Cy-S3c/BurpMCP-Ultra

View on GitHub ↗

AI-powered MCP server for Burp Suite Professional — 149 tools across proxy, scanner, inline fuzzer, race conditions, guided injection, JWT/IDOR attacks, recon & OOB, with a real-time dashboard and hardened localhost security. Drive Burp from Claude Code or any MCP client.

190 ★26 forksKotlinUpdated 1mo ago

What you need to know

Native Kotlin Burp Suite Professional extension with an embedded MCP server exposing 150 tools for AI-driven pentesting

Install

Clone the repo, run ./gradlew shadowJar, and load the JAR into Burp Suite Professional via Extensions > Add

Usage

  • Connect Claude Code via SSE with url http://127.0.0.1:9876/ and the server token as Bearer auth
  • Use the 150 tools to run proxy history analysis, active scans, fuzzing, race conditions, OOB testing and guided exploitation

Key features

  • 150 MCP tools across 37 categories covering proxy, HTTP, scanner, Collaborator, Intruder, WebSocket, offensive and recon
  • Guided injection probes (SQLi/SSTI/LFI) with confirmation oracles
  • JWT attacks, access-control sweep, race-condition testing, inline fuzzer
  • BCheck and script custom scan checks
  • Hardened localhost security: host allowlist, origin lockdown, per-session tokens, scope gate, append-only audit log
  • Real-time web and Swing dashboards

Best for

Bug-bounty hunters and pentesters who want AI-powered Burp Suite automation

Caveats

  • Requires Burp Suite Professional 2025.x or later
  • Offensive tools issuing live requests are scope-gated and destructive tools disabled by default
  • Port 9876 clashes with PortSwigger's own MCP server extension
Platforms: Windows · macOS · LinuxClients: Claude Code · Claude Desktop · Any MCP client

Reviewed 2026-08-11

Topics

bug-bountyburpsuiteclaudekotlinmcpmodel-context-protocolpentestingsecurity-tools
Stars
190★
Forks
26
Language
Kotlin
License
MIT
Created
2026-04-03
Last push
2026-08-05