CtrlK
BlogDocsLog inGet started
Tessl Logo

burp-suite-testing

This skill should be used when the user asks to "intercept HTTP traffic", "modify web requests", "use Burp Suite for testing", "perform web vulnerability scanning", "test with Burp Repeater", "analyze HTTP history", or "configure proxy for web testing". It provides comprehensive guidance for using Burp Suite's core features for web application security testing.

56

Quality

63%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./skills/burp-suite-testing/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

57%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a well-structured, genuinely actionable Burp walkthrough with exact UI paths, tables, and worked examples. Its weaknesses are verbosity from generic payload/reference material Claude already knows, missing validation checkpoints in the scan/Intruder batch workflows, and a monolithic single-file layout with no progressive disclosure into reference files.

Suggestions

Move the Common Testing Payloads, Examples, and Troubleshooting sections into references/ files (e.g., references/payloads.md, references/examples.md) and keep SKILL.md as a concise phase-by-phase overview with one-level-deep pointers.

Add explicit validation checkpoints to the batch workflows — e.g., verify scope is set before launching a scan, confirm a canary request is intercepted before starting Intruder, and re-check Issues after each scan with a review-for-false-positives loop.

Trim known-to-Claude material (generic SQLi/XSS payload lists, Scope Benefits prose, window-positioning filler) so every remaining token carries Burp-specific information.

DimensionReasoningScore

Conciseness

The body is mostly tight tables and numbered steps, but includes content Claude already knows — a full "Common Testing Payloads" block of generic SQLi/XSS/traversal payloads — plus padded filler like "Position windows to view both Burp and browser simultaneously" and a "Scope Benefits" bullet list. This matches the mostly-efficient-with-unnecessary-explanation anchor, not 4's only-minor-trim-needed level.

3 / 5

Actionability

Guidance is highly concrete for a GUI tool: exact menu paths ("Proxy > Intercept tab", "Dashboard > New scan"), a copy-paste-ready HTTP example, Intruder payload position/config snippets, keyboard shortcuts, and attack-type tables. A few steps stay vague ("Use filters to focus on relevant traffic", "Configure scan settings"), matching 4's mostly-executable-with-minor-gaps anchor rather than 5's fully-executable coverage of common cases.

4 / 5

Workflow Clarity

The six phases are clearly sequenced, but the batch operations (automated scans, Intruder attacks) have no explicit validation or feedback checkpoints — no verify-scope-before-scanning, no confirm-proxy-working step, no review-and-retry loop. The rubric's scoring note caps workflow clarity at 3 when batch operations lack validation, so this cannot reach 4 despite the clean sequence.

3 / 5

Progressive Disclosure

The single ~370-line SKILL.md has good internal section structure, but everything is inlined — payload lists, worked examples, troubleshooting, and the editions comparison are content that belongs in separate reference files. No bundle files exist (references/, scripts/, assets/ are absent), matching the some-structure-but-inline-content anchor rather than 4's mostly-appropriate placement; the under-50-line simple-skill exception does not apply.

3 / 5

Total

13

/

20

Passed

Description

70%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description has an explicit, natural trigger list strongly anchored to the Burp Suite product, giving it good completeness and low confusion risk. Its main weakness is a generic what-clause ("comprehensive guidance... core features") that pads rather than concretely stating capabilities.

Suggestions

Replace "It provides comprehensive guidance for using Burp Suite's core features" with the concrete capabilities, e.g., "Intercepts and modifies HTTP traffic, replays and fuzzes requests with Repeater and Intruder, runs vulnerability scans, and analyzes HTTP history".

Add a couple of missing natural trigger variations such as "pentest a web app" or "test a web application for vulnerabilities" to broaden natural-phrase coverage.

DimensionReasoningScore

Specificity

The domain is named ("Burp Suite's core features for web application security testing") and the trigger list implicitly names several concrete actions (intercept, modify requests, scan, Repeater, HTTP history, proxy), but the what-clause itself is generic fluff ("provides comprehensive guidance") rather than a list of concrete capabilities. It fits the anchor of naming the domain with concrete actions but not comprehensive stated capabilities, and the guidelines penalize the vague "comprehensive guidance" padding, keeping it below 4.

3 / 5

Completeness

Both parts are present: an explicit when-clause with quoted trigger phrases, and a what-clause (guidance for Burp Suite's core features for web security testing). It matches the anchor where both exist but the what could be more specific; the what is too generic ("comprehensive guidance for core features") to reach 5's fully concrete both-what-and-when anchor.

4 / 5

Trigger Term Quality

Trigger phrases are natural user phrasing ("intercept HTTP traffic", "use Burp Suite for testing", "test with Burp Repeater", "configure proxy for web testing") and include the product name users would say. A few common variations are missing (e.g., "web app pentest", "HTTP proxy testing", "security test a web app"), matching the good-but-not-comprehensive anchor rather than 5's synonym/extension-complete coverage.

4 / 5

Distinctiveness Conflict Risk

The repeated "Burp Suite" and "Burp Repeater" naming establishes a clear niche distinct from generic skills, but broad proxy phrases ("intercept HTTP traffic", "configure proxy for web testing") could overlap with other proxy/traffic-testing skills (e.g., mitmproxy-style skills). Mostly distinct with minor overlap risk — the 4 anchor, not 5's minimal-conflict clear niche.

4 / 5

Total

15

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
zebbern/claude-code-guide
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.