Cy-S3c/BurpMCP-Ultra
View on GitHub ↗AI-powered MCP server for Burp Suite Professional — 149 tools across proxy, scanner, inline fuzzer, race conditions, guided injection, JWT/IDOR attacks, recon & OOB, with a real-time dashboard and hardened localhost security. Drive Burp from Claude Code or any MCP client.
190 ★26 forksKotlinUpdated 1mo ago
What you need to know
Native Kotlin Burp Suite Professional extension with an embedded MCP server exposing 150 tools for AI-driven pentesting
Install
Clone the repo, run ./gradlew shadowJar, and load the JAR into Burp Suite Professional via Extensions > Add
Usage
- •Connect Claude Code via SSE with url http://127.0.0.1:9876/ and the server token as Bearer auth
- •Use the 150 tools to run proxy history analysis, active scans, fuzzing, race conditions, OOB testing and guided exploitation
Key features
- ✓150 MCP tools across 37 categories covering proxy, HTTP, scanner, Collaborator, Intruder, WebSocket, offensive and recon
- ✓Guided injection probes (SQLi/SSTI/LFI) with confirmation oracles
- ✓JWT attacks, access-control sweep, race-condition testing, inline fuzzer
- ✓BCheck and script custom scan checks
- ✓Hardened localhost security: host allowlist, origin lockdown, per-session tokens, scope gate, append-only audit log
- ✓Real-time web and Swing dashboards
Best for
Bug-bounty hunters and pentesters who want AI-powered Burp Suite automation
Caveats
- ⚠Requires Burp Suite Professional 2025.x or later
- ⚠Offensive tools issuing live requests are scope-gated and destructive tools disabled by default
- ⚠Port 9876 clashes with PortSwigger's own MCP server extension
Platforms: Windows · macOS · LinuxClients: Claude Code · Claude Desktop · Any MCP client
Reviewed 2026-08-11
Topics
- Stars
- 190★
- Forks
- 26
- Language
- Kotlin
- License
- MIT
- Created
- 2026-04-03
- Last push
- 2026-08-05