six2dez/burp-mcp-agents ? reverse-engineered prompt

Reverse engineered prompt

Build me a practical toolkit repo for connecting Burp Suite MCP Server to a few AI assistants, like Codex, Gemini, Ollama, and LM Studio.

I want it to be centered on safe, passive security review of real Burp traffic, not scanning or fuzzing. Please include clear setup instructions for each backend, a simple Caddy reverse proxy setup for MCP SSE, and small shell helpers that can start the proxy and the chosen backend together. It should feel easy to follow for someone who is not deeply technical, with one main quick start path and separate folders for each backend.

Also add reusable prompt files for things like passive vulnerability hunting, IDOR and BOLA checks, auth flow mapping, SSRF and redirect ideas, logic flaws, session scope issues, rate limit abuse, and a report writer that turns findings into clean evidence based notes. If something depends on current docs or model settings, look up the latest info online and keep the instructions practical.

Are you gonna build this?

make sure you review the code using coderabbit

Try freeSponsored — opens CodeRabbit in a new tab