What an agent can do
The Hugin tool families an AI agent can drive over MCP — from reading flows and Repeater to the Scanner, a real browser, and access-control testing.
Once you connect an agent and point it at Hugin, it can call the same tools you use by hand. They come grouped into families, each an umbrella tool with many actions — the agent picks the action it needs. A fresh agent can call doctor to list every tool its licence unlocks, plus a few starter recipes. Here is what it can reach.
For the full list of every tool and its actions, see the MCP tool reference.
The tool families
List, search, and read History; filter flows, flag the interesting ones, and file findings. Community.
Replay and tamper with a single request as many times as it takes. Community.
Fuzz a request automatically — sniper, battering ram, pitchfork, and cluster bomb. Community.
Run the active and passive checks, or aim a per-class detector: SQLi, XSS, path traversal, open redirect, postMessage, source maps, DOM Invader. Community.
Encode, decode, and hash payloads; diff two responses; test how random a session token really is. Community.
Crawl a target, run content and parameter discovery, surface interesting parameters with Nerve, import an API spec, and fingerprint the stack. api_map works the other way round from a spec import — it rebuilds a host's API surface straight from the traffic you already captured: every method and path, its query and body parameters, the auth headers, and one sample request and response per endpoint. Community; the identity-aware and advanced discovery actions are Pro.
Drive a real browser through more than 80 actions — navigate, click, type, screenshot, run JS, capture network and HAR, harvest cookies, and replay DOM XSS taint. Capture a logged-in session and restore it to bring the browser back after a crash, with cookies and storage intact. Pro.
bac_audit replays a request across identities and roles to expose IDOR and broken access control. Capture each login as a named session profile, replay a single endpoint across every identity to see who can reach it, then run the cross-account IDOR battery — send one identity's action against another identity's object — to confirm horizontal access bugs. Pro.
Catch out-of-band (OOB) callbacks to confirm blind SSRF, XXE, SQLi, and RCE. Pro.
Share a live session and its findings with a team. Pro.
Chain steps into a workflow, run campaigns across many targets, and schedule recurring scans. Pro.
The 35-tool SSRF and request-smuggling toolkit. Pro.
Your licence decides which tools an agent gets: the Community core — flows, Repeater, Intruder, the Scanner, Decoder, Comparer, and Sequencer — on every install, and the Pro families above once a Pro licence is active.