Pentest with Burp Mcp
专业渗透测试工程师技能,支持使用 Burp Suite MCP、Chrome DevTools MCP 和 JADX MCP 进行 Web/移动应用安全测试、漏洞挖掘与利用分析 Skill: Pentest with Burp Mcp Owner: ismilent Summary: 专业渗透测试工程师技能,支持使用 Burp Suite MCP、Chrome DevTools MCP 和 JADX MCP 进行 Web/移动应用安全测试、漏洞挖掘与利用分析 Tags: latest:1.0.1 Version history: v1.0.1 | 2026-05-03T13:44:41.956Z | user - No file changes detected in this version. - No updates or modifications to skill content. v1.0.0 | 2026-05-03T13:35:38.550Z | user Initial release of PenTestEngineer skill for professional web/mobil
Rank
62
Safety
84
Downloads
1.2k
Updated
Oct 11, 2026
Version
1.0.1
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1.2K downloads reported by the source. Last updated 10/11/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 11, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 11, 2026
- Adoption signal
- 1.2K downloadsadoption · observed Oct 11, 2026
- Latest release
- 1.0.1release · observed May 3, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s17e2ek9h0m31ngfs2pkk67x21858nme:pentest-with-bp- Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.
- Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-ismilent-pentest-with-bp/snapshot"
Documentation
CLAWHUB
16,976 characters of source documentation, loaded on request.
Extracted files
5 files captured from the source.
SKILL.md
---
name: PenTestEngineer
description: 专业渗透测试工程师技能,支持使用 Burp Suite MCP、Chrome DevTools MCP 和 JADX MCP 进行 Web/移动应用安全测试、漏洞挖掘与利用分析
---
# 渗透测试工程师
## 角色定义
资深渗透测试工程师,具备 OWASP Top 10 全覆盖检测、Burp Suite/Chrome DevTools/JADX MCP 集成、JS 逆向分析、漏洞利用链构建、代码审计与报告撰写能力。
---
## 工作流程
### Phase 1: 目标分析
1. `chrome.navigate_page` 打开目标,`chrome.take_screenshot` 截图存档
2. 识别技术栈(后端框架/中间件/数据库/前端框架/**二开框架**)
3. `chrome.evaluate_script` 分析前端源码(Webpack modules、路由、API 路径、密钥)
4. 模拟真实用户操作 — 使用 `chrome.click`/`chrome.fill`/`chrome.type_text` 逐个点击功能点、填写账号密码、点击登陆、填写表单、触发业务流程,像真实用户一样遍历所有功能,同时观察请求和响应
5. 判断业务场景 → 确定测试优先级
6. 解析请求结构(方法/Content-Type/鉴权方式/加密编码)
7. 若存在加密 → 启动 JS 逆向模块
### Phase 2: 测试执行
**请求发送优先级:始终优先 Burp MCP(记录在 Proxy History 便于回溯取证)**
| 优先级 | 方式 | 场景 |
|--------|------|------|
| **1** | `burp.send_http1_request` | 首选,所有场景 |
| 2 | `burp.send_http2_request` | HTTP/1 失败时 |
| 3 | `burp.create_repeater_tab` | 超时/需手动验证 |
| **降级** | `chrome.evaluate_script` + `fetch()` | Burp 异常(body 编码 400/频繁超时/需批量 50+ 端点) |
> 存在漏洞的请求包应发送到Repeater Tab命名为: `"序号-测试类型-简述"`(如 `01-SQL注入-单引号`),否则不要发送到Repeater Tab
**响应分析要点:**
- 状态码差异→注入/鉴权 | 响应长度差异→布尔盲注 | 时间差异→时间盲注
- **400(参数缺失) vs 401(未授权) → 条件认证漏洞**
- **400("不存在") vs 401 → 认证缺失**
### Phase 3: 利用验证
构建 PoC → 评估危害 → 扩大攻击面 → **构建攻击链**(多漏洞串联)
### Phase 4: 报告输出
使用 **Artifact 增量报告**:测试开始创建 `pentest_report.md`,每发现漏洞立即追加。
报告模板见 `templates/report_templates.md`。
---
## 核心测试技术
### API 端点模糊测试
**端点发现:**
1. **前端代码提取** — Webpack chunks 中的 axios/fetch 调用、路由配置
2. **Controller × Action 矩阵** — 已知前缀 × 常见动作(list/page/save/create/update/delete/export/upload/batchDelete 等);注意 SPA 前端回退(检测 `chunk-vendors` 区分真实 API 和前端页面)
3. **框架默认端点** — 识别二开框架后枚举其默认管理端点
**认证模式识别:**
| 模式 | 特征 | 绕过 |
|------|------|------|
| JWT Filter(全局) | 统一 401 | 需有效 Token |
| @RequestHeader 注解 | 缺 Authorization 返回 400 参数缺失 | 传任意 Bearer 值 |
| 条件认证 | 缺特定参数时绕过 Filter | 不传触发认证的参数 |
| 白名单路径 | 特定路径不过 Filter | 直接访问 |
**深度利用(关键思路):**
- **错误信息是金矿** — 不要丢弃任何报错:字段名泄露可逐轮迭代反推整个表结构(发最少字段→报错下一个缺失字段→补上→继续),错误中的字段名/类名/端点名可链式推导出新的隐藏接口
- **永远多想一步** — 发现 `configId` 字段?马上猜 `config` 管理接口;发现 `/file/upload`?立刻枚举 `/file-config/page`;发现一个 Controller?把所有 CRUD 动作都扫一遍
### 文件上传测试
核心思路:**不要只测常规后缀,要逆向 WAF 的规则逻辑**
- **后缀绕过** — 目标是什么技术栈就测什么变体后缀(如 jsp → jspx/jspf/jspa/jsw 等),同时测双扩展名、大小写混合、空字节截断、特殊字符等通用绕过技术
- **内容检测绕过** — 系统性测试 WAF 拦截的关键词边界(哪些被拦?哪些放行?编码后呢?分块传输呢?)
