Awesome MCPSecurity & Reverse Engineering

six2dez/burp-ai-agent

⭐ 1496 Kotlin added to this list on 2026-01-31 repository created 2026-01-27

Burp AI Agent is a sophisticated extension for Burp Suite that integrates advanced AI capabilities into the security testing workflow. It acts as a bridge between Burp Suite and modern AI technologies, enabling users to leverage local AI models or cloud-based AI providers to enhance vulnerability detection and analysis. The extension supports multiple AI backends including Ollama, LM Studio, and various OpenAI-compatible services, as well as CLI-based cloud providers like Gemini, Claude, Codex, and OpenCode. This flexibility allows users to choose the AI backend that best fits their environment and requirements. The extension offers over 53 Model Context Protocol (MCP) tools, allowing external AI agents such as Claude Desktop to autonomously interact with Burp Suite, driving automated security assessments. It includes both passive and active AI-powered scanners that cover 62 different vulnerability classes, ranging from injection flaws to authentication and cryptographic weaknesses. This comprehensive scanning capability helps security professionals identify a wide array of security issues efficiently. Privacy is a key focus of the Burp AI Agent, with three configurable privacy modes (STRICT, BALANCED, OFF) that redact sensitive data before it leaves the Burp environment, ensuring compliance and data protection. Additionally, the extension features audit logging with JSONL format and SHA-256 integrity hashing to support compliance and traceability. Installation is straightforward, with the extension available as a JAR file for easy integration into Burp Suite. Users can configure AI backends through a dedicated settings tab and initiate AI-assisted analysis directly from the Burp Proxy HTTP history interface. The extension also supports MCP server functionality, enabling seamless connection with external AI clients via the Model Context Protocol. Comprehensive documentation is provided, covering installation, configuration, usage, and advanced features. The project is actively maintained under the MIT License, emphasizing responsible use and legal compliance. Overall, Burp AI Agent significantly enhances Burp Suite's capabilities by embedding AI-driven security analysis and automation within the familiar Burp environment.

https://github.com/six2dez/burp-ai-agent

active-scanningaiai-assisted-analysisai-integrationappsecaudit-loggingbugbountyburpburp-extensionsburp-pluginburp-suiteclaude-desktophackingjava-extensionkotlinllmlm-studiomcpmcp-toolsmodel-context-protocolollamaopenai-compatiblepassive-scanningpentestingprivacy-controlssecuritysecurity-testingvulnerability-detectionweb-security

Also in Security & Reverse Engineering

mukul975/Anthropic-Cybersecurity-Skills

A comprehensive open-source library featuring 754 structured cybersecurity skills for AI agents, mapped to five industry frameworks to provide expert-level guidance.

NVIDIA/SkillSpector

NVIDIA security scanner for AI agent skills and MCP tooling that detects prompt injection, data exfiltration, MCP tool poisoning and least-privilege problems, and can itself be run as an MCP server inside agent sessions.

mrexodia/ida-pro-mcp

ida-pro-mcp is an MCP server for IDA Pro that enables advanced reverse engineering capabilities through MCP-based interactions and automation.

LaurieWired/GhidraMCP

GhidraMCP is an MCP server that integrates Ghidra's reverse engineering capabilities with MCP clients, enabling automated binary analysis and decompilation through large language models.

invariantlabs-ai/mcp-scan

MCP-Scan is a security tool that statically and dynamically scans and monitors Model Context Protocol (MCP) connections to detect and prevent vulnerabilities such as prompt injections, tool poisoning, and cross-origin escalations.

zinja-coder/jadx-ai-mcp

JADX-AI-MCP is a JADX plugin integrating Model Context Protocol to enable AI-powered live reverse engineering, vulnerability detection, and code analysis of Android APKs using large language models like Claude.

mariocandela/beelzebub

Beelzebub is a secure low-code honeypot framework leveraging large language models and the Model Context Protocol (MCP) to detect and analyze cyber attacks, including prompt injection attempts against LLM agents.

svnscha/mcp-windbg

mcp-windbg is a Model Context Protocol server that enables AI models to analyze Windows crash dumps using WinDBG through natural language interaction and command execution.