burp-scan

Coordinate Burp Suite scans via MCP for vulnerability identification.

1.4k|207|Updated Jan 27, 2026
One-click install
npx skills add https://github.com/six2dez/burp-ai-agent --skill burp-scan
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: burp-scan
Source: https://github.com/six2dez/burp-ai-agent/tree/main/skills/burp-scan
Command: npx skills add https://github.com/six2dez/burp-ai-agent --skill burp-scan

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Burp Scan Skill provides an automated workflow to orchestrate Burp Suite scanning through MCP tools, enabling AI-assisted analysis of web traffic and vulnerability reporting.

Core Features & Use Cases

  • Passive traffic analysis to detect anomalies and potential vulnerabilities without active requests.
  • Active payload testing to validate findings using configurable Burp tools and AI prompts.
  • OOB verification and vulnerability reporting via Burp Collaborator and the MCP server.

Quick Start

Install and run Burp with the AI Agent MCP server and load the Burp Scan Skill to begin automated reconnaissance and testing of target web applications.

Frequently Asked Questions about burp-scan

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate Burp Suite scanning and vulnerability reporting?

Yes, AI-assisted web security testing works by applying AI prompts to Burp scanner data, enabling passive analysis to detect anomalies and active payload testing to validate findings.

Do I need the MCP server to run active payload testing with Burp Suite?

OOB verification in web security testing is handled through Burp Collaborator and the MCP server, allowing you to confirm out-of-band interactions and compile vulnerability reports.

Can I use this for passive analysis without sending active web requests?

To start automated reconnaissance and testing, install and run Burp Suite with the AI Agent MCP server, load the MCP-enabled extension, and access Burp's proxy, Collaborator, and scanner APIs.

What are the limitations of orchestrating Burp scans via MCP?

Orchestrating Burp scans via MCP is limited to Burp-enabled environments and requires access to Burp's proxy, Collaborator, and scanner APIs, making it unsuitable for non-Burp testing setups.