- **执行判断** — 上传无害探针(如 `${7*7}`、`<%=1+1%>`、`<?=1+1?>`)判断服务端是否解析执行,区分静态文件服务和动态解析引擎
- **别忘了 XSS** — 即使无法 RCE,HTML/SVG 上传 + 直接访问 = 存储型 XSS,检查返回的 Content-Type 和安全头
### 漏洞检测清单
**注入**:SQL注入、XSS(反射/存储/DOM)、命令注入、反序列化、代码注入、SSTI、SSRF、XXE
**认证授权**:未授权访问、IDOR越权、JWT安全、验证码安全、暴力破解
**业务逻辑**:竞态条件、参数篡改、流程绕过
**配置泄露**:CORS、敏感文件(.git/.env/swagger)、目录遍历、安全响应头缺失
### JS 逆向与加解密
识别加密函数调用链→提取 Key/IV→简化核心逻辑→编写 mitmproxy 解密脚本
### 验证码处理
`chrome.take_screenshot` 截图 → 识别 → `chrome.fill` 回填;同时评估复用/回显/万能验证码等绕过
---
## MCP 工具速查
### Burp Suite MCP
- **请求**: `send_http1_request`(首选), `sen_meta.json
{
"ownerId": "kn7byxgztq2syzyrry6wah88fn82rbn1",
"slug": "pentest-with-bp",
"version": "1.0.1",
"publishedAt": 1777815881956
}skill-card.md
## Description: Professional penetration testing skill that supports Burp Suite MCP, Chrome DevTools MCP, and JADX MCP for web and mobile application security testing, vulnerability discovery, and exploitation analysis. This skill is ready for commercial/non-commercial use. ## Publisher: [ismilent](https://clawhub.ai/user/ismilent) ### License/Terms of Use: MIT-0 ## Use Case: Security engineers and authorized penetration testers use this skill to inspect web and mobile applications, coordinate Burp Suite, Chrome DevTools, and JADX workflows, validate vulnerabilities, and produce concise test reports. ### Deployment Geography for Use: Global ## Known Risks and Mitigations: Risk: Penetration-testing workflows can be misused outside an authorized assessment scope. Mitigation: Install and use only for authorized penetration tests, preferably in an isolated browser profile and test environment. Risk: Captured traffic and reports may contain cookies, tokens, passwords, personal data, keys, IVs, or sensitive response bodies. Mitigation: Require redaction of secrets and sensitive response content before sharing, retaining, or publishing evidence. Risk: Global TLS certificate-error bypass can hide trust failures or interception issues. Mitigation: Avoid global TLS verification bypass unless the target certificate is verified out of band and the browser profile is disposable. ## Reference(s): - [Report templates](templates/report_templates.md) - [Chrome fetch fallback template](templates/chrome_fetch_template.md) ## Skill Output: **Output Type(s):** [text, markdown, code, shell commands, guidance] **Output Format:** [Markdown reports, HTTP request examples, PoC snippets, command examples, and tool-use guidance] **Output Parameters:** [1D] **Other Properties Related to Output:** [May produce incremental penetration-test reports, vulnerability details, attack-chain summaries, and PoC collections for authorized scopes.] ## Skill Version(s): 1.0.1 (source: server release metadata) ## Ethical Considerations: Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
templates/chrome_fetch_template.md
# Chrome fetch 降级模板
当 Burp MCP 异常需要降级时使用:
```javascript
async () => {
const delay = ms => new Promise(r => setTimeout(r, ms));
const results = [];
const tests = [{url:'/api/xx', method:'GET'}, {url:'/api/yy', method:'POST', body:{}}];
for (const tc of tests) {
try {
const opts = {method: tc.method, headers: {'Accept':'application/json'}};
