burp-zap-hardenedQuery Burp Suite via MCP to extract security findings and proxy data.
Install via ClawdBot CLI:
clawdbot install snazar-faberlens/burp-zap-hardenedGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Potentially destructive shell commands in tool definitions
eval (Calls external URL not in known-safe list
http://127.0.0.1:9876Uses known external API (expected, informational)
discord.comAudited Apr 22, 2026 · audit v1.0
Generated May 13, 2026
A security consultant uses the Burp MCP skill to bulk retrieve proxy history from a target web application, then applies local filtering to identify endpoints by scope and exclude noise. This enables rapid triage of intercepted traffic across thousands of requests without overwhelming the Burp API.
During a penetration test of an e-commerce platform, the agent queries Burp's sitemap and proxy history to discover API endpoints with ID patterns. It then uses response analysis patterns to detect sensitive data exposure like credit card numbers or API keys in responses.
A security engineer uses the comparative retrieval strategy to group requests by auth context (e.g., different user tokens) and compare responses for the same endpoint. This reveals broken access control vulnerabilities where users can access other users' data.
After gaining access to a compromised web server, the agent extracts object references from historical requests using ID patterns. It then replays requests via send_to_repeater to validate IDOR vulnerabilities and extract sensitive data like personal information.
A compliance officer queries Burp's proxy history to verify that sensitive endpoints (e.g., /api/users with IDs) require authentication and return proper 401 responses for unauthenticated requests. The skill's filtering patterns help isolate auth-related endpoints.
Offer automated security testing and vulnerability scanning of customer web applications using AI agents that leverage Burp MCP skills. The service provides CIS-hardened security checks with actionable reports.
Provide on-demand penetration testing services where AI agents autonomously triage and analyze Burp data, then deliver structured vulnerability reports with evidence. This reduces manual effort by 80%.
Embed the skill into CI/CD pipelines as a Burp MCP connector that automatically triggers security analysis after each deployment. Revenue comes from licensing the connector or usage-based fees per API call.
💬 Integration Tip
Set up a persistent MCP connection to Burp Suite's REST API and configure scope filters (hosts, include/exclude patterns) before querying to avoid rate limits and reduce noise.
Scored May 13, 2026
Provides a comprehensive testing methodology for AI software, covering strategy design, unit, integration, and end-to-end tests with coverage and reporting g...
Control Samsung TVs via SmartThings (OAuth app + device control).
CLI for AI agents to search and lookup anime info for their humans. Uses Jikan (unofficial MyAnimeList API). No auth required.
Instant rug pull detection for any token. Holder concentration, liquidity locks, contract risks. DYOR before you ape. Works with AI agents.
Security scanner for Moltbot skills. Scan GitHub repositories for vulnerabilities before installation.
NadMail - Email for AI Agents on Monad. Register [email protected], send emails that micro-invest in meme coins, boost with emo-buy. SIWE auth, no CAPTCHA,...