CtrlK
BlogDocsLog inGet started
Tessl Logo

burp-suite-testing

Execute comprehensive web application security testing using Burp Suite's integrated toolset, including HTTP traffic interception and modification, request analysis and replay, automated vulnerability scanning, and manual testing workflows.

45

Quality

47%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./plugins/antigravity-awesome-skills-claude/skills/burp-suite-testing/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

27%Scale 1-3

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

This skill reads more like a comprehensive Burp Suite user manual than a focused skill for Claude. It is excessively verbose, explaining GUI workflows and basic concepts that add little value for an AI assistant that cannot directly interact with Burp Suite's interface. The content would benefit significantly from aggressive trimming, splitting into reference files, and refocusing on what Claude can uniquely contribute (e.g., crafting payloads, analyzing responses, interpreting findings).

Suggestions

Reduce content by at least 60% — remove GUI navigation steps Claude cannot execute, the editions comparison table, scope benefits list, and basic explanations. Focus on payload crafting, response analysis, and vulnerability identification logic.

Split reference material (payloads, keyboard shortcuts, troubleshooting, attack type descriptions) into separate bundle files and reference them from the main SKILL.md.

Add explicit validation checkpoints in the workflow, such as 'Verify authorization scope before scanning' and 'Confirm target is in scope before running Intruder attacks' with feedback loops for when checks fail.

Reframe the skill around what Claude can actually do — help users construct test payloads, analyze HTTP responses for vulnerability indicators, and interpret scan results — rather than documenting Burp Suite's UI navigation.

DimensionReasoningScore

Conciseness

The skill is extremely verbose at ~300+ lines, explaining many concepts Claude already knows (what HTTP history is, what interception means, what Burp Suite editions offer). The editions comparison table, scope benefits list, and extensive troubleshooting section add significant token bloat. Much of this is general Burp Suite documentation rather than actionable delta knowledge.

1 / 3

Actionability

The skill provides step-by-step GUI navigation instructions and some concrete payloads/examples, but since Burp Suite is a GUI tool that Claude cannot directly operate, the actionability is inherently limited. The testing payloads and HTTP request examples are concrete and useful, but much of the content is click-by-click GUI walkthroughs that Claude can only relay, not execute.

2 / 3

Workflow Clarity

The six-phase workflow is clearly sequenced and logically ordered, but it lacks explicit validation checkpoints and feedback loops. For security testing involving potentially destructive operations (scanning, intruder attacks), there are no verification steps like 'confirm authorization before proceeding' at each phase, and no error recovery loops beyond the troubleshooting appendix.

2 / 3

Progressive Disclosure

The entire skill is a monolithic wall of text with no references to external files or bundle resources. Content like the full payload lists, troubleshooting guide, keyboard shortcuts, and detailed intruder configuration could easily be split into separate reference files. With no bundle files provided and no external references, everything is crammed into one long document.

1 / 3

Total

6

/

12

Passed

Description

67%Scale 1-3

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is strong in specificity and distinctiveness, clearly identifying Burp Suite as the tool and listing concrete security testing actions. However, it lacks an explicit 'Use when...' clause, which weakens its completeness score, and could benefit from more natural trigger terms that users commonly use when requesting security testing help.

Suggestions

Add a 'Use when...' clause such as 'Use when the user asks about web security testing, penetration testing, intercepting HTTP requests, or using Burp Suite.'

Include common user-facing trigger terms like 'pentest', 'pen testing', 'web security audit', 'proxy', 'OWASP', and 'intercept requests' to improve keyword coverage.

DimensionReasoningScore

Specificity

Lists multiple specific concrete actions: HTTP traffic interception and modification, request analysis and replay, automated vulnerability scanning, and manual testing workflows. These are clear, actionable capabilities.

3 / 3

Completeness

Clearly answers 'what does this do' with specific capabilities, but lacks an explicit 'Use when...' clause or equivalent trigger guidance, which per the rubric caps completeness at 2.

2 / 3

Trigger Term Quality

Includes good terms like 'Burp Suite', 'security testing', 'HTTP traffic interception', 'vulnerability scanning', but misses common user variations like 'pentest', 'pen testing', 'web security', 'proxy', 'intercept requests', or 'OWASP'.

2 / 3

Distinctiveness Conflict Risk

The mention of 'Burp Suite' specifically and the focus on web application security testing with interception/proxy workflows creates a very clear niche that is unlikely to conflict with other skills.

3 / 3

Total

10

/

12

Passed

Validation

90%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 10 / 11 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

10

/

11

Passed

Repository
popey/claude-code-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.