CtrlK
BlogDocsLog inGet started
Tessl Logo

burp-suite-testing

This skill should be used when the user asks to "intercept HTTP traffic", "modify web requests", "use Burp Suite for testing", "perform web vulnerability scanning", "test with Burp Repeater", "analyze HTTP history", or "configure proxy for web testing". It provides comprehensive guidance for using Burp Suite's core features for web application security testing.

68

Quality

82%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

65%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

Actionable and well-sequenced, but the body is a monolithic wall of text with some conceptual padding and no validation feedback loops for batch operations, and it makes no use of separate reference files.

Suggestions

Trim explanations of Burp feature mechanics Claude already knows and remove 'Result:'/'Finding:' narration to tighten conciseness toward a lean reference.

Add explicit validation/checkpoint steps to the Intruder and automated-scan workflows (e.g. verify scope and rate limits before launching, confirm findings aren't false positives before reporting) to introduce feedback loops.

Move reference material such as the Common Testing Payloads, keyboard shortcuts, and editions comparison into separate files under references/ and link to them from SKILL.md so the body stays an overview.

DimensionReasoningScore

Conciseness

Mostly practical but explains Burp feature mechanics (e.g. 'When ON: Requests pause... When OFF: Requests pass through, logged to history') and adds 'Result:'/'Finding:' narration that Claude largely already knows and could be trimmed.

2 / 3

Actionability

Provides concrete UI navigation paths, copy-paste HTTP request examples (e.g. the /cart price manipulation), payload lists, Intruder § positions, and a keyboard-shortcut table — directly executable.

3 / 3

Workflow Clarity

Six phases are clearly sequenced with numbered steps, but batch/destructive operations (Intruder attacks, automated scans) lack explicit validation or verify-then-proceed checkpoints, which caps clarity at 2.

2 / 3

Progressive Disclosure

No bundle files exist and the >250-line body is monolithic; reference material (payloads, keyboard shortcuts, editions table) sits inline and could be split into linked files, though section organization is good.

2 / 3

Total

9

/

12

Passed

Description

100%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: concrete actions, natural trigger phrasing, explicit when-and-what guidance, and a clear niche tied to Burp Suite.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — 'intercept HTTP traffic', 'modify web requests', 'perform web vulnerability scanning', 'test with Burp Repeater', 'analyze HTTP history', 'configure proxy for web testing' — rather than vague language.

3 / 3

Completeness

Explicitly states what ('provides comprehensive guidance for using Burp Suite's core features for web application security testing') and when ('This skill should be used when the user asks to...').

3 / 3

Trigger Term Quality

Natural phrases a user would actually say are quoted directly, and 'Burp Suite' recurs as the recognizable keyword across several triggers.

3 / 3

Distinctiveness Conflict Risk

Tightly scoped to Burp Suite specifically, with distinct triggers unlikely to fire for unrelated skills.

3 / 3

Total

12

/

12

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
zebbern/claude-code-guide
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.