Agent skill · security · membranedev
burp-suite
Burp Suite integration. Manage data, records, and automate workflows. Use when the user wants to interact with Burp Suite data.
Why this skill is useful
Adds specific commands and workflows for automating interactions with Burp Suite that the AI wouldn't reliably generate on its own.
What it needs
Requires @membranehq/cli installed locally. Requires membrane account access. About 4k tokens when loaded. Last updated 2026-04-28. 253 stars on the source repository.
What this skill does
Burp Suite Burp Suite is a popular set of tools used for web application security testing. Security professionals and penetration testers use it to identify vulnerabilities in web applications. It acts as a proxy, allowing users to intercept and manipulate HTTP traffic. Official docs: https://portswigger.net/burp/documentation Burp Suite Overview Scan Scan Configuration Issue Extension Project Proxy Intruder Repeater Sequencer Comparer Extender Options User Options Project Options Alert Audit Spider Target Search Settings Help Working with Burp Suite This skill uses the Membrane CLI to interact with Burp Suite. Membrane handles authentication and credentials refresh automatically — so you can focus on the integration logic rather than auth plumbing. Install the CLI Install the Membrane CLI so you can run membrane from the terminal: Authentication This will either open a browser for authentication or print an authorization URL to the console, depending on whether interactive mode is available. Headless environments: The command will print an authorization URL. Ask the user to open it in a browser. When they see a code after completing login, finish with: Add --json to any command for machine-readable JSON output. Agent Types : claude, openclaw, codex, warp, windsurf, etc. Those will be used to adjust tooling to be used best with your harness Connecting to Burp Suite Use membrane connection ensure to find or create a connection by app URL or domain: The user completes authentication in the browser. The output contains the new connection id. This is the fastest way to get a connection. The URL is normalized to a domain and matched against known apps. If no app is found, one is created and a connector is built automatically. If the returned connection has state: "READY", skip to Step 2. 1b. …
How to use it
Reference it in AdaL, Claude Code, Cursor or any coding agent — nothing to install:
@skills membranedev/burp-suite