docs

Bug-bounty recon with an AI agent

Bug-bounty recon (Chrome through Hugin)

Composes drive-chrome (Hugin-proxied mode) with Hugin's own MCP tools. Authorized targets only.

Preconditions

  • Launch opencode from ~/bugbounty/toolkit/hugin so the local-scope proxied chrome-devtools override is active (routes through Hugin 127.0.0.1:8080).
  • Hugin must be running on :8080 (Chrome launches lazily; if down, pages won't load).
  • Confirm the program scope before touching anything. Stay on in-scope hosts.

Flow

  1. Verify the path. list_pages/navigate_page to a known in-scope URL, take_screenshot, and confirm the request shows up in Hugin (history/sitemap via Hugin's MCP tools). If it doesn't, you're not routed through the proxy — stop and fix.

  2. Crawl. Drive the target like a user: follow internal links, open the main flows, log in with provided creds if in scope. Use take_snapshot to map structure; let Hugin capture the JS-heavy traffic a passive proxy misses.

  3. Exercise client-side. Trigger SPA routes, postMessage flows, form submissions — so Hugin's DOM-XSS / postMessage observation seam records the sinks.

  4. Triage with Hugin. Read Hugin's findings/sitemap via its MCP tools; prioritize.

  5. Reproduce + PoC. Drive Chrome to reproduce a candidate finding; take_screenshot for the report artifact. Capture the exact request/response via list_network_requests.

  6. Hunt. After recon has captured flows and mapped endpoints, run the bug-bounty-hunt skill — a systematic 22-phase attack methodology checklist that runs every vulnerability class against what you found. Do not stop at "mapped the target." Break it.

Scope & ethics (hard)

  • In-scope hosts only. Consider a local-scope override with --allowedUrlPattern 'https://*.target.com/*' so an autonomous crawl can't wander out.
  • Don't defeat anti-bot/WAF. Clicking a real checkbox is fine; engineering human-input emulation to beat DataDome/Cloudflare bot detection is out — it tests the WAF vendor, not the app, and is out of scope. If challenges block testing, get the program to allowlist the test account/IP.
  • No destructive actions, no out-of-scope pivoting, no data exfiltration beyond PoC need.
  • Note any coverage you bounded (capped depth, skipped a surface) — don't imply full coverage.

Last updated 2026-07-10.