🚀 BurpSuite MCP Full Control — 83 Tools, 4 Phases, One Extension

Transform Burp Suite into an AI-powered penetration testing platform with full MCP protocol support. Every core feature exposed as MCP tools for AI clients (Claude Code / Kiro / Cursor / Cline).

https://github.com/zhaoxuya520/reverse-skill

🔥 What's new in v2.2.0 (Phase 1-4):

Phase 1 — WebSocket Lifecycle + Session Rules
• Full WS: create → send text/binary → close → list
• send_request_parallel: batch async HTTP requests
• passive_intel: auto-extract AWS keys / JWTs / secrets
• session_create/list/remove_rule: regex find/replace on requests

Phase 2 — Attack Modules
• jwt_decode + jwt_attack: alg:none forgery
• injection_probe: SQLi / SSTI / LFI oracle detection
• access_control_sweep: cross-auth replay & diff
• race_condition: TOCTOU testing
• inline_fuzzer: FUZZ/marker fuzzing

Phase 3-4 — Security Controls
• scope_gate: restrict tools to in-scope hosts
• privacy_mode: strict host anonymization
• audit_log: auto-recorded operation history

🛡️ Demo (scanme.nmap.org):
JWT decode → forged token via alg:none ✅
SQLi probe → 3 payloads sent, oracle detection ✅
Access control → 3 auth levels compared ✅
Race condition → 5 parallel requests, verdict: "all identical" ✅
Inline fuzzer → 3 FUZZ positions tested ✅

Integration with @Anthropic Claude Code / @Cursor / Kiro
All tools available via stdio MCP bridge on localhost:9876

⬇️ Clone, build, load into Burp — zero Gradle needed
#BurpSuite #MCP #Pentest #BugBounty #AI #InfoSec #RedTeam #AppSec
