BurpMCP-Ultra (Cy-S3c)
AI-powered Burp Suite Pro MCP server with 149 tools for proxy, scanner, fuzzing, race conditions, and JWT/IDOR attacks.
🛡️ AgentReady threat assessment
MAESTRO 7-layer threat model + OWASP AIVSS risk score for BurpMCP-Ultra (Cy-S3c), derived from its capabilities.
These scores are auto-generated from public information (the agent's own listing, docs, and repository) using the canonical OWASP AIVSS formula and the MAESTRO framework — an estimate for guidance, not a penetration test, audit, or certification. See the scoring methodology — every score is re-derived by the same automated method as an agent's public evidence changes.
Overview
BurpMCP-Ultra is an ambitious Burp Suite Professional MCP server exposing 149 tools across proxy, scanner, inline fuzzer, race conditions, guided injection, JWT and IDOR attacks, recon and out-of-band testing, with a real-time dashboard and hardened localhost security. It lets an agent drive Burp end-to-end from Claude Code or any MCP client. The breadth of active-attack tooling makes scope control and localhost hardening essential.
Key features and capabilities
- 149 tools incl. fuzzer, race conditions, JWT/IDOR
- Real-time dashboard
- Hardened localhost security
Use cases
- Agent-driven web-app attack workflows
- Automated fuzzing and injection testing