docs

Hugin Browser

Hugin — browser & infrastructure

Drive Chrome through Hugin's proxy, manage authentication, handle anti-bot, configure infrastructure. This is the largest bundle — load it when you need browser automation, auth handling, or infra config.

Load the tools

Call tools/list with _meta.bundle = "browser". You get the browser, auth, and infra tools: browser, screenshot, ui_automate, antibot, datadome, login_sequence, spnego, mfa, totp, cookie_jar, tokens, user_agent, http3, webtransport, websocket, ws_client, invisible_proxy, proxy_status, environment, extensions, plugins, files, hosted, tools_registry, resource_pools, settings, backup, collab, mobile.

Load the skill fragment

Read MCP resource hugin://skill/browser for the full workflow + gotchas.

Workflow

  1. Launch browser — call browser to start Chrome through Hugin's proxy.
  2. Authenticate — set up login_sequence or cookie_jar with a valid session.
  3. Drive — navigate, click, fill forms. Hugin captures all traffic.
  4. Screenshot — call screenshot to capture evidence for findings.
  5. Anti-bot — if blocked, use antibot/datadome (within scope rules).

Rules

  • Authorised targets only. Stay in scope.
  • Don't defeat anti-bot/WAF — clicking a real checkbox is fine; engineering human-input emulation to beat DataDome/Cloudflare is out of scope.
  • login_sequence captures a real browser login once and replays it — set it up before long sessions.
  • cookie_jar manages cookies across requests — use it to maintain sessions.
  • Evidence over assertion — screenshot the vulnerability in action.