CtrlK
BlogDocsLog inGet started
Tessl Logo

testland/burp-headless

Configures and runs headless Burp Suite Professional / Enterprise vulnerability scans (a "Burp scan"): Pro drives scans via its local REST API, Enterprise runs CI-driven scans at scale via its server API; supports BApp Store extensions (BCheck, custom scanners) and authenticated targets via session-handling rules; exports issues as HTML / XML / CSV / JSON or SARIF. Use when the team has a Burp Suite license and wants to run a vulnerability scan with Burp - paid-tier dynamic application security testing (DAST) layered on top of OWASP ZAP.

75

Quality

94%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Overview
Quality
Evals
Security
Files

Quality

Content

85%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, actionable skill body with a clear multi-step workflow, explicit validation checkpoints, and clean one-level-deep progressive disclosure. The only real weakness is conciseness, due to mild concept re-explanation and overlap between the How-to-use list and the Step sections.

Suggestions

Trim the Overview's definitional sentence ('Burp Scanner is a web vulnerability scanning tool...') — Claude already knows what Burp is; keep only the licensing/headless distinction that drives the workflow.

Collapse or cross-reference the 'How to use' numbered list against Steps 1-7 to avoid restating the same sequence twice; consider making 'How to use' a one-line pointer to the steps.

Merge the redundant licensing paragraph in 'Step 1' with the Overview's edition guidance so the Pro-vs-Enterprise framing appears once.

DimensionReasoningScore

Conciseness

Mostly efficient and Burp-specific, but the Overview explains what Burp Scanner is ('a web vulnerability scanning tool built into Burp Suite Professional') — a concept Claude already knows — and the 'How to use' numbered list largely restates the Step 1-7 sections that follow. Could be tightened without losing clarity.

2 / 3

Actionability

Provides copy-paste-ready curl commands for the Pro REST API, a concrete BCheck suppression template with fields, named BApp extensions, and a complete executable GitHub Actions workflow in the referenced file. Fully executable, specific guidance.

3 / 3

Workflow Clarity

Clear 7-step sequence (Step 1-7) with explicit validation checkpoints: license-edition verification (Step 1), MANDATORY false-positive triage with justification/expiry template (Step 6), and CI severity-gating with poll-until-status handling. Matches the clear-sequence-with-validation anchor.

3 / 3

Progressive Disclosure

SKILL.md is an overview with a single one-level-deep reference (references/enterprise-ci.md), clearly signaled inline multiple times and verified to exist; the detailed GitHub Actions workflow is appropriately split out rather than inlined. Easy navigation, no nested references.

3 / 3

Total

11

/

12

Passed

Description

100%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, specific description that answers both what and when, uses natural trigger terms, and carves out a distinct niche against sibling DAST skills. No meaningful gaps relative to the rubric anchors.

DimensionReasoningScore

Specificity

Lists multiple concrete actions: 'Configures and runs headless Burp Suite... scans', 'Pro drives scans via its local REST API', 'Enterprise runs CI-driven scans at scale', 'exports issues as HTML / XML / CSV / JSON or SARIF'. Matches the score-3 anchor of multiple specific concrete actions.

3 / 3

Completeness

Explicitly answers both 'what' (configures/runs scans, supports extensions + auth, exports issues) and 'when' ('Use when the team has a Burp Suite license and wants to run a vulnerability scan with Burp'). Matches the score-3 what-and-when anchor.

3 / 3

Trigger Term Quality

Covers natural terms a user would say: 'vulnerability scan', 'Burp scan', 'Burp Suite', 'DAST', 'BApp Store', 'session-handling rules'. Good coverage of common phrasings, not just jargon.

3 / 3

Distinctiveness Conflict Risk

Occupies a clear niche (paid-tier Burp DAST layered on OWASP ZAP) with distinct triggers tied to a Burp license, and explicitly contrasts sister tools zap-baseline / nightvision-dast, making wrong-skill triggering unlikely.

3 / 3

Total

12

/

12

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Reviewed

Table of Contents