Dual-transport MCP server bridge for Burp Suite Professional supporting both stdio (Claude Code) and HTTP/SSE (OpenAI, Google Gemini) connections. Features self-documentation system, AI discovery tools, enhanced organizer management, advanced session management, native cookie jar integration, proxy history filtering, WebSocket interception, response analysis, managed HTTP jobs, and 24 registered tools focused on Montoya API
The Burp MCP Bridge exposes three security testing tools (burp_add_issue, burp_annotate, burp_bambda) with varying quality. Tool definitions are present with schemas and descriptions, but multiple issues reduce confidence: (1) burp_add_issue has comprehensive schema coverage and clear descriptions for its 17 parameters, making it the strongest tool. (2) burp_annotate uses an enum-driven action pattern with 15 distinct actions, but conflates multiple concerns (annotation operations, searching, auto-annotation rules) into one tool rather than splitting by responsibility, violates single-responsibility principle. (3) burp_bambda supports preset/custom Bambda filters but the 'customScript' parameter lacks format/length constraints and error handling guidance for malformed Java. Common issues across all tools: no pagination guidance for list operations, no documented output schemas (what fields the agent receives), limited error recovery guidance (e.g., what to do if a Burp connection drops), and descriptions assume familiarity with Burp internals rather than explaining plainly when/why to use each tool. Schema definitions are present but descriptions average ~180 chars (within baseline 194 char average), acceptable but could be more prescriptive about prerequisites and recovery paths. No tool includes validation guidance or examples of expected success/failure patterns.
Add custom audit issues to Burp Suite with intelligent dynamic grouping. Use this to report security findings discovered through manual testing or external tools. Automatically groups with existing issues of the same type. Supports detailed evidence including request/response pairs, payloads, remediation guidance, and references. Issues appear in Burp's Target > Issues panel.
Add notes and highlight colors to entries across all Burp Suite components. Use this to mark interesting items, add testing notes, and organize findings visually. Supports Proxy, Target, Organizer, Repeater, Intruder, Scanner, WebSocket, and Collaborator. Actions: ANNOTATE_* (per component), GET_ANNOTATIONS, ANNOTATE_BY_PATTERN (bulk), SEARCH_BY_ANNOTATION, ENABLE/DISABLE_AUTO_ANNOTATION.
Import preset or custom Bambda view filters written in Java. Import success means loaded without native errors; active filter state cannot be verified by this tool. Bambdas are powerful filters written in Java that can filter Proxy history, Site map, and Logger. Actions: APPLY_FILTER (use preset or custom), LIST_PRESETS (available filters), CREATE_CUSTOM (write Java filter), GET_ACTIVE_FILTER (compatibility action; always returns an unsupported error). Presets include: authenticated_requests, api_endpoints, sql_injection_candidates, error_responses, xss_candidates.
burp_annotate violates single-responsibility principle: 15 action enums (ANNOTATE_PROXY, ANNOTATE_TARGET, ..., ENABLE_AUTO_ANNOTATION, DISABLE_AUTO_ANNOTATION) combine distinct concerns (annotating specific components, searching, bulk operations, auto-rules). Should split into separate tools: annotate_entry, search_annotations, configure_auto_annotation.
No output schemas documented for any tool. Agents cannot plan downstream calls without knowing what fields are returned. E.g., burp_add_issue should document: does it return issue_id, issue_key, or both? burp_annotate: what does GET_ANNOTATIONS return (list of entries with notes/colors)? burp_bambda: what does LIST_PRESETS return (array of preset names and descriptions)?
burp_bambda 'customScript' parameter lacks constraints: no max length, no format hint that Java must be valid, no guidance on available bindings (requestResponse, message, node). Description says 'Java filter source returning boolean' but does not explain: what context is available? what imports are included? what exceptions halt compilation? LLM will hallucinate invalid Bambda code.
Inferred effective spec: 2025-06-18+.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | D | 57 | 2025-06-18+ | v2 |
| 2026-03-09 | F | 14 | 2025-06-18+ | v1 |
Error handling absent: no guidance on recovery. burp_add_issue: what happens if URL is malformed or unreachable? burp_annotate: what if entry_id is out of bounds? burp_bambda: what if customScript has syntax errors? Responses should include: retryable vs fatal classification, actionable next steps, and the invalid input/constraint violated (e.g., 'entryId 999 out of range; max is 42').
burp_add_issue: 'requests'/'responses' array parameters accept 'raw request string or object' but schema does not specify the object shape. Description says 'Objects may also include metadata fields like id or notes - only raw/request are required', but schema omits type:object with properties, so parser cannot validate. Use explicit object schema with required ['raw'] and optional ['id', 'notes'] fields.
burp_annotate parameter 'entryId' documentation admits instability: 'Burp's Montoya sitemap exposes no stable id, so this is the current in-memory ordering and is NOT interchangeable with the proxy id.' This makes the parameter unreliable across sessions. Recommend exposing entry lookup by (source, url, method) triple instead, or documenting that entryId is session-scoped only.
No pagination support documented. burp_annotate GET_ANNOTATIONS, burp_bambda LIST_PRESETS, what if there are 1000+ items? No limit/offset params specified. Returning all items wastes tokens and risks context window exhaustion. Implement: limit (default 20-50), offset, and total_count in response.
burp_add_issue 'severity' and 'confidence' parameters default to MEDIUM and FIRM respectively, but no guidance on when to use each. Should add to descriptions: e.g., 'severity HIGH if exploitable in production; INFORMATION for non-exploitable findings like version disclosure.'
burp_bambda description mentions 'Presets include: authenticated_requests, api_endpoints, ...' (5 presets) but enum lists 10 presets: includes 'file_uploads', 'json_endpoints', 'admin_interfaces', 'auth_endpoints', 'interesting_status'. Description should match schema.