vurl
The Pro offensive MCP toolkit — 35 tools an AI agent drives to hunt SSRF, request smuggling, WAF bypass, and blind bugs for you. (Pro)
vurl is Hugin's offensive toolkit for an AI agent. Connect an agent over MCP and it gains 35 tools that go at the target directly: SSRF against cloud metadata, HTTP request smuggling, WAF evasion, out-of-band confirmation of blind bugs, and payload generators for modern stacks — Next.js, edge runtimes, AI and LLM services, IoT protocols.
The Community MCP tools let an agent read flows, run the Scanner, and drive Repeater. vurl is the Pro add-on that goes on the offensive. It needs a Pro licence, and it needs the MCP server running — it is an MCP toolkit, so attaching an agent is the only way to reach it.
vurl breaks things. Smuggling poisons shared connections, SSRF reaches internal services, and the harvester captures other users' requests off a desynced socket. Run it only against targets you are explicitly authorised to test, and keep the agent inside scope.
Two kinds of tool
vurl splits into tools that act and tools that generate, and the agent uses them in that order.
- Send tools fire live traffic at the target. They check scope before the first byte leaves, and the requests
vurl_httpandvurl_http_rawsend land in History as flows you can open, replay, or hand to the Scanner — the agent's traffic is captured like any other, not fired off to the side. - Payload tools never touch the target. They hand back attack payloads and wordlists — cloud-metadata URLs, smuggling request bodies, WAF-bypass variants — for the agent to fire through
vurl_http, Repeater, or Intruder. Generate first, then send.
Six tools send; the rest generate. All 35 require the Scan permission, so an agent confined to read-only reaches none of them.
What the agent can reach
vurl_http sends one request with full control — method, headers, body, timeout, redirects, upstream proxy. vurl_http_raw sends a raw request string for smuggling and malformed-protocol tests. vurl_http_compare diffs two URLs' responses for status, length, timing, and content. All three are scope-checked; the first two record what they send in History.
vurl_crawl runs a standalone crawler on vurl's own HTTP engine, so it works with no Hugin proxy in the path. Route it direct, through Hugin, through Mullvad, or a custom proxy, then export the discovered URLs as JSON, CSV, or text.
vurl_smuggle builds CL.TE, TE.CL, TE.TE, and HTTP/2-downgrade payloads aimed at an internal host behind a public Host header. vurl_harvest runs a continuous smuggling daemon — it rotates confirmed techniques, holds poisoned keep-alive connections, and captures the victim requests that land on them, the route to account takeover through stolen session cookies. vurl_hopbyhop, vurl_rust_http_diff, and vurl_grpc_diff cover header-stripping and parser-differential desync.
vurl_cloud generates cloud-metadata SSRF endpoints for AWS, Azure, GCP, Kubernetes, Docker, DigitalOcean, Oracle, and Alibaba; set high_value_only to cut straight to the credential and token endpoints. vurl_payload wraps Redis, Memcached, SMTP, MySQL, LDAP, and FastCGI in gopher:// and matching schemes for SSRF chaining. vurl_rebind builds DNS-rebinding URLs, and vurl_soap builds XML body-injection with an OOB exfil target.
vurl_waf_evade mutates a payload into encoding, case, Unicode, and comment-injection variants to slip a filter — cap it with max_variants before piping into a fuzzer. vurl_charset_rce builds best-fit charset payloads (Shift-JIS, GBK, Big5, UTF-7) for traversal, argument injection, and null-byte tricks.
vurl_redirect chains open redirects from a redirector entry-point. vurl_hydration targets Next.js RSC and hydration hijacking, vurl_edge_runtime hits Vercel and Cloudflare Workers boundary tricks, vurl_identity builds OIDC logout and front-channel payloads, and vurl_quic covers HTTP/3 and QUIC frame abuse.
vurl_mcp_rce builds RCE payloads for agent frameworks — Langflow, CrewAI, AutoGPT, LangChain, OpenAI Assistants, Claude MCP, Gemini, Dify, Flowise — with vurl_mcp_rce_crewai and vurl_mcp_rce_langflow for the framework-specific shapes. vurl_llm_poison covers RAG injection and system-prompt overwrites, vurl_vectordb hits Chroma, Milvus, Pinecone, Qdrant, and Weaviate, vurl_ai_gateway returns prompt encodings to bypass an AI gateway, and vurl_shadow_ai finds browser-side AI integrations.
vurl_mqtt, vurl_coap, and vurl_grpc_web build protocol-specific payloads. vurl_fluentbit (CVE-2024-4323) and vurl_sharepoint (CVE-2025-53770) build payloads for those specific bugs, and vurl_rust_panic builds panic-chain DoS payloads.
vurl_oastify is the OOB callback hub. It registers every payload under a unique marker that encodes the bug class and technique (sq-ubn-a3f2 is union-based SQLi), then correlates incoming callbacks back to the exact payload — the proof that a blind SSRF, XXE, or RCE actually fired.
vurl_modules lists every payload module the server exposes, so an agent can read the catalogue at runtime instead of guessing tool names.
Out-of-band is how blind bugs get confirmed
Most of vurl's payload tools take an OOB target, and on their own they prove nothing — a blind SSRF returns the same empty 200 whether it fired or not. vurl_oastify closes that loop: register the payloads, fire them, then poll for callbacks. A hit ties back to its marker, so the agent knows which input reached the network and which bug class confirmed. Stand up the hub before a smuggling or SSRF run so nothing rests on reading tea leaves in the response body.
A smuggling run, end to end
The way an agent works a desync, using the real tools:
Generate the variants
vurl_smugglebuilds CL.TE, TE.CL, TE.TE, and HTTP/2-downgrade payloads for the host and tags each with its technique.Send them raw
vurl_http_rawfires each variant, in scope, and every attempt lands in History so you can read exactly what went on the wire.Spot the desync
vurl_http_comparediffs a poisoned response against a clean one — a status, length, or timing split is the tell that the front end and back end disagreed.Harvest it
Once a technique confirms,
vurl_harvest startholds the poisoned socket and captures the next user's request. Captured session cookies are the account-takeover proof.
It won't attack Hugin itself
vurl_mcp_rce refuses any payload aimed at a loopback address, Hugin's own MCP server, or the OOB receiver — a denylist that stops an agent turning the toolkit on the host it is running on. The send tools' scope check covers the rest: a request to an out-of-scope host is refused before it leaves, so the agent stays on the engagement.
Drive it from an agent
Activate Pro
vurl is Pro. Both the toolkit and the wider agent campaign surface need a Pro licence active.
Start Hugin with MCP
Run
hugin start --mcpso one daemon holds your project, scope, and any browser sessions for the agent to attach to. See drive Hugin from an AI agent.Point the agent at Hugin
Add Hugin as an MCP server in opencode, Cursor, or Codex — see AI setup. The vurl tools appear alongside the base tools.
Set scope, then ask
Set scope to the target and tell the agent what to hunt — "check this fetch parameter for SSRF to cloud metadata", "try a CL.TE smuggle against this host". It picks the tools, fires them, and brings back what landed in History.
Treat what the agent reports as leads, not a finished report. Confirm anything it flags in Repeater before you write it up.