
discover
Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload…

Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload…

Terminal API client for HTTP, GraphQL and gRPC. Plain .http files you can diff and version, with workflows, mocks, profiling, tracing, OpenAPI…

The AI toolkit for building reliable browser automations

Open-source MITM proxy to intercept, inspect, and mock network traffic.

REST/JSON API to the Burp Suite security tool.

Bambdas collection for Burp Suite Professional and Community.

Wireshark for MCP. A transparent proxy that shows every real tool call between your AI client and your MCP servers, live in your terminal.

Exporter is a Burp Suite extension to copy a request to a file or the clipboard as multiple programming languages functions.

Node.js SDK for capturing and replaying API calls made to/from your service

Automated testing suite with live traffic record and replay

Moxy is an open-source DAST tool designed for modern web application security testing. It provides an easy-to-use interface with agentic capabilities…

Web2 bug bounty Agent Skill — evidence-based, no AI slop. Covers 18 vulnerability classes across HackerOne, Bugcrowd, Intigriti, and YesWeHack.

HTTP Proxy Analysis for reverse engineering protocol communication

Ruby command-line interface to Burp Suite's REST API

Collaborative application security testing between humans and agents via CLI and MCP

Extension adds a new tab in Burp Suite called Extractor

API Scraper Agent for Web API's

ExtendedMacro - BurpSuite plugin providing extended macro functionality