docs

MCP tool reference

MCP tool reference

Hugin exposes its tools over MCP. Each tool is an umbrella with many actions — the agent picks the action it needs. This page lists every tool, what it does, and whether it needs Community or Pro.

The exact count grows with each release — run hugin doctor over MCP to see the live inventory for your licence. This page is the reference for what each tool does.

Run hugin mcp to start the MCP server, then point your agent at it.

Flow reading and triage (Community)

ToolWhat it does
hugin_list_flowsList captured HTTP flows with filters (method, host, URL, status, flagged). Supports HTTPQL via filter_expr.
hugin_get_flowGet full details of a flow — request, response, headers, body, intelligence findings.
hugin_search_flowsFull-text search across URL, headers, body, status. Literal/regex/wildcard.
hugin_search_presetsCRUD for saved search presets — list, save, delete, update.
hugin_flow_facetsAggregate flows into (key, count) buckets — status_class, status, host, method, content_type.
hugin_annotate_flowFlag, unflag, highlight, comment, delete, tag flows. Batch operations.
hugin_websocketInspect WebSocket traffic — view connections, read/search messages, send/replay, annotate frames.
hugin_webtransportWebTransport over HTTP/3 session inspection. Refuse / mirror_only modes.

Proxy and intercept (Community)

ToolWhat it does
hugin_interceptMITM intercept control — intercept, inspect, modify, forward, drop requests/responses in real time. Controls flow recording.
hugin_proxy_statusProxy health, stats, CA cert, tunnel/bypass domain list, upstream proxy config.
hugin_scopeProxy scope management — set capture mode (all/in-scope/out-of-scope), record/remove host patterns.
hugin_invisible_proxyTransparent proxy mode — intercept without client-side proxy settings.
hugin_rulesIntercept rules — match by host, path, method, headers, body. CRUD with dry-run.
hugin_logger_filtersFilter presets for HTTP history, capture filter rules, dynamic-tool dispatch filters.

HTTP History and sitemap (Community)

ToolWhat it does
hugin_site_mapExplore captured traffic by host and path — hosts list, path tree, flow lookup.
hugin_sitemapAlias for site_map with same actions and filters.
hugin_dashboardEvent log, active tasks, aggregated stats.

Repeater and Intruder (Community)

ToolWhat it does
hugin_repeaterReplay a single request with modifications. Route through browser fetch() for real TLS fingerprinting.
hugin_intruderFuzz parameters — sniper, battering ram, pitchfork, cluster bomb. Payload sets, processors, match/extract.

Scanner (Community)

ToolWhat it does
hugin_scannerActive scanner with 55 checks. Actions: start, scan_from_url, status, checks, cancel, pause, resume, live_audit, findings CRUD, export, report.
hugin_sqliSQLi scanner — error-based (15+ SQL signatures), time-based blind, boolean-based, OOB. Per-param or per-flow.
hugin_xssReflected XSS scanner — context-aware payloads (HTML, attribute, JS, URL, CSS). Detects unescaped reflection.
hugin_pathtraversalPath traversal fuzzer — 8 encoding variants (plain, URL, double-URL, base64, UTF-16, etc.).
hugin_open_redirectOpen redirect scanner — 30x Location, meta-refresh, JS location redirect param detection.
hugin_uploadFile upload vulnerability scanner — 16 extension variants, 6 content-type bypasses, polyglot, zip-slip.
hugin_pipelineSecurity pipeline — runs flow_analysis → authz → idor → sqli → pathtraversal → xss → bac in sequence.
hugin_live_auditContinuous passive-on-every-flow scanner. Auto-scans each newly captured flow.
hugin_scan_optimizerAI-powered scan priority scoring — analyses endpoints to rank vulnerability likelihood.

Passive analysis (Community)

ToolWhat it does
hugin_intelligenceCross-flow intelligence — params, nerve findings, response intel, client-side signals, CSPT, paramhunter. 7 action modes.
hugin_flow_analysisFlow security analyzer — postMessage handlers, DOM sinks, prototype pollution, source/sink tracing.
hugin_postmessagepostMessage exposure scanner — lists flows with message handlers or postMessage(data, '*').
hugin_sourcemapJavaScript sourcemap disclosure — lists flows with sourceMappingURL=. Fetch + extract secrets.
hugin_dom_invaderDOM Invader — prototype pollution scan, global clobber, postMessage intercept, sink detection.
hugin_engagementSitemap engagement — find scripts, extract forms, analyse per-target structure.
hugin_secretsT16 Secrets / PII classifier — scans response bodies for leaked credentials, API keys, tokens.
hugin_paramhunterParameter signal analysis — maps params to 21 vulnerability categories (IDOR, SQLi, SSRF, CMDi, etc.).

