burpsuite-project-parser
Pass
Audited by Gen Agent Trust Hub on May 6, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses a wrapper script
skills/scripts/burp-search.shto execute the Burp Suite Java JAR with a specialized extension. This allows the agent to perform regex searches on HTTP traffic stored locally in.burpfiles. The execution relies on user-configured environment variables for the Java and Burp paths. - [PROMPT_INJECTION]: The skill has an indirect prompt injection surface as it is designed to ingest and analyze HTTP traffic (headers and bodies) from external websites captured in Burp projects.
- Ingestion points: Untrusted data from project files enters the context via the
burp-search.shscript (documented inskills/SKILL.md). - Boundary markers: The skill does not use specific boundary delimiters for the ingested content but provides strict instructional guidance on how to search and handle the results.
- Capability inventory: The skill utilizes shell commands including
wc,jq,grep, andheadto process and filter the data (specified inskills/SKILL.md). - Sanitization: The instructions explicitly mandate the use of
head -c 50000to limit total output size and require the truncation of HTTP response bodies to 1000 characters usingjqto mitigate the risk of processing large or malicious payloads (found inskills/SKILL.md).
Audit Metadata