MCP tool reference
MCP tool reference
Hugin exposes its tools over MCP. Each tool is an umbrella with many actions — the agent picks the action it needs. This page lists every tool, what it does, and whether it needs Community or Pro.
The exact count grows with each release — run hugin doctor over MCP to see
the live inventory for your licence. This page is the reference for what
each tool does.
Run hugin mcp to start the MCP server, then point your agent at it.
Flow reading and triage (Community)
| Tool | What it does |
|---|---|
hugin_list_flows | List captured HTTP flows with filters (method, host, URL, status, flagged). Supports HTTPQL via filter_expr. |
hugin_get_flow | Get full details of a flow — request, response, headers, body, intelligence findings. |
hugin_search_flows | Full-text search across URL, headers, body, status. Literal/regex/wildcard. |
hugin_search_presets | CRUD for saved search presets — list, save, delete, update. |
hugin_flow_facets | Aggregate flows into (key, count) buckets — status_class, status, host, method, content_type. |
hugin_annotate_flow | Flag, unflag, highlight, comment, delete, tag flows. Batch operations. |
hugin_websocket | Inspect WebSocket traffic — view connections, read/search messages, send/replay, annotate frames. |
hugin_webtransport | WebTransport over HTTP/3 session inspection. Refuse / mirror_only modes. |
Proxy and intercept (Community)
| Tool | What it does |
|---|---|
hugin_intercept | MITM intercept control — intercept, inspect, modify, forward, drop requests/responses in real time. Controls flow recording. |
hugin_proxy_status | Proxy health, stats, CA cert, tunnel/bypass domain list, upstream proxy config. |
hugin_scope | Proxy scope management — set capture mode (all/in-scope/out-of-scope), record/remove host patterns. |
hugin_invisible_proxy | Transparent proxy mode — intercept without client-side proxy settings. |
hugin_rules | Intercept rules — match by host, path, method, headers, body. CRUD with dry-run. |
hugin_logger_filters | Filter presets for HTTP history, capture filter rules, dynamic-tool dispatch filters. |
HTTP History and sitemap (Community)
| Tool | What it does |
|---|---|
hugin_site_map | Explore captured traffic by host and path — hosts list, path tree, flow lookup. |
hugin_sitemap | Alias for site_map with same actions and filters. |
hugin_dashboard | Event log, active tasks, aggregated stats. |
Repeater and Intruder (Community)
| Tool | What it does |
|---|---|
hugin_repeater | Replay a single request with modifications. Route through browser fetch() for real TLS fingerprinting. |
hugin_intruder | Fuzz parameters — sniper, battering ram, pitchfork, cluster bomb. Payload sets, processors, match/extract. |
Scanner (Community)
| Tool | What it does |
|---|---|
hugin_scanner | Active scanner with 55 checks. Actions: start, scan_from_url, status, checks, cancel, pause, resume, live_audit, findings CRUD, export, report. |
hugin_sqli | SQLi scanner — error-based (15+ SQL signatures), time-based blind, boolean-based, OOB. Per-param or per-flow. |
hugin_xss | Reflected XSS scanner — context-aware payloads (HTML, attribute, JS, URL, CSS). Detects unescaped reflection. |
hugin_pathtraversal | Path traversal fuzzer — 8 encoding variants (plain, URL, double-URL, base64, UTF-16, etc.). |
hugin_open_redirect | Open redirect scanner — 30x Location, meta-refresh, JS location redirect param detection. |
hugin_upload | File upload vulnerability scanner — 16 extension variants, 6 content-type bypasses, polyglot, zip-slip. |
hugin_pipeline | Security pipeline — runs flow_analysis → authz → idor → sqli → pathtraversal → xss → bac in sequence. |
hugin_live_audit | Continuous passive-on-every-flow scanner. Auto-scans each newly captured flow. |
hugin_scan_optimizer | AI-powered scan priority scoring — analyses endpoints to rank vulnerability likelihood. |
Passive analysis (Community)
| Tool | What it does |
|---|---|
hugin_intelligence | Cross-flow intelligence — params, nerve findings, response intel, client-side signals, CSPT, paramhunter. 7 action modes. |
hugin_flow_analysis | Flow security analyzer — postMessage handlers, DOM sinks, prototype pollution, source/sink tracing. |
hugin_postmessage | postMessage exposure scanner — lists flows with message handlers or postMessage(data, '*'). |
hugin_sourcemap | JavaScript sourcemap disclosure — lists flows with sourceMappingURL=. Fetch + extract secrets. |
hugin_dom_invader | DOM Invader — prototype pollution scan, global clobber, postMessage intercept, sink detection. |
hugin_engagement | Sitemap engagement — find scripts, extract forms, analyse per-target structure. |
hugin_secrets | T16 Secrets / PII classifier — scans response bodies for leaked credentials, API keys, tokens. |
