burp-headless
Warn
Audited by Socket on Aug 12, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
BENIGN for purpose alignment but HIGH RISK in use: it is a legitimate Burp automation skill whose installs and API endpoints mostly match official PortSwigger infrastructure, with no clear credential-harvesting or exfiltration pattern. The main risks are inherent to giving an AI agent autonomous vulnerability-scanning capability and optionally loading third-party Burp extensions/community converters.
Confidence: 91%Severity: 78%
Audit Metadata