Recon and discovery (Community + Pro)

ToolTierWhat it does
hugin_crawlerCommunityWeb crawler — discover pages, forms, URLs. Static + headless modes.
hugin_discoverCommunityContent discovery — brute-force directories, files, backups. Auto-calibrates wildcard 404s. Recursion.
hugin_ffuzzerCommunityFUZZ keyword fuzzer — ffuf-like. Multi-keyword (cluster bomb, pitchfork, sniper). Raw TCP/TLS or browser mode.
hugin_api_mapCommunityReconstruct API surface from captured traffic — method, path template, params, auth headers.
hugin_api_specCommunityAPI spec auto-discovery — OpenAPI/Swagger, GraphQL introspection, WSDL/SOAP, Docker registry.
hugin_param_discoverCommunityParameter discovery — fuzz hidden/undocumented param names. JS mining for app-specific names.
hugin_fingerprintCommunityTechnology fingerprinting — passive detection of web tech, frameworks, CMS, CDN.
hugin_bundleCommunityBundle Engine — deminify JS, extract hidden endpoints, params, secrets. Feed to scanner.
hugin_assetsCommunityAsset inventory — unified recon database. CRUD with host/ip/source/status/tag/port filters.
hugin_recon_pipelineProRecon pipeline — chains crawl → bundle → intelligence → scanner → BAC → notify in one call.

Decoder and analysis tools (Community)

ToolWhat it does
hugin_smart_decodeEncoder/decoder — encode, decode, multi-step chains. URL, base64, hex, HTML, JWT, and more.
hugin_comparerResponse comparer — diff two responses by flow_id or content. Blind comparison mode.
hugin_sequencerToken randomness — capture tokens, analyse entropy. Session IDs, CSRF tokens, reset tokens.
hugin_hackvertorHackvertor tag pipeline — nested <@base64>...</@base64> tag templates.

Cookies and sessions (Community)

ToolWhat it does
hugin_cookie_jarCookie jar — view, edit, delete, import/export cookies. Parse Set-Cookie from traffic.
hugin_sessionSession management — track tokens, create login macros, auto-refresh sessions.
hugin_macrosSession macros — record, edit, replay multi-step sequences. Token extraction (CSRF, session IDs).
hugin_login_sequenceRecorded login sequences — CDP-driven browser login captured + replayed by scanner on session expiry.
hugin_mfaMFA challenge orchestration — block a login macro until an OOB verification code arrives.
hugin_session_profilesSession profiles — manage auth contexts for BAC testing. Capture and replay with different identities.

Access control (Pro)

ToolWhat it does
hugin_bac_auditBroken Access Control audit — corpus-driven active scanner. Detects role/tenant field leaks, predictable IDs.
hugin_bac_matrixT13 BAC matrix — identity vault, manual matrix_test replay, continuous mode auto-fires on captured flows.
hugin_authzAuthorization matrix scanner — replay flows with different auth contexts (admin, user, no-auth), diff responses.
hugin_idorIDOR scanner — extract parameterized IDs, swap auth, compare responses. Inline findings.
hugin_rbacRole-Based Access Control — users, roles, permissions, audit logging for multi-user environments.

CORS and headers (Community)

ToolWhat it does
hugin_corsCORS misconfiguration scanner — 9 origin probes: null, arbitrary, credential reflection, wildcard with creds.

Browser automation (Pro)

ToolWhat it does
hugin_browserBrowser automation — Chrome (CDP) or Mullvad/Firefox (Marionette) through Hugin proxy. 80+ actions.
hugin_taintDOM XSS taint analysis — headless Chrome traces source→sink data flow. location.hash, postMessage, etc.
hugin_screenshotScreenshot capture for PoC evidence. Uses existing browser session, not a separate headless.
hugin_antibotAnti-bot bypass toolkit — batch_fetch via browser fetch API to bypass WAF/CDN bot detection.
hugin_datadomeDataDome bypass — solve JS interstitial by driving real CDP/Chrome to the page.
hugin_ui_automateFull desktop UI automation — control every interactive element via MCP. Navigation, clicks, typing.

OOB detection (Pro)

ToolWhat it does
hugin_oastifyOOB server — DNS + HTTP listeners. Start, stop, poll, register payloads. Confirms blind SSRF, XXE, SQLi, RCE.