hugin_paramhunter | Parameter signal analysis — maps params to 21 vulnerability categories (IDOR, SQLi, SSRF, CMDi, etc.). |
Recon and discovery (Community + Pro)
| Tool | Tier | What it does |
|---|---|---|
hugin_crawler | Community | Web crawler — discover pages, forms, URLs. Static + headless modes. |
hugin_discover | Community | Content discovery — brute-force directories, files, backups. Auto-calibrates wildcard 404s. Recursion. |
hugin_ffuzzer | Community | FUZZ keyword fuzzer — ffuf-like. Multi-keyword (cluster bomb, pitchfork, sniper). Raw TCP/TLS or browser mode. |
hugin_api_map | Community | Reconstruct API surface from captured traffic — method, path template, params, auth headers. |
hugin_api_spec | Community | API spec auto-discovery — OpenAPI/Swagger, GraphQL introspection, WSDL/SOAP, Docker registry. |
hugin_param_discover | Community | Parameter discovery — fuzz hidden/undocumented param names. JS mining for app-specific names. |
hugin_fingerprint | Community | Technology fingerprinting — passive detection of web tech, frameworks, CMS, CDN. |
hugin_bundle | Community | Bundle Engine — deminify JS, extract hidden endpoints, params, secrets. Feed to scanner. |
hugin_assets | Community | Asset inventory — unified recon database. CRUD with host/ip/source/status/tag/port filters. |
hugin_recon_pipeline | Pro | Recon pipeline — chains crawl → bundle → intelligence → scanner → BAC → notify in one call. |
Decoder and analysis tools (Community)
| Tool | What it does |
|---|---|
hugin_smart_decode | Encoder/decoder — encode, decode, multi-step chains. URL, base64, hex, HTML, JWT, and more. |
hugin_comparer | Response comparer — diff two responses by flow_id or content. Blind comparison mode. |
hugin_sequencer | Token randomness — capture tokens, analyse entropy. Session IDs, CSRF tokens, reset tokens. |
hugin_hackvertor | Hackvertor tag pipeline — nested <@base64>...</@base64> tag templates. |
Cookies and sessions (Community)
| Tool | What it does |
|---|---|
hugin_cookie_jar | Cookie jar — view, edit, delete, import/export cookies. Parse Set-Cookie from traffic. |
hugin_session | Session management — track tokens, create login macros, auto-refresh sessions. |
hugin_macros | Session macros — record, edit, replay multi-step sequences. Token extraction (CSRF, session IDs). |
hugin_login_sequence | Recorded login sequences — CDP-driven browser login captured + replayed by scanner on session expiry. |
hugin_mfa | MFA challenge orchestration — block a login macro until an OOB verification code arrives. |
hugin_session_profiles | Session profiles — manage auth contexts for BAC testing. Capture and replay with different identities. |
Access control (Pro)
| Tool | What it does |
|---|---|
hugin_bac_audit | Broken Access Control audit — corpus-driven active scanner. Detects role/tenant field leaks, predictable IDs. |
hugin_bac_matrix | T13 BAC matrix — identity vault, manual matrix_test replay, continuous mode auto-fires on captured flows. |
hugin_authz | Authorization matrix scanner — replay flows with different auth contexts (admin, user, no-auth), diff responses. |
hugin_idor | IDOR scanner — extract parameterized IDs, swap auth, compare responses. Inline findings. |
hugin_rbac | Role-Based Access Control — users, roles, permissions, audit logging for multi-user environments. |
CORS and headers (Community)
| Tool | What it does |
|---|---|
hugin_cors | CORS misconfiguration scanner — 9 origin probes: null, arbitrary, credential reflection, wildcard with creds. |
Browser automation (Pro)
| Tool | What it does |
|---|---|
hugin_browser | Browser automation — Chrome (CDP) or Mullvad/Firefox (Marionette) through Hugin proxy. 80+ actions. |
hugin_taint | DOM XSS taint analysis — headless Chrome traces source→sink data flow. location.hash, postMessage, etc. |
hugin_screenshot | Screenshot capture for PoC evidence. Uses existing browser session, not a separate headless. |
hugin_antibot | Anti-bot bypass toolkit — batch_fetch via browser fetch API to bypass WAF/CDN bot detection. |
hugin_datadome | DataDome bypass — solve JS interstitial by driving real CDP/Chrome to the page. |
hugin_ui_automate | Full desktop UI automation — control every interactive element via MCP. Navigation, clicks, typing. |
OOB detection (Pro)
| Tool | What it does |
|---|---|
hugin_oastify | OOB server — DNS + HTTP listeners. Start, stop, poll, register payloads. Confirms blind SSRF, XXE, SQLi, RCE. |
Projects and workspace (Community + Pro)
| Tool | Tier | What it does |
|---|---|---|
hugin_project | Community | Project isolation — per-target profiles with isolated scope, flows, recon data. |
hugin_environment | Community | Named environments and variables — CRUD, activate, duplicate. |
hugin_wordlists | Community | Wordlist library — manage saved wordlists. List, preview, search, count, delete. |
