{"repo":"Cy-S3c/BurpMCP-Ultra","free":true,"listed":false,"github":"https://github.com/Cy-S3c/BurpMCP-Ultra","clone":"git clone https://github.com/Cy-S3c/BurpMCP-Ultra.git","description":"AI-powered MCP server for Burp Suite Professional — 149 tools across proxy, scanner, inline fuzzer, race conditions, guided injection, JWT/IDOR attacks, recon & OOB, with a real-time dashboard and hardened localhost security. Drive Burp from Claude Code or any MCP client.","language":"Kotlin","stars":190,"topics":["bug-bounty","burpsuite","claude","kotlin","mcp","model-context-protocol","pentesting","security-tools"],"license":"MIT","category":"mcp-servers","readme_excerpt":"BurpMCP-Ultra The most powerful MCP server for Burp Suite Professional. Drop a single JAR into Burp, connect Claude Code (or any MCP client), and drive every part of Burp Suite programmatically through AI agents. 150 Tools &bull; 8 Resources &bull; 17 Event Types &bull; Real-time Dashboard &bull; Hardened Localhost Security Quick Start &bull; Tools &bull; Features &bull; Security &bull; Dashboard &bull; Setup Guides &bull; Contact --- BurpMCP-Ultra is a native Kotlin Burp Suite extension with an embedded MCP (Model Context Protocol) server. It exposes Burp's Montoya API as 150 structured tools over a token-secured local SSE transport, so an AI agent can run proxy history analysis, active scans, fuzzing, race conditions, OOB testing, custom scan checks, and guided exploitation — all from natural language. Why BurpMCP-Ultra? BurpMCP-Ultra burp-ai-agent PortSwigger Official --- :---: :---: :---: MCP Tools 150 53 12 Custom Scan Checks BCheck + Script – – Guided Injection Probe SQLi / SSTI / LFI oracles – – JWT Attacks alg:none, RS→HS, crack – – Access-Control Sweep IDOR / privesc across identities – – WebSocket Testing Full lifecycle – – Inline Fuzzer 3 modes (FUZZ / Marker / Offset) – – Race Condition Testing Single-packet attack – – API Schema Import OpenAPI / Swagger + $ref – – Passive Intel Extraction 30+ patterns, entropy de-noised – – Recon JS endpoints, content/param discovery – – Real-time Dashboard Web + Swing – – Hardened Localhost Security Host + Origin + token, scope ","default_branch":null,"files":null,"tree":[],"storefront":"/r/Cy-S3c","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/Cy-S3c/BurpMCP-Ultra/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}