burp-headless

Warn

Audited by Socket on Aug 12, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

BENIGN for purpose alignment but HIGH RISK in use: it is a legitimate Burp automation skill whose installs and API endpoints mostly match official PortSwigger infrastructure, with no clear credential-harvesting or exfiltration pattern. The main risks are inherent to giving an AI agent autonomous vulnerability-scanning capability and optionally loading third-party Burp extensions/community converters.

Confidence: 91%Severity: 78%
Audit Metadata
Analyzed At
Aug 12, 2026, 10:54 AM
Package URL
pkg:socket/skills-sh/testland%2Fqa%2Fburp-headless%2F@1a49d5eac52963482618e103e13d4a4307ed748d254d91a9a7f3d71c390db34d
Security Audit — socket — burp-headless