hugin_files | Community | Payload file library — add, remove, list, preview, search. |
hugin_hosted | Community | Payload files served via proxy at /hosted/{label}. |
hugin_collections | Community | Collections — curated bundles of HTTP requests with annotations. |
hugin_organizer | Community | Organizer — save, categorize, annotate, search interesting requests for triage. |
hugin_session_notes | Community | Session notes — timestamped observations. CRUD with search. |
hugin_events | Community | Event log — view, filter, export, manage system events. |
hugin_activity | Community | MCP activity audit — query the per-call ring from the dispatch hook. |
hugin_collab | Pro | Real-time collaboration — share, join, sync sessions, publish scope changes. |
Extensions and plugins (Pro)
| Tool | What it does |
|---|---|
hugin_extensions | Lua extension management — load, unload, enable, disable, test hooks. |
hugin_plugins | Native MCP tool plugins — list, install, update, remove, enable, disable, reload. |
hugin_synaps | Synaps WASM module store — list, install, uninstall, run sandboxed scanner modules. |
hugin_bambda | Bambda — Lua filter expressions for flow tables. Inline Lua to filter/transform traffic. |
hugin_bcheck | BCheck DSL — list/validate/run/reload .bcheck declarative scan-check files. |
hugin_tools_registry | External tools registry — list, health check, execute registered external tools. |
Workflows and automation (Pro)
| Tool | What it does |
|---|---|
hugin_workflows | Event-driven workflows — triggers + actions for automated flow processing. Passive auto-execute. |
hugin_campaigns | Automation campaigns — multi-step intruder attacks with payload sets. Start/pause/resume/stop. |
hugin_scheduler | Scheduled scan jobs — list, create, update, delete, trigger, view run history. |
hugin_resource_pools | Named resource pools — concurrency + RPS + retry. Shared by scanner, intruder, crawler, ratrace. |
hugin_orchestrate | AI orchestration — explain flows, generate payloads, autonomous exploration with HITL approval. |
hugin_orchestration_usage | Orchestration usage snapshot — token/cost counters, daily + monthly caps, provider latency. |
Race conditions (Pro)
| Tool | What it does |
|---|---|
hugin_ratrace | Race condition engine — TOCTOU, double-spend, rate-limit bypass. Test, detect, quick, batch, sessions. |
Settings and admin (Community)
| Tool | What it does |
|---|---|
hugin_settings | Settings — proxy, HTTP, DNS, TLS, Oastify, resource pool, backup, platform auth, scope presets, updates. |
hugin_backup | SQLite backup management — list, create (VACUUM INTO snapshot), restore, delete. |
hugin_user_agent | User-Agent pool — get/set the UA injected into outbound requests. |
hugin_license_status | License status — tier, account hint, enabled/locked feature matrix. |
hugin_tokens | API access token management — list (masked), create, revoke. |
hugin_doctor | One-shot "what's available and working right now" — full tool inventory with MCP tool IDs. |
hugin_exports | Export flows and project data in JSON, CSV, or HAR. |
hugin_reporting | Security reports — SARIF 2.1.0, executive summary, styled HTML. |
HTTP/3 and SPNEGO (Community + Pro)
| Tool | Tier | What it does |
|---|---|---|
hugin_http3 | Community | HTTP/3 (QUIC) config, analysis, client, Alt-Svc cache that steers egress to HTTP/3. |
hugin_spnego | Pro | SPNEGO/NTLM enterprise auth — credentials, token generation, auth session management. |
hugin_smuggle_continuous | Pro | Continuous smuggling probe — per-origin CL.TE/TE.CL with dedup window. |
Assistant (Community)
| Tool | What it does |
|---|---|
hugin_assistant_chat | One-shot chat through the legacy Assistant surface. Message + history. |
hugin_assistant_list_conversations | List persisted chat conversations (newest first). |
hugin_assistant_get_conversation | Load a conversation by id. |
hugin_assistant_save_conversation | Save a full conversation JSON record. |
hugin_assistant_delete_conversation | Delete a conversation (idempotent). |
hugin_assistant_export_conversation | Export as Markdown or JSON. |
hugin_assistant_config_get | Get Assistant config with API key masked. |
hugin_assistant_config_set | Update Assistant config (API key encrypted at rest). |
hugin_assistant_list_explore_tools | List the explore-agent tool registry for autonomous loop. |
Platform integrations (Pro)
| Tool | What it does |
|---|---|
hugin_platforms | Bug bounty platforms — manage API keys, sync programs from HackerOne, Bugcrowd, YesWeHack, Intigriti. |
hugin_yeswehack | YesWeHack deep integration — JWT/TOTP auth, programs, report drafting, CVSS calculator. |
hugin_hackerone | HackerOne integration — programs, scopes, weaknesses, report drafting, hacktivity. |
vurl — offensive toolkit (Pro)
35 tools for SSRF, request smuggling, cloud exploitation, AI agent RCE, and protocol attacks.