Projects and workspace (Community + Pro)

ToolTierWhat it does
hugin_projectCommunityProject isolation — per-target profiles with isolated scope, flows, recon data.
hugin_environmentCommunityNamed environments and variables — CRUD, activate, duplicate.
hugin_wordlistsCommunityWordlist library — manage saved wordlists. List, preview, search, count, delete.
hugin_filesCommunityPayload file library — add, remove, list, preview, search.
hugin_hostedCommunityPayload files served via proxy at /hosted/{label}.
hugin_collectionsCommunityCollections — curated bundles of HTTP requests with annotations.
hugin_organizerCommunityOrganizer — save, categorize, annotate, search interesting requests for triage.
hugin_session_notesCommunitySession notes — timestamped observations. CRUD with search.
hugin_eventsCommunityEvent log — view, filter, export, manage system events.
hugin_activityCommunityMCP activity audit — query the per-call ring from the dispatch hook.
hugin_collabProReal-time collaboration — share, join, sync sessions, publish scope changes.

Extensions and plugins (Pro)

ToolWhat it does
hugin_extensionsLua extension management — load, unload, enable, disable, test hooks.
hugin_pluginsNative MCP tool plugins — list, install, update, remove, enable, disable, reload.
hugin_synapsSynaps WASM module store — list, install, uninstall, run sandboxed scanner modules.
hugin_bambdaBambda — Lua filter expressions for flow tables. Inline Lua to filter/transform traffic.
hugin_bcheckBCheck DSL — list/validate/run/reload .bcheck declarative scan-check files.
hugin_tools_registryExternal tools registry — list, health check, execute registered external tools.

Workflows and automation (Pro)

ToolWhat it does
hugin_workflowsEvent-driven workflows — triggers + actions for automated flow processing. Passive auto-execute.
hugin_campaignsAutomation campaigns — multi-step intruder attacks with payload sets. Start/pause/resume/stop.
hugin_schedulerScheduled scan jobs — list, create, update, delete, trigger, view run history.
hugin_resource_poolsNamed resource pools — concurrency + RPS + retry. Shared by scanner, intruder, crawler, ratrace.
hugin_orchestrateAI orchestration — explain flows, generate payloads, autonomous exploration with HITL approval.
hugin_orchestration_usageOrchestration usage snapshot — token/cost counters, daily + monthly caps, provider latency.

Race conditions (Pro)

ToolWhat it does
hugin_ratraceRace condition engine — TOCTOU, double-spend, rate-limit bypass. Test, detect, quick, batch, sessions.

Settings and admin (Community)

ToolWhat it does
hugin_settingsSettings — proxy, HTTP, DNS, TLS, Oastify, resource pool, backup, platform auth, scope presets, updates.
hugin_backupSQLite backup management — list, create (VACUUM INTO snapshot), restore, delete.
hugin_user_agentUser-Agent pool — get/set the UA injected into outbound requests.
hugin_license_statusLicense status — tier, account hint, enabled/locked feature matrix.
hugin_tokensAPI access token management — list (masked), create, revoke.
hugin_doctorOne-shot "what's available and working right now" — full tool inventory with MCP tool IDs.
hugin_exportsExport flows and project data in JSON, CSV, or HAR.
hugin_reportingSecurity reports — SARIF 2.1.0, executive summary, styled HTML.

HTTP/3 and SPNEGO (Community + Pro)

ToolTierWhat it does
hugin_http3CommunityHTTP/3 (QUIC) config, analysis, client, Alt-Svc cache that steers egress to HTTP/3.
hugin_spnegoProSPNEGO/NTLM enterprise auth — credentials, token generation, auth session management.
hugin_smuggle_continuousProContinuous smuggling probe — per-origin CL.TE/TE.CL with dedup window.

Assistant (Community)

ToolWhat it does
hugin_assistant_chatOne-shot chat through the legacy Assistant surface. Message + history.
hugin_assistant_list_conversationsList persisted chat conversations (newest first).
hugin_assistant_get_conversationLoad a conversation by id.
hugin_assistant_save_conversationSave a full conversation JSON record.
hugin_assistant_delete_conversationDelete a conversation (idempotent).
hugin_assistant_export_conversationExport as Markdown or JSON.
hugin_assistant_config_getGet Assistant config with API key masked.
hugin_assistant_config_setUpdate Assistant config (API key encrypted at rest).
hugin_assistant_list_explore_toolsList the explore-agent tool registry for autonomous loop.

