Use Case: A bug bounty hunter reviewing Burp proxy history for a target domain can use this Skill to safely verify potential vulnerabilities, confirm WeChat mini program session leaks, and generate structured, auditable evidence for valid reports.
Quick Start
Use this Skill to verify low-impact web vulnerabilities from your Burp proxy history by replaying baseline requests, mutating single variables, and comparing differential response evidence to confirm findings.