Bug-bounty recon with an AI agent
Bug-bounty recon (Chrome through Hugin)
Composes drive-chrome (Hugin-proxied mode) with Hugin's own MCP tools. Authorized
targets only.
Preconditions
- Launch opencode from
~/bugbounty/toolkit/huginso the local-scope proxiedchrome-devtoolsoverride is active (routes through Hugin127.0.0.1:8080). - Hugin must be running on
:8080(Chrome launches lazily; if down, pages won't load). - Confirm the program scope before touching anything. Stay on in-scope hosts.
Flow
-
Verify the path.
list_pages/navigate_pageto a known in-scope URL,take_screenshot, and confirm the request shows up in Hugin (history/sitemap via Hugin's MCP tools). If it doesn't, you're not routed through the proxy — stop and fix. -
Crawl. Drive the target like a user: follow internal links, open the main flows, log in with provided creds if in scope. Use
take_snapshotto map structure; let Hugin capture the JS-heavy traffic a passive proxy misses. -
Exercise client-side. Trigger SPA routes, postMessage flows, form submissions — so Hugin's DOM-XSS / postMessage observation seam records the sinks.
-
Triage with Hugin. Read Hugin's findings/sitemap via its MCP tools; prioritize.
-
Reproduce + PoC. Drive Chrome to reproduce a candidate finding;
take_screenshotfor the report artifact. Capture the exact request/response vialist_network_requests. -
Hunt. After recon has captured flows and mapped endpoints, run the
bug-bounty-huntskill — a systematic 22-phase attack methodology checklist that runs every vulnerability class against what you found. Do not stop at "mapped the target." Break it.
Scope & ethics (hard)
- In-scope hosts only. Consider a local-scope override with
--allowedUrlPattern 'https://*.target.com/*'so an autonomous crawl can't wander out. - Don't defeat anti-bot/WAF. Clicking a real checkbox is fine; engineering human-input emulation to beat DataDome/Cloudflare bot detection is out — it tests the WAF vendor, not the app, and is out of scope. If challenges block testing, get the program to allowlist the test account/IP.
- No destructive actions, no out-of-scope pivoting, no data exfiltration beyond PoC need.
- Note any coverage you bounded (capped depth, skipped a surface) — don't imply full coverage.