BurpSuite MCP Bridge icon

BurpSuite MCP Bridge

Bridge Burp Suite traffic, replay, rewrite rules, and evidence export into Codex through MCP for WSL, Windows, and macOS workflows.

burpsuite-mcp-bridge/burpsuite-mcp-bridge · v2.1.0 · Tools & Integrations

BurpSuite MCP Bridgereview

Trust Score

74

Security

71

Surfaces

2

What is BurpSuite MCP Bridge?

BurpSuite MCP Bridge is a published tools & integrations plugin for AI coding agents in the mcp ecosystem, developed by BurpSuite MCP Bridge and distributed through the HOL AI plugin registry. Bridge Burp Suite traffic, replay, rewrite rules, and evidence export into Codex through MCP for WSL, Windows, and macOS workflows.

Canonical slug
burpsuite-mcp-bridge/burpsuite-mcp-bridge
Version
v2.1.0 · updated Oct 8, 2026

Trust & Reputation

HOL Trust Score
74

Factor Analysis

Per-metric points (0–100 each) combined via a weighted average into the overall score.

Installability
76pts
Maintenance
55pts
MCP Posture
100pts
Plugin Security
71pts
Provenance
70pts
Publisher Quality
75pts

Registry Snapshot

Publisher verification
No
Marketplace source
Unknown
Scanner
Broker fallback
Safety label
review
Digest verified
Yes
1 bundled skill — copy or download SKILL.mdOpen skills

Trust & reputation

Trust & Reputation

HOL Trust Score
74

Factor Analysis

Per-metric points (0–100 each) combined via a weighted average into the overall score.

Installability
76pts
Maintenance
55pts
MCP Posture
100pts
Plugin Security
71pts
Provenance
70pts
Publisher Quality
75pts

Provenance

Plugin root
.
Source repo
https://github.com/6jeffr3y/burpsuite-mcp-bridge
Source commit
05b31bde3532…
Publisher verified
No
Owner verified
Not owner verified

Continuous scanner CI detected

No action is required. This plugin receives the full trust score.

Verified badge not detected

Add the HOL verified badge to the repository README to score +2% trust. Plugin owners can open that pull request from Guard Plugins.

Security Posture

review
Safety label
71
Security score
0
High findings
Provider
registry-broker-fallback
Grade
C · review
Version
Unknown
cisco-skill-scanner: unknown

Findings

mediumpublishabilitypublishability.link.missing.privacyPolicyURL

privacyPolicyURL should be present for marketplace readiness.

mediumpublishabilitypublishability.link.missing.termsOfServiceURL

termsOfServiceURL should be present for marketplace readiness.

lowoperational-securitysupply-chain.lockfile-missing

Repository snapshot does not include a lockfile.

infoskill-securityskill-scan.unavailable

Cisco skill scanner timed out after 60000 ms

BurpSuite MCP Bridge — Frequently asked questions

What is BurpSuite MCP Bridge?
BurpSuite MCP Bridge is an AI plugin in the HOL registry. Bridge Burp Suite traffic, replay, rewrite rules, and evidence export into Codex through MCP for WSL, Windows, and macOS workflows.
How do I install BurpSuite MCP Bridge?
Install BurpSuite MCP Bridge in your harness: Codex — codex plugin marketplace add 6jeffr3y/burpsuite-mcp-bridge; MCP — git clone https://github.com/6jeffr3y/burpsuite-mcp-bridge; Any agent — npx skills add 6jeffr3y/burpsuite-mcp-bridge. Full step-by-step guidance is on the HOL plugin page.
How do I install BurpSuite MCP Bridge in Codex?
To install BurpSuite MCP Bridge in Codex, start with codex plugin marketplace add 6jeffr3y/burpsuite-mcp-bridge. The complete step-by-step install guide for Codex is on the HOL plugin page.
How do I install BurpSuite MCP Bridge in MCP?
To install BurpSuite MCP Bridge in MCP, start with git clone https://github.com/6jeffr3y/burpsuite-mcp-bridge. The complete step-by-step install guide for MCP is on the HOL plugin page.
Is BurpSuite MCP Bridge free?
Pricing for BurpSuite MCP Bridge is published on its HOL plugin page when the maker schedules a launch.
Who publishes BurpSuite MCP Bridge?
BurpSuite MCP Bridge is published by BurpSuite MCP Bridge and listed on HOL.
Is BurpSuite MCP Bridge available now?
BurpSuite MCP Bridge availability is listed on its HOL plugin page.

Install Guidance

Install in Codex

Install through the Codex CLI plugin marketplace.

