CtrlK
BlogDocsLog inGet started
Tessl Logo

burp-suite-testing

Execute comprehensive web application security testing using Burp Suite's integrated toolset, including HTTP traffic interception and modification, request analysis and replay, automated vulnerability scanning, and manual testing workflows.

57

Quality

Does it follow best practices?

Impact

No eval scenarios have been run

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

65%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is highly actionable with concrete Burp UI steps and examples, but it is verbose and monolithic, and its batch/destructive workflows lack explicit validation feedback loops.

Suggestions

Add explicit validation checkpoints to batch/destructive workflows, e.g. 'Review Intruder results for anomalies before reporting; re-run with adjusted payloads if no signal is found.'

Move the payload reference, troubleshooting, and examples into separate referenced files to apply progressive disclosure and reduce the SKILL.md token footprint.

Trim the 'Common Testing Payloads' list and other concepts Claude already knows to keep the body lean.

DimensionReasoningScore

Conciseness

The body is mostly efficient procedural UI guidance, but it also includes a payload reference list (' OR '1'='1, <script>alert(1)</script>) and introductory prose that Claude already knows and that could be trimmed.

2 / 3

Actionability

Concrete UI navigation steps ('Go to Proxy > Intercept tab', 'Click Open Browser'), real HTTP request examples, and detailed attack-type/scan-config tables give copy-paste-ready guidance.

3 / 3

Workflow Clarity

The six phases are clearly sequenced with numbered steps, but batch/destructive operations (Intruder brute force, automated scans) lack explicit validate→fix→retry checkpoints, which caps workflow clarity at 2.

2 / 3

Progressive Disclosure

Sections are well organized, but the ~380-line body is monolithic with no external references; payloads, troubleshooting, and examples are inline content that could be split into separate files.

2 / 3

Total

9

/

12

Passed

Description

67%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific and distinctive, clearly tied to Burp Suite with a strong statement of what it does, but it omits an explicit 'Use when…' trigger clause and lacks the natural-term variations that would raise its trigger and completeness scores.

Suggestions

Append an explicit trigger clause, e.g. 'Use when performing web application security testing, pentesting, or vulnerability scanning with Burp Suite.'

Add natural user phrasings such as 'penetration testing', 'pentest', and 'web app pentest' to broaden trigger-term coverage.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — 'HTTP traffic interception and modification, request analysis and replay, automated vulnerability scanning, and manual testing workflows' — matching the score-3 anchor of multiple specific concrete actions.

3 / 3

Completeness

The 'what' is clearly stated, but there is no 'Use when…' clause or equivalent explicit trigger guidance, so per the judging guidelines completeness is capped at 2.

2 / 3

Trigger Term Quality

'Burp Suite', 'web application security testing', and 'vulnerability scanning' are natural terms a user would say, but the description lacks common variations (e.g., 'pentest', 'penetration testing', 'web app pentest') that the score-3 anchor expects.

2 / 3

Distinctiveness Conflict Risk

Naming 'Burp Suite' alongside its integrated toolset gives the skill a clear, distinctive niche that is unlikely to trigger for the wrong skill.

3 / 3

Total

10

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
sickn33/antigravity-awesome-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.