Burp AI Agent
- Pluggable Backends: Use local models (Ollama, LM Studio), generic OpenAI-compatible providers, or cloud providers (Gemini, Claude, OpenAI/Codex, OpenCode). Add custom backends via drop-in JARs.
Key Features
7 Built-in Backends
Use Cases
- AI-Assisted Analysis: Analyze requests, explain JS, draft PoCs, and generate issue narratives directly from Burp context.
- Local Privacy: Run local models for low-leakage workflows and keep strict redaction controls when using cloud providers.
- MCP Workflows: Connect external MCP clients to Burp and run supervised tool-driven workflows.
- Automated Scanning: Keep passive and active AI scanners running while you focus on manual testing.
- Defensible Operations: Preserve auditable, reproducible prompt bundles with deterministic redaction options.
Operational Guarantees
- Your settings persist across restarts and are migrated safely between versions.
- Passive and active scanners enforce queue/size limits to avoid runaway resource usage.
- Privacy policies are applied before prompt data leaves Burp.
- MCP tools are safety-gated with safe/unsafe controls and per-tool toggles.
- Session history and context size controls help limit token/cost growth.
- Audit logging provides tamper-evident JSONL records for reproducibility workflows.