| Tool | What it does |
|---|---|
hugin_vurl_http | Send HTTP request with full control over method, headers, body, timeouts, redirects, proxy. |
hugin_vurl_http_raw | Send raw HTTP request string — smuggling, malformed requests, protocol-level testing. |
hugin_vurl_http_compare | Compare HTTP responses from two URLs — behavioural differences, timing, content changes. |
hugin_vurl_crawl | Standalone web crawler using Vurl HTTP engine — works without Hugin proxy. Multiple routing modes. |
hugin_vurl_smuggle | HTTP request smuggling payloads — CL.TE / TE.CL / TE.TE / HTTP/2 downgrade. Internal host targeting. |
hugin_vurl_harvest | SmuggleHarvester — continuous smuggling daemon. Rotates techniques, maintains poisoned connections. |
hugin_vurl_cloud | Cloud-metadata SSRF payloads — AWS / Azure / GCP / K8s / Docker / DigitalOcean / Oracle / Alibaba. |
hugin_vurl_payload | Protocol-smuggling payloads — Redis, Memcached, SMTP, MySQL, LDAP, FastCGI, GraphQL, XXE, SOAP. |
hugin_vurl_redirect | Open-redirect chain payloads — pass vuln_url and target. |
hugin_vurl_rebind | DNS rebinding URL payloads — xip.io, nip.io, sslip.io. |
hugin_vurl_hopbyhop | Hop-by-hop / Connection / TE / Trailer header tricks for proxy header-stripping. |
hugin_vurl_waf_evade | WAF-evasion payload variants — encoding mutations, case, Unicode, comments. |
hugin_vurl_charset_rce | Best-Fit / charset RCE payloads — Shift-JIS, GBK, Big5, UTF-7. |
hugin_vurl_edge_runtime | Edge-runtime attack payloads — Vercel / Cloudflare Workers boundary tricks. |
hugin_vurl_hydration | Next.js RSC / hydration hijack payloads. |
hugin_vurl_identity | OIDC logout / front-channel exploitation payloads. |
hugin_vurl_llm_poison | LLM context-poisoning payloads — RAG injection, jailbreaks, system-prompt overwrites. |
hugin_vurl_mcp_rce | MCP / AI-agent RCE payloads — Langflow, CrewAI, AutoGPT, LangChain, Claude MCP, Gemini. Refuses payloads that target the caller. |
hugin_vurl_mcp_rce_crewai | CrewAI agent-framework exploitation payloads. |
hugin_vurl_mcp_rce_langflow | Langflow agent-framework exploitation payloads. |
hugin_vurl_shadow_ai | Shadow-AI detection / exploitation — browser-side AI integration discovery. |
hugin_vurl_rust_http_diff | Rust HTTP parser differential payloads — proxy-vs-backend desync. |
hugin_vurl_rust_panic | Rust panic-chain DoS / RCE payloads — integer overflow, unsafe triggers. |
hugin_vurl_grpc_diff | gRPC gateway-vs-backend differential payloads. |
hugin_vurl_grpc_web | gRPC-Web exploitation payloads. |
hugin_vurl_coap | CoAP exploitation payloads. |
hugin_vurl_mqtt | MQTT broker exploitation payloads — CVE chains, topic enumeration. |
hugin_vurl_quic | HTTP/3 + QUIC attack payloads — header smuggling, frame-level abuse. |
hugin_vurl_vectordb | Vector DB attack payloads — Chroma, Milvus, Pinecone, Qdrant, Weaviate. |
hugin_vurl_soap | SOAP / XML body injection payloads. |
hugin_vurl_sharepoint | SharePoint CVE-2025-53770 payloads. |
hugin_vurl_fluentbit | Fluent Bit CVE-2024-4323 exploitation payloads. |
hugin_vurl_ai_gateway | AI gateway bypass encodings. |
hugin_vurl_oastify | OOB callback tracking — central hub for all tools. Register payloads, poll for callbacks. |
hugin_vurl_modules | Enumerate every offensive vurl payload module. Returns the dispatch table. |
Totp (Community)
| Tool | What it does |
|---|---|
hugin_totp | RFC 6238 TOTP code generator — derive a one-time code from a base32 secret. |
Licence decides what an agent sees
Your licence filters the tool list an agent receives. Community gets every tool
above that's marked Community. Pro unlocks everything. Run hugin doctor over
MCP to see exactly which tools your licence unlocks — the count grows with
each release, so don't rely on a number printed here.