rrsaldanha/burp-mcp-agents
๐ Connect Burp Suite MCP Server to multiple AI backends with practical guides and templates for safe, real traffic analysis.
What's novel
๐ Connect Burp Suite MCP Server to multiple AI backends with practical guides and templates for safe, real traffic analysis.
Code Analysis
15 files read ยท 4 roundsA collection of zsh scripts and Python agents that bridge Burp Suite's MCP server to local AI backends (Ollama, LM Studio) via a Caddy reverse proxy, enabling AI-assisted security analysis of captured traffic through tool-calling loops.
Strengths
The Caddy reverse proxy workaround for Burp MCP's anti-DNS-rebinding protection is a genuinely practical and clever solution to a real problem. The prompts are well-structured, evidence-based, and safety-conscious, providing a solid workflow for AI-assisted vulnerability analysis.
Weaknesses
The README is severely misleading, describing a downloadable application with installers and settings tabs that don't exist in the code. There are zero tests, significant code duplication between the Ollama and LM Studio agents, and the project is clearly early-stage with no CI/CD or automated verification.
Score Breakdown
Signal breakdown
Innovation
Craft
Traction
Scope
Evidence
Commits
7
Contributors
2
Files
28
Active weeks
4
Repository
Language
Python
Stars
2
Forks
0
License
MIT