CtrlK
BlogDocsLog inGet started
Tessl Logo

burp-suite-testing

Execute comprehensive web application security testing using Burp Suite's integrated toolset, including HTTP traffic interception and modification, request analysis and replay, automated vulnerability scanning, and manual testing workflows.

54

Quality

61%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./skills/burp-suite-testing/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

57%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-organized, genuinely actionable guide to Burp Suite testing with an exemplary authorization gate, but it is overweight for a single SKILL.md: generic payloads, shortcut tables, troubleshooting, and examples should be split into reference files, and the batch/offensive phases need explicit validation checkpoints. The workflow cap and the inline-bloat together hold the content score to the middle of the scale.

Suggestions

Move the payload library, keyboard shortcuts, worked examples, and troubleshooting into references/ files (e.g., references/payloads.md, references/troubleshooting.md) linked one level deep from SKILL.md.

Add explicit validation checkpoints to the risky phases: before launching an Intruder attack, verify the target is in scope and rate-limited; after scans/attacks, verify findings against false positives before reporting.

Delete or trim content Claude already knows — the canonical SQLi/XSS/path-traversal payload list and generic explanations like "Scope Benefits" — to tighten token efficiency.

DimensionReasoningScore

Conciseness

The body is mostly tight, procedural, and UI-path-driven, but it spends tokens on things Claude already knows: a "Common Testing Payloads" block of canonical SQLi/XSS/traversal one-liners, generic keyboard-shortcut and editions-comparison tables, and advisory sections like "Scope Benefits". These are unnecessary explanations/padding rather than skill-specific knowledge, matching the anchor for "mostly efficient but includes some unnecessary explanation".

3 / 5

Actionability

Guidance is concrete and directly executable for a GUI-tool skill: exact navigation paths ("Proxy > Intercept tab", "right-click > Send to Intruder"), a worked HTTP request/response example with a concrete before/after body, a filled-in Intruder payload-position example ("username=§admin§&password=§password§"), and scan-configuration tables. It falls short of 5 because several phases (e.g., scan configuration, response analysis) describe what to look at rather than giving specific parameter values or commands.

4 / 5

Workflow Clarity

The six-phase workflow is clearly sequenced with numbered steps, and the authorization confirmation gate at the top is an excellent upfront checkpoint. However, the rubric caps workflow clarity at 3 for batch/destructive operations lacking validation, and the Intruder credential-testing and automated-scan phases include no validate/verify/fail-fast checkpoints — e.g., no step to confirm scope and rate limits before launching an attack, or to verify findings against false positives before reporting.

3 / 5

Progressive Disclosure

The body has clear section headers and a logical overview-to-detail flow, but it is a ~400-line monolith with no bundle files and no references: content that clearly belongs in separate reference files (payload library, keyboard shortcuts, troubleshooting, and the three worked examples) is all inlined. This matches the anchor "some structure but could be better organized; content that should be separate is inline".

3 / 5

Total

13

/

20

Passed

Description

66%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A solid, third-person description with specific, tool-anchored capabilities and strong natural keywords. Its main weakness is the complete absence of a "when to use" trigger clause, which caps completeness and slightly weakens its utility for skill selection.

Suggestions

Append an explicit trigger clause, e.g. "Use when the user asks to test a web application's security, intercept or modify HTTP traffic, or mentions Burp Suite, Burp Repeater, or Burp Intruder."

Add common synonyms such as "penetration testing", "pentest", or "appsec" to widen natural-term coverage.

Mention the deliverable the skill produces (e.g., vulnerability findings with proof-of-concept evidence) to sharpen the "what" beyond a tool feature list.

DimensionReasoningScore

Specificity

The description lists several concrete actions — "HTTP traffic interception and modification", "request analysis and replay", "automated vulnerability scanning, and manual testing workflows" — giving good, specific coverage of the toolset. It stops short of a 5 because it recites the tool's feature list rather than comprehensively describing what the skill itself accomplishes (e.g., vulnerability discovery/proof-of-concept outcomes are only implied).

4 / 5

Completeness

The "what" is clearly stated (execute web application security testing with Burp Suite's toolset), but there is no "Use when..." clause or any equivalent trigger guidance — the description ends after the capability list. Per the judging guidelines, a missing explicit trigger clause caps completeness at 3.

3 / 5

Trigger Term Quality

Strong natural keywords are present: "Burp Suite", "web application security testing", "HTTP traffic interception", "vulnerability scanning" — phrases a user would plausibly say. It misses common synonyms a user might use, such as "penetration testing", "pentest", "appsec", or "web app pentest", keeping it below a 5.

4 / 5

Distinctiveness Conflict Risk

Naming "Burp Suite" carves out a clear niche that would not trigger for unrelated skills, and the tool-specific actions (Proxy/Repeater/Intruder-style work) reinforce it. There is minor overlap risk with closely related skills such as general web-app pentesting or OWASP ZAP testing skills, since the description also opens with the broad phrase "comprehensive web application security testing".

4 / 5

Total

15

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
sickn33/agentic-awesome-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.