burpsuite-project-parser

Pass

Audited by Gen Agent Trust Hub on May 6, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses a wrapper script skills/scripts/burp-search.sh to execute the Burp Suite Java JAR with a specialized extension. This allows the agent to perform regex searches on HTTP traffic stored locally in .burp files. The execution relies on user-configured environment variables for the Java and Burp paths.
  • [PROMPT_INJECTION]: The skill has an indirect prompt injection surface as it is designed to ingest and analyze HTTP traffic (headers and bodies) from external websites captured in Burp projects.
  • Ingestion points: Untrusted data from project files enters the context via the burp-search.sh script (documented in skills/SKILL.md).
  • Boundary markers: The skill does not use specific boundary delimiters for the ingested content but provides strict instructional guidance on how to search and handle the results.
  • Capability inventory: The skill utilizes shell commands including wc, jq, grep, and head to process and filter the data (specified in skills/SKILL.md).
  • Sanitization: The instructions explicitly mandate the use of head -c 50000 to limit total output size and require the truncation of HTTP response bodies to 1000 characters using jq to mitigate the risk of processing large or malicious payloads (found in skills/SKILL.md).
Audit Metadata
Risk Level
SAFE
Analyzed
May 6, 2026, 02:08 PM
Security Audit — agent-trust-hub — burpsuite-project-parser