a agentk.it Browse tools
Back to Tools
single-tool ยท tool profile

Burp Ai Agent

Burp Suite extension that adds built-in MCP tooling, AI-assisted analysis, privacy controls, passive and active scanning and more

security CodexClaude CodeGeneric
01

At a glance.

A compact read before the deeper capability notes and official setup links.

Fit snapshot
Format SINGLE-TOOL
Category security
CodexClaude CodeGeneric
02

Core features.

Feature cards focus on what the tool helps users do, not generated setup commands.

01

Burp AI Agent is an extension for Burp Suite that integrates AI into your security workflow.

02

Use local models or cloud providers, connect external AI agents via MCP, and let passive/active scanners find vulnerabilities while you focus on manual testing.

03

10 AI Backends โ€” Burp AI (built-in), Ollama, LM Studio, NVIDIA NIM, Generic OpenAI-compatible, Gemini CLI, Claude CLI, Codex CLI, OpenCode CLI, Copilot CLI.

04

53+ MCP Tools โ€” Let Claude Desktop (or any MCP client) drive Burp autonomously.

05

Burp Scan Skill โ€” Use your preferred AI coding assistant (Claude Code, Gemini CLI, Codex, etc.) as a scanner via MCP.

06

The extension auto-installs the bundled profiles into ~/.burp-ai-agent/AGENTS/ on first run.

07

Open the AI Agent tab and go to Settings.

08

Select Extensions > Burp AI Agent > Analyze this request.

04

Agent / Skill / MCP / Workflow fit.

This panel keeps technical format separate from the user-facing AI category.

Tool type SINGLE-TOOL
Use categories security
Works with Codex, Claude Code, Generic
05

Official setup path.

Generated install snippets are intentionally not mirrored here because they drift. The page links to source-owned setup docs instead.

06

Evidence and adoption notes.

These notes help a user decide whether to investigate the official project further.

Source repository last pushed at 2026-05-06T19:00:46Z.

Generated from source metadata; confirm operational details in the official project before adopting it.

Review the upstream license, maintenance activity, and issue history before using it in production.

Trusted source

Trace the origin before adopting.