burp-suite-testing
FeaturedThis skill should be used when the user asks to "intercept HTTP traffic", "modify web requests", "use Burp Suite for testing", "perform web vulnerability scanning", "test with Burp Repeater", "analyze HTTP history", or "configure proxy for web testing". It provides comprehensive guidance for using Burp Suite's core features for web application security testing.
Install
Quality Score: 96/100
Skill Content
Details
- Author
- zebbern
- Repository
- zebbern/claude-code-guide
- Created
- 1 years ago
- Last Updated
- today
- Language
- Python
- License
- MIT
Integrates with
Similar Skills
Semantically similar based on skill content — not just same category
burp-pentest
Elite methodology for authenticated web application penetration testing and bug bounty hunting using Burp Suite via MCP. Triggers on any mention of pentest, bug bounty, web vulnerability hunting, Burp, authorization/IDOR/BOLA/BFLA testing, injection (SQLi/NoSQLi/SSTI/cmd/LDAP/XPath/XSLT/CSV-formula/LaTeX), authentication/MFA/SSO flaws, OAuth/OIDC abuse, SAML attacks (XSW signature wrapping / comment injection / audience confusion), JWT attacks, SSRF, business logic flaws, race conditions, HTTP request smuggling, HTTP header injection (User-Agent SQLi, Referer abuse, Host header injection, log4shell, CRLF, HPP), insecure deserialization (Java ysoserial / .NET ViewState / PHP unserialize / Python pickle / Ruby Marshal / Node serialize), JavaScript source/sink analysis, Spring Boot Actuator abuse (heapdump, env, jolokia, gateway), JBoss/WebLogic/WebSphere/Tomcat exploitation, Struts CVE chain, Spring4Shell, H2 console RCE, cloud post-exploitation (AWS IAM / Azure managed identity / GCP service accounts / K8s pod
web-application-security-testing
OWASP Top 10 testing, injection vulnerability detection, API security assessment, authentication testing, and web vulnerability reporting for authorized assessments
pentest-windftsy
A Web security assessment workflow built on globally installed Chrome DevTools MCP and Burp MCP. It establishes real browser state, synchronizes Burp evidence, models endpoints and permissions, validates vulnerabilities endpoint by endpoint, and completes threat convergence. It outputs structured data only.