Burp Suite for AI Agent
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| PORT | No | Port for the MCP server (customizable via --port) | 9999 |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": true
} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| burp_statusA | Show Burp bridge connection status and store statistics (requests, tasks, issues captured). Call first to confirm bridge is running. |
| burp_requestsA | List recent HTTP requests captured from Burp (most-recent first). Returns id, method, url, and status for each captured request. |
| burp_request_detailA | Fetch full details for one captured request: headers, request body, and response body (when available). Pass the id from burp_requests. |
| burp_endpointsA | List unique endpoints (METHOD + path) observed from Burp traffic, with query/body parameter names and hit counts. Helps identify attack surface. |
| burp_tasksA | List scan / plan / scope tasks queued from the Burp extension. Use these to decide what to analyze next. |
| burp_issuesA | List security findings/issues queued for Burp import. These are confirmed findings that can be imported as Burp Scanner issues. |
| burp_import_issueB | Submit a confirmed finding as a Burp-importable issue. The issue will appear in the bridge and can be pulled into Burp via the burpAI Burp plugin. |
| burp_snapshotA | Return the most recent session snapshot (cookies, localStorage, sessionStorage). Useful for constructing authenticated requests. |
| burp_send_to_burpA | Queue an action for execution in Burp Suite. The next time the Burp plugin polls, it will execute the action. Supports: send_to_repeater (open Repeater tab with a request), add_scan_issue (add scan issue to Burp), console_log (write to Burp output tab). |
| burp_outbound_statusA | List pending outbound actions queued for the Burp plugin to execute. Actions remain here until the Burp plugin polls and drains them. |
| burp_clearA | Clear all captured requests, endpoints, tasks, and issues from the bridge store. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 11 tools
Each tool targets a distinct aspect of the Burp Suite integration: clearing, status, requests (list/detail), endpoints, tasks, issues (list/import), session snapshot, and outbound actions (send/status). Despite some related operations, the descriptions clearly differentiate them, leaving no ambiguity.
All tools follow a consistent 'burp_' prefix with snake_case names. Verbs and nouns are used predictably (e.g., burp_clear, burp_requests, burp_import_issue). There is no mixing of conventions, ensuring easy pattern recognition.
With 11 tools, the set is well-scoped for a Burp Suite bridge. It covers essential operations without being bloated or sparse. Each tool serves a clear purpose, and the count aligns with the expected complexity of security testing workflows.
The tool set covers the core workflow: connection status, request capture, endpoint discovery, task and issue management, import, session retrieval, and outbound actions. Minor gaps exist, such as the lack of detailed views for individual tasks or issues, but these do not critically hinder the primary use case.