No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by Cy-S3c · MCP Server · ★ 172
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is BurpMCP-Ultra safe to install? View the security audit →
BurpMCP-Ultra The most powerful MCP server for Burp Suite Professional. Drop a single JAR into Burp, connect Claude Code (or any MCP client), and drive every part of Burp Suite programmatically through AI agents. 149 Tools • 8 Resources • 17 Event Types • Real-time Dashboard • Hardened Localhost Security Quick Start • Tools • Features • Security • Dashboard • Setup Guides • Contact BurpMCP-Ultra is a native Kotlin Burp Suite extension with an embedded MCP (Model Context Protocol) server. It exposes Burp's Montoya API as 149 structured tools over a token-secured local SSE transport, so an AI agent can run proxy history analysis, activ
| Stars | 172 |
| Forks | 27 |
| Language | Kotlin |
| Category | MCP Server |
| License | MIT |
| Quality Score | 76.3419821375211/100 |
| Open Issues | 4 |
| Last Updated | 2026-08-05 |
| Created | 2026-04-03 |
| Platforms | claude-code, cli, mcp |
| Est. Tokens | ~22k |
These tools work well together with BurpMCP-Ultra for enhanced workflows:
Looking for a BurpMCP-Ultra alternative? If you're comparing BurpMCP-Ultra with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.
Bug bounty agent framework for Claude Code, Codex, Gemini, Cursor, Windsurf, Copilot, and OpenClaw — 48 agents
MCP for Security: A collection of Model Context Protocol servers for popular security tools like SQLMap, FFUF,
MCP server that connects AI assistants to HackerOne for bug bounty hunting
Clean, LLM-optimized Reddit MCP server. Browse posts, search content, analyze users. No fluff, just Reddit dat
A growing collection of MCP servers bringing offensive security tools to AI assistants. Nmap, Ghidra, Nuclei,
一款证据驱动的 FOFA 资产测绘智能体:支持自然语言侦察、AI 反思、CLI / MCP / Skill / REST API,以及经人工审批的 Nuclei 扫描。
Explore other popular mcp server tools:
BurpMCP-Ultra is AI-powered MCP server for Burp Suite Professional — 149 tools across proxy, scanner, inline fuzzer, race conditions, guided injection, JWT/IDOR attacks, recon & OOB, with a real-time dashboard and har. It is categorized as a MCP Server with 172 GitHub stars.
BurpMCP-Ultra is primarily written in Kotlin. It covers topics such as bug-bounty, burpsuite, claude.
You can find installation instructions and usage details in the BurpMCP-Ultra GitHub repository at github.com/Cy-S3c/BurpMCP-Ultra. The project has 172 stars and 27 forks, indicating an active community.
BurpMCP-Ultra is released under the MIT license, making it free to use and modify according to the license terms.
The top alternatives to BurpMCP-Ultra on Agent Skills Hub include pentest-agents, mcp-for-security, h1-brain. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.