CtrlK
BlogDocsLog inGet started
Tessl Logo

burp-suite

Burp Suite integration. Manage data, records, and automate workflows. Use when the user wants to interact with Burp Suite data.

60

Quality

70%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/burp-suite/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

75%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is highly actionable with executable commands and a sound connection/state workflow, but it spends tokens explaining Burp Suite basics Claude already knows and includes a low-value menu bullet list. Tightening the intro and resolving the dangling 'Step 2' reference would improve it.

Suggestions

Cut the opening paragraph explaining what Burp Suite is and the flat 'Burp Suite Overview' menu bullet list; assume Claude's knowledge and keep only integration-relevant context.

Fix the dangling navigation: either label an explicit 'Step 2: Search and run actions' heading or remove 'skip to Step 2' references so the flow is unambiguous.

Merge the redundant 'Searching for actions' and 'Popular actions' sections, which both show `action list --intent=QUERY`, to remove duplicated guidance.

DimensionReasoningScore

Conciseness

The body opens by explaining what Burp Suite is ('a popular set of tools used for web application security testing... acts as a proxy...') which Claude already knows, and the flat 'Burp Suite Overview' menu bullet list adds little actionable value, so it is mostly efficient but carries padding.

3 / 5

Actionability

The skill provides copy-paste-ready, executable commands throughout (install, login, connection ensure, connection get --wait, action list/run, request) plus a concrete flag table, covering the common cases clearly.

5 / 5

Workflow Clarity

A clear sequence (install -> authenticate -> ensure connection -> poll until READY -> search actions -> run/proxy) with explicit state-based validation (READY, BUILDING, CLIENT_ACTION_REQUIRED) and feedback loops for re-polling, but the dangling 'skip to Step 2' reference and the oddly labeled '1b' heading leave minor navigation gaps.

4 / 5

Progressive Disclosure

Content is organized into well-labeled sections with clear headers and no nested references, and there are no bundle files to mislink; the inlined Overview menu list and thin 'Popular actions' section are minor organization gaps rather than structural problems.

4 / 5

Total

16

/

20

Passed

Description

66%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description cleanly states a niche (Burp Suite) and includes a usable 'Use when' trigger, but its capability list is generic and the trigger phrasing lacks concrete variations. Strengthening the action verbs and trigger terms would raise specificity and completeness.

Suggestions

Replace generic verbs ('manage data, records, automate workflows') with concrete Burp-specific actions such as 'run scans, review issues, proxy and intercept HTTP traffic, automate Intruder/Repeater workflows'.

Expand the 'when' clause with concrete trigger phrases, e.g. 'Use when the user wants to scan a web app, intercept proxy traffic, review Burp issues, or automate Burp workflows'.

Add common synonyms users say, such as 'web application security testing', 'vulnerability scanning', or 'HTTP proxying', to broaden trigger term coverage.

DimensionReasoningScore

Specificity

The description names the domain ('Burp Suite integration') and lists a few actions ('Manage data, records, and automate workflows'), but the actions are generic rather than concrete Burp-specific operations like scanning, proxying, or analyzing issues.

3 / 5

Completeness

It explicitly provides both a 'what' (manage data, records, automate workflows) and a 'when' ('Use when the user wants to interact with Burp Suite data'), but the 'when' clause is generic rather than tied to concrete trigger phrases.

4 / 5

Trigger Term Quality

'Burp Suite' and 'Burp Suite data' are relevant keywords a user would say, but the description misses common variations, synonyms, or related phrasings such as 'web scanning', 'proxy traffic', or 'vulnerabilities'.

3 / 5

Distinctiveness Conflict Risk

Burp Suite is a specific, well-known security tool, so 'Burp Suite integration' carves a clear niche with distinct triggers and minimal overlap with other skills.

5 / 5

Total

15

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
membranedev/application-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.