{"repo":"six2dez/burp-ai-agent","free":true,"listed":false,"github":"https://github.com/six2dez/burp-ai-agent","clone":"git clone https://github.com/six2dez/burp-ai-agent.git","description":"Burp Suite extension that adds built-in MCP tooling, AI-assisted analysis, privacy controls, passive and active scanning and more","language":"Kotlin","stars":1408,"topics":["bugbounty","burp","burp-extensions","burp-plugin","burp-suite","hacking","pentesting","security","ai","web-security"],"license":"MIT","category":"security-tools","readme_excerpt":"Custom AI Agent The bridge between Burp Suite and modern AI. A note on the name: This extension is published as Custom AI Agent (formerly Burp AI Agent ). It was renamed to comply with PortSwigger's BApp Store naming requirements and to avoid confusion with Burp Suite's built-in Burp AI provider. The GitHub repository ( github.com/six2dez/burp-ai-agent ), the documentation site ( burp-ai-agent.six2dez.com ), and the configuration directory ( /.burp-ai-agent/ ) keep the burp-ai-agent identifier for continuity. Custom AI Agent is an extension for Burp Suite that integrates AI into your security workflow. Use local models or cloud providers, connect external AI agents via MCP, and let passive/active scanners find vulnerabilities while you focus on manual testing. What's new in v0.9.0 - Native Anthropic backend (CAP-01) — direct Anthropic Messages API via Burp's HTTP transport; all traffic appears in Proxy history. - AES-256-GCM secrets at rest (SEC-01) — all stored API keys and tokens are encrypted with a per-install key using javax.crypto ; no plaintext in preferences. - Real HKDF host anonymization (PRIV-01) — STRICT mode now uses genuine HMAC-SHA256 extract/expand (not salted SHA-256) for host anonymization. - Request/response body redaction + custom patterns (PRIV-02) — redaction pipeline covers body fields and user-configurable regex patterns validated against ReDoS. - Pre-send secret tripwire (PRIV-03) — warns before high-entropy values leave Burp; allowlist actions are au","default_branch":null,"files":null,"tree":[],"storefront":"/r/six2dez","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/six2dez/burp-ai-agent/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}