Platform integrations (Pro)

ToolWhat it does
hugin_platformsBug bounty platforms — manage API keys, sync programs from HackerOne, Bugcrowd, YesWeHack, Intigriti.
hugin_yeswehackYesWeHack deep integration — JWT/TOTP auth, programs, report drafting, CVSS calculator.
hugin_hackeroneHackerOne integration — programs, scopes, weaknesses, report drafting, hacktivity.

vurl — offensive toolkit (Pro)

35 tools for SSRF, request smuggling, cloud exploitation, AI agent RCE, and protocol attacks.

ToolWhat it does
hugin_vurl_httpSend HTTP request with full control over method, headers, body, timeouts, redirects, proxy.
hugin_vurl_http_rawSend raw HTTP request string — smuggling, malformed requests, protocol-level testing.
hugin_vurl_http_compareCompare HTTP responses from two URLs — behavioural differences, timing, content changes.
hugin_vurl_crawlStandalone web crawler using Vurl HTTP engine — works without Hugin proxy. Multiple routing modes.
hugin_vurl_smuggleHTTP request smuggling payloads — CL.TE / TE.CL / TE.TE / HTTP/2 downgrade. Internal host targeting.
hugin_vurl_harvestSmuggleHarvester — continuous smuggling daemon. Rotates techniques, maintains poisoned connections.
hugin_vurl_cloudCloud-metadata SSRF payloads — AWS / Azure / GCP / K8s / Docker / DigitalOcean / Oracle / Alibaba.
hugin_vurl_payloadProtocol-smuggling payloads — Redis, Memcached, SMTP, MySQL, LDAP, FastCGI, GraphQL, XXE, SOAP.
hugin_vurl_redirectOpen-redirect chain payloads — pass vuln_url and target.
hugin_vurl_rebindDNS rebinding URL payloads — xip.io, nip.io, sslip.io.
hugin_vurl_hopbyhopHop-by-hop / Connection / TE / Trailer header tricks for proxy header-stripping.
hugin_vurl_waf_evadeWAF-evasion payload variants — encoding mutations, case, Unicode, comments.
hugin_vurl_charset_rceBest-Fit / charset RCE payloads — Shift-JIS, GBK, Big5, UTF-7.
hugin_vurl_edge_runtimeEdge-runtime attack payloads — Vercel / Cloudflare Workers boundary tricks.
hugin_vurl_hydrationNext.js RSC / hydration hijack payloads.
hugin_vurl_identityOIDC logout / front-channel exploitation payloads.
hugin_vurl_llm_poisonLLM context-poisoning payloads — RAG injection, jailbreaks, system-prompt overwrites.
hugin_vurl_mcp_rceMCP / AI-agent RCE payloads — Langflow, CrewAI, AutoGPT, LangChain, Claude MCP, Gemini. Refuses payloads that target the caller.
hugin_vurl_mcp_rce_crewaiCrewAI agent-framework exploitation payloads.
hugin_vurl_mcp_rce_langflowLangflow agent-framework exploitation payloads.
hugin_vurl_shadow_aiShadow-AI detection / exploitation — browser-side AI integration discovery.
hugin_vurl_rust_http_diffRust HTTP parser differential payloads — proxy-vs-backend desync.
hugin_vurl_rust_panicRust panic-chain DoS / RCE payloads — integer overflow, unsafe triggers.
hugin_vurl_grpc_diffgRPC gateway-vs-backend differential payloads.
hugin_vurl_grpc_webgRPC-Web exploitation payloads.
hugin_vurl_coapCoAP exploitation payloads.
hugin_vurl_mqttMQTT broker exploitation payloads — CVE chains, topic enumeration.
hugin_vurl_quicHTTP/3 + QUIC attack payloads — header smuggling, frame-level abuse.
hugin_vurl_vectordbVector DB attack payloads — Chroma, Milvus, Pinecone, Qdrant, Weaviate.
hugin_vurl_soapSOAP / XML body injection payloads.
hugin_vurl_sharepointSharePoint CVE-2025-53770 payloads.
hugin_vurl_fluentbitFluent Bit CVE-2024-4323 exploitation payloads.
hugin_vurl_ai_gatewayAI gateway bypass encodings.
hugin_vurl_oastifyOOB callback tracking — central hub for all tools. Register payloads, poll for callbacks.
hugin_vurl_modulesEnumerate every offensive vurl payload module. Returns the dispatch table.

Totp (Community)

ToolWhat it does
hugin_totpRFC 6238 TOTP code generator — derive a one-time code from a base32 secret.

Licence decides what an agent sees

Your licence filters the tool list an agent receives. Community gets every tool above that's marked Community. Pro unlocks everything. Run hugin doctor over MCP to see exactly which tools your licence unlocks — the count grows with each release, so don't rely on a number printed here.

Last updated 2026-07-10.