Hugin DOM
Hugin — DOM testing
Test DOM-based vulnerabilities: DOM XSS, prototype pollution, postMessage sinks, DOM clobbering. Requires captured traffic or a live browser session.
Load the tools
Call tools/list with _meta.bundle = "bugclass-dom". You get: dom_invader,
dom_implementation, taint.
Load the skill fragment
Read MCP resource hugin://skill/bugclass-dom for the full workflow + gotchas.
Workflow
- Capture traffic — drive the target through Hugin's proxy (load
browserbundle). - Static scan — run
dom_invaderscan_pp / postmessage_probe over captured flows. - Identify sources — postMessage events, URL params, hash fragments that reach sinks.
- Dynamic augment — enable dom_invader augmentation on a live Chrome session for real-time detection.
- Trace — use
taintto trace source→sink data flow in headless Chrome. - Prove it — craft a PoC that reaches the sink with attacker-controlled data.
Rules
- Authorised targets only. Stay in scope.
- DOM bugs need a browser — load the
browserbundle and drive Chrome through Hugin's proxy. - postMessage is a source, not a bug — trace it to a sink (innerHTML, eval, Function, document.write).
- Prototype pollution: check if
__proto__orconstructor.prototypeis writable, then find gadgets. - Taint analysis is expensive — use it on specific pages, not whole crawls.
- Evidence over assertion — show the PoC reaching the sink.