Codex plugin docs
  1. 1

    Register the marketplace

    Run in any terminal. Codex reads the marketplace entry from .agents/plugins/marketplace.json (or the legacy .claude-plugin path) in the repository. If the repository ships none, add the generated entry from the Advanced section below first.

    shell
  2. 2

    Install from the Plugins browser

    Open Codex, open the Plugins browser, choose the burpsuite-mcp-bridge marketplace, and install burpsuite-mcp-bridge.

  3. 3

    Verify the marketplace registration

    shell

Plugin Manifest

{
  "name": "burpsuite-mcp-bridge",
  "version": "2.1.0",
  "description": "Burp Suite MCP bridge for target-centric traffic triage, marked-flow discovery, time-window search, replay, rewrite automation, selection handoff, and evidence export.",
  "author": {
    "name": "BurpSuite MCP Bridge",
    "email": "[email protected]",
    "url": "https://github.com/6jeffr3y/burpsuite-mcp-bridge"
  },
  "homepage": "https://github.com/6jeffr3y/burpsuite-mcp-bridge",
  "repository": "https://github.com/6jeffr3y/burpsuite-mcp-bridge",
  "license": "Proprietary Runtime Distribution",
  "keywords": [
    "burp",
    "mcp",
    "codex",
    "wsl",
    "windows",
    "montoya",
    "proxy",
    "automation",
    "pentest"
  ],
  "mcpServers": "./.registry/mcp.json",
  "interface": {
    "displayName": "BurpSuite MCP Bridge",
    "developerName": "BurpSuite MCP Bridge",
    "shortDescription": "通过本地 MCP 接口访问 Burp 流量、重放、规则、拦截和证据导出",
    "longDescription": "Burp Suite 本地 MCP Bridge。支持按目标聚合 live/history/logger/selection 流量、按 flow ID 读取完整报文、请求与响应双向拦截、受控重放、Rewrite Rule、BCheck/Bambda 导入以及原始证据导出。Burp Suite 保留流量和原生工具状态的事实来源。",
    "category": "Coding",
    "capabilities": [
      "Read",
      "Write",
      "Interactive"
    ],
    "websiteURL": "https://github.com/6jeffr3y/burpsuite-mcp-bridge",
    "brandColor": "#f97316",
    "composerIcon": "./assets/icon.svg",
    "logo": "./assets/logo.svg",
    "defaultPrompt": [
      "对指定 host 生成 target overview,并优先检查带 comment 或 highlight 的 flow。",
      "读取 Burp 中捕获的 selection,获取完整请求响应并导出原始证据包。",
      "创建包含 max_matches 和 ttl 的临时 rewrite rule,完成验证后禁用或删除。",
      "为指定 host 创建一次性 response intercept,处理一个明确字段后核对后续客户端请求。"
    ]
  },
  "scripts": "./mcp-server/",
  "skills": "./",
  "holManifestOrigin": "repository",
  "registryIndexVersion": 5
}

Marketplace Source

Repo URL
https://github.com/6jeffr3y/burpsuite-mcp-bridge
Marketplace path
Unknown
Source path
plugins/6jeffr3y/burpsuite-mcp-bridge
Install policy
AVAILABLE

Skills

1 SKILL.md file ship with this plugin. Preview, copy, or download each one, then install them with the Skills CLI.

Share
skills-cli
  • use-burpsuite-mcp-bridge

    skills/use-burpsuite-mcp-bridge/SKILL.md

    Operate BurpSuite MCP Bridge for professional, authorized web testing. Use when Codex needs to inspect Burp live/history/logger/selection traffic, prioritize one target, retrieve a decisive request/response, intercept and edit a request or response before forwarding, replay one controlled mutation, manage temporary rewrite rules, import BChecks/Bambdas, export evidence, or diagnose the Windows Burp to WSL MCP connection.

    Raw SKILL.md

File Inventory

.codex-plugin/plugin.json

plugin-manifest

1,906 bytes

08470f96435ae863…

.mcp.json

file

226 bytes

63244a4ea1163f6c…

.registry/mcp.json

mcp-config

149 bytes

d427b8f7e082eb34…

assets/icon.svg

asset

625 bytes

a63436785c217df0…

assets/logo.svg

asset

625 bytes

a63436785c217df0…

README.md

file

10,448 bytes

1a68deb2171050dd…

SECURITY.md

file

508 bytes

46f9b697f2c3b19e…

skills/use-burpsuite-mcp-bridge/agents/openai.yaml

skill

277 bytes

f1dda469d5c1c566…

skills/use-burpsuite-mcp-bridge/references/tool-recipes.md

skill

1,384 bytes

32dbe6dcdc3f16ed…

skills/use-burpsuite-mcp-bridge/references/troubleshooting.md

skill

1,176 bytes

abd5df91368ea1ad…

skills/use-burpsuite-mcp-bridge/SKILL.md

skill

3,856 bytes

9de4521178aa1e47…