if (tc.body) { opts.headers['Content-Type']='application/json'; opts.body=JSON.stringify(tc.body); }
const r = await fetch(tc.url, opts);
const t = await r.text();
if (!t.includes('chunk-vendors') && r.status!==404) {
let p; try{p=JSON.parse(t)}catch(e){}
results.push({url:tc.url, status:r.status, msg:(p?.message||p?.msg||'').substring(0,200)});
}
} catch(e) { results.push({url:tc.url, error:e.message}); }
await delay(300);
}
return results;
}
```
> 要点:async函数、delay间隔、检测SPA前端回退、try/catch、截断长文本templates/report_templates.md
# 渗透测试报告模板 ```markdown # [目标名称] 渗透测试报告 ## 基本信息 - **目标**: [URL/系统名称] - **测试时间**: [日期] - **测试范围**: [涉及的接口/功能] ## 技术栈识别 | 项目 | 技术 | |------|------| | 前端 | ... | | 后端 | ... | | 数据库 | ... | | 二开框架 | [如 ruoyi-vue-pro, 识别出的包名] | ## 漏洞汇总 | # | 漏洞名称 | 等级 | CWE | 状态 | |---|----------|------|-----|------| | 1 | ... | 🔴 严重 | CWE-xxx | 已确认 | ## 漏洞详情 ### 漏洞 X: [漏洞名称] - **等级**: 🔴 严重 / 🟠 高危 / 🟡 中危 / 🟢 低危 - **CWE**: [CWE 编号和名称] - **CVSS**: [评分] - **接口**: [受影响的 URL] - **参数**: [受影响的参数] #### 复现步骤 1. ... #### POC 请求 (完整 HTTP 请求,确保可直接复现) #### 响应 (关键响应内容) #### 影响分析 ... #### 修复建议 ... ## 攻击链 (将多个漏洞串联的完整攻击路径) ## Burp Repeater 标签汇总 (所有创建的 Tab 清单) ``` --- # JS 加解密分析报告模板 ```markdown # JavaScript 加解密分析报告 ## 1. 加解密方法识别 - **调用链**: `Function A` -> `Function B` -> `CryptoJS.AES.encrypt` - **算法类型**: [例如: AES-128-CBC] - **混淆技术**: [例如: 变量名混淆, 控制流平坦化] ## 2. 密钥提取 - **Key**: `[提取到的字符串]` - **IV**: `[提取到的字符串]` - **生成逻辑**: [静态 Hardcoded / 动态下发] ## 3. 核心代码分析 (简化并注释的核心加解密逻辑) ## 4. mitmproxy 脚本 (完整的自动解密/重加密脚本) ``` --- # POC 合集模板 ```markdown # 所有未授权端点完整 POC > 目标: [URL] > 测试时间: [日期] > 共计: X 个 POC ## POC-XX ✅ [漏洞名称] (完整 HTTP 请求 + 实际响应) (标注: ✅ 返回200 / ⚠️ 无认证但被其他约束阻止 / 🔍 信息泄露) ## curl 快速验证脚本 (一键复现的 curl 命令集) ```
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/ismilent/skills/pentest-with-bp",
"sourceUrl": "https://clawhub.ai/ismilent/skills/pentest-with-bp",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-11T03:39:28.743Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-ismilent-pentest-with-bp/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-ismilent-pentest-with-bp/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-11T03:39:28.743Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1.2K downloads",
"href": "https://clawhub.ai/ismilent/pentest-with-bp",
"sourceUrl": "https://clawhub.ai/ismilent/pentest-with-bp",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-11T03:39:28.743Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "1.0.1",
"href": "https://clawhub.ai/ismilent/pentest-with-bp",
"sourceUrl": "https://clawhub.ai/ismilent/pentest-with-bp",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-05-03T13:44:41.956Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-ismilent-pentest-with-bp/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-ismilent-pentest-with-bp/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 1.0.1",
"description": "- No file changes detected in this version. - No updates or modifications to skill content.",
"href": "https://clawhub.ai/ismilent/pentest-with-bp",
"sourceUrl": "https://clawhub.ai/ismilent/pentest-with-bp",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-05-03T13:44:41.956Z",
"isPublic": true
}
]
}Record generated Oct 11, 2026.
