Agent skill · security · membranedev

burp-suite

Burp Suite integration. Manage data, records, and automate workflows. Use when the user wants to interact with Burp Suite data.

Why this skill is useful

Adds specific commands and workflows for automating interactions with Burp Suite that the AI wouldn't reliably generate on its own.

What it needs

Requires @membranehq/cli installed locally. Requires membrane account access. About 4k tokens when loaded. Last updated 2026-04-28. 253 stars on the source repository.

What this skill does

Burp Suite Burp Suite is a popular set of tools used for web application security testing. Security professionals and penetration testers use it to identify vulnerabilities in web applications. It acts as a proxy, allowing users to intercept and manipulate HTTP traffic. Official docs: https://portswigger.net/burp/documentation Burp Suite Overview Scan Scan Configuration Issue Extension Project Proxy Intruder Repeater Sequencer Comparer Extender Options User Options Project Options Alert Audit Spider Target Search Settings Help Working with Burp Suite This skill uses the Membrane CLI to interact with Burp Suite. Membrane handles authentication and credentials refresh automatically — so you can focus on the integration logic rather than auth plumbing. Install the CLI Install the Membrane CLI so you can run membrane from the terminal: Authentication This will either open a browser for authentication or print an authorization URL to the console, depending on whether interactive mode is available. Headless environments: The command will print an authorization URL. Ask the user to open it in a browser. When they see a code after completing login, finish with: Add --json to any command for machine-readable JSON output. Agent Types : claude, openclaw, codex, warp, windsurf, etc. Those will be used to adjust tooling to be used best with your harness Connecting to Burp Suite Use membrane connection ensure to find or create a connection by app URL or domain: The user completes authentication in the browser. The output contains the new connection id. This is the fastest way to get a connection. The URL is normalized to a domain and matched against known apps. If no app is found, one is created and a connector is built automatically. If the returned connection has state: "READY", skip to Step 2. 1b. …

How to use it

Reference it in AdaL, Claude Code, Cursor or any coding agent — nothing to install:

@skills membranedev/burp-suite

View the source on GitHub

Browse the @skills marketplace