docs

MCP Activity

A live record of every MCP tool call and agent run — so you can supervise an AI agent mid-run and audit exactly what it sent to the target.

When you drive Hugin from an AI agent over MCP, MCP Activity is where you watch it work. Every tool the agent calls and every run it makes lands here as it happens, alongside the plugins an agent can reach. It sits in the AI group next to Autopilot, and it is your window onto an agent that sends real requests at a real target. MCP Activity is a Pro feature.

The view has four tabs. A Live / Offline dot in the toolbar tells you whether the feed is streaming.

Tool calls

Every MCP tool call — the name, the arguments, the result, who called it, how long it took, and whether it was allowed.

HTTP flows

The real requests those tools fired at the target — where you confirm an agent stayed in scope.

Agents

Each agent run as a session you can replay step by step.

Plugins

The MCP plugins you have installed that add tools an agent can call.

Tool calls

The Tool Calls tab lists every call as one row: time, tool, action, caller, duration, status, result size, and the error if it failed. Status is one of six outcomes — success, error, timeout, or one of three denies: license denied, read-only denied, permission denied. A call blocked before it ran shows a deny, so an agent reaching past its tier or its permissions stands out at a glance.

The caller marks where the call came from:

Autopilot

Hugin's built-in Copilot and Autopilot — calls from the in-app AI.

Stdio MCP

A client attached over stdio — opencode, Cursor, or Codex through the hugin mcp setup. This is the bucket your editor's agent lands in; filter to it to isolate one client's calls.

External MCP

A client attached over the local socket — another tool, or a second Hugin peer.

Internal

Hugin itself: a workflow, a scheduled job, or another tool.

A row tagged REDACTED with a count means that many argument values were scrubbed before logging. Secrets never reach the log, so it is safe to export. Click any row to open the detail pane: who called it, the permission the call needed, the full arguments with secrets scrubbed (and which keys got scrubbed), and the exact error if it was blocked.

The list shows the 200 most recent matching calls. Narrow the filters, or run the activity MCP tool (activity export) for the full window. Copy All as JSON and Copy All as CSV export exactly what you are looking at.

Confirm it stayed in scope

The HTTP Flows tab shows the actual requests the agent's tools sent — time, method, host, path, status, and latency — with the full request and response for any row you select. An agent that can send requests can send a lot of them, so this is where you check it only touched hosts you are authorised to test. Read it against your scope.

Agents

The Agents tab turns each run into a session you can step through. Runs come in two kinds — Explore, which you steer, and Auto, which runs on its own — and a sub-filter narrows the list to All, Active, Explore, or Auto. Each row carries the task, the run state, when it last moved, and its step count, token use, and estimated cost. Move through the list with j/k or the arrow keys.

Select a session to read its step log: every reasoning step, tool call, checkpoint, budget warning, and error in order, each with its time and duration. The header tallies the steps by kind and tracks the run against its step budget, so you can see a run burning toward its limit. Open any step's raw JSON with the eye, or copy a single step or the whole session.

Export JSON ships the filtered session list. Clear terminated removes every finished session in one click, behind a two-click confirm.

Plugins

The Plugins tab lists the MCP plugins you have installed — extra scanners, browser helpers, and custom tools that an agent or MCP client can call — with each plugin's file name and size. If the tab is empty, open the plugin folder from the tab and drop one in. For full detail on a plugin, run the plugins MCP tool's list action, or hugin plugin mcp list. For Hugin's other extension types — Lua hooks and Synaps scanner modules — see Plugins.

Filter, pause, and export

Search matches tool name, action, and argument summary on the Tool Calls tab, and host, path, or method on the flow lists. The source filter narrows by where the traffic came from. On the Tool Calls tab you can also filter by caller, by any of the six statuses, by project, and flip a redacted-only toggle to show only calls that scrubbed a secret.

When calls are streaming fast, hit Pause tail (shortcut p) to freeze the Tool Calls list so rows stop scrolling past while you read one. The control reads Tail paused until you resume.

Keep MCP Activity open whenever an agent runs. It is your live record of what it sent — check the HTTP Flows tab against your scope, and stop the agent the moment it strays.

Last updated 2026-06-17.