Skip to main content
Glama
jayluxferro

Burp Suite MCP Server

by jayluxferro

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault
BURP_REST_API_KEYYesThe API key created in Burp Suite settings
BURP_REST_API_BASEYesThe base URL for Burp's REST API (e.g., http://127.0.0.1:1337)
BURP_REST_API_VERSIONNoThe version of the Burp REST API (e.g., v0.1)v0.1

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Features and capabilities supported by this server

Protocol revision2025-11-25

CapabilityDetails
tools
{
  "listChanged": false
}
prompts
{
  "listChanged": false
}
resources
{
  "subscribe": false,
  "listChanged": false
}
experimental
{}

Tools

Functions exposed to the LLM to take actions

NameDescription
burp_suite_security_issue_definitionsA

Get all Burp Suite security issue definitions (name, description, remediation, references).

scan_urls_for_vulnerabilitiesC
Scan URL(s) for security vulnerabilities.

Args:
    urls: List of URLs to scan
    scope: Optional scope configuration (passed to API if supported)
check_security_scan_progressA
Retrieves scan progress and details using the task_id.

Args:
    task_id: Task ID from an initiated scan (numeric ID or full path)
    severity: Filter issues: low, info, medium, high, or "all" (default)
get_scan_summaryA
Get a high-level summary of scan results: total issues by severity.

Args:
    task_id: Task ID from an initiated scan
list_active_scansA

List running and pending scans. May not be supported by all Burp API versions.

cancel_scanC
Cancel a scan by task_id. May not be supported by all Burp API versions.

Args:
    task_id: Task ID of the scan to cancel
check_burp_connectivityA

Test connectivity to the Burp REST API. Validates config and performs a simple request.

wait_for_scan_completionA
Poll scan progress until the scan completes or times out.
Useful for long-running scans in CI/CD.

Args:
    task_id: Task ID from an initiated scan
    poll_interval_seconds: Seconds between polls (default: 10)
    max_wait_seconds: Maximum time to wait (default: 3600 = 1 hour)

Prompts

Interactive templates invoked by user choice

NameDescription

No prompts

Resources

Contextual data attached and managed by the client

NameDescription

No resources

TDQS

A3.7/5.0

Scored across 8 tools

Disambiguation4/5

Most tools have distinct purposes, but there is some potential overlap between check_security_scan_progress and get_scan_summary, as both retrieve scan results using a task_id, which could cause confusion. However, their descriptions clarify that one provides detailed progress and filtered issues while the other gives a high-level summary, helping to differentiate them.

Naming Consistency5/5

All tool names follow a consistent snake_case pattern with clear verb_noun structures, such as cancel_scan, check_burp_connectivity, and scan_urls_for_vulnerabilities. This uniformity makes the tool set predictable and easy to navigate, with no deviations in naming conventions.

Tool Count5/5

With 8 tools, the server is well-scoped for managing Burp Suite security scans, covering connectivity testing, scan initiation, progress monitoring, result retrieval, and cancellation. Each tool serves a specific role in the scanning lifecycle, and the count is appropriate for the domain without being excessive or insufficient.

Completeness4/5

The tool set provides comprehensive coverage for security scanning workflows, including initiation, monitoring, and result analysis, with minor gaps such as the lack of tools for configuring scan settings or managing scan history. However, core operations are well-covered, and agents can perform essential tasks without significant dead ends.

Maintenance

ActivityInactive
ResponsivenessNo issues