docs

Hugin Findings

Hugin — findings & reporting

Write up and export findings. Load this skill when you have confirmed bugs to report.

Load the tools

Call tools/list with _meta.bundle = "findings". You get: reporting, exports, screenshot.

Load the skill fragment

Read MCP resource hugin://skill/findings for the full workflow + gotchas.

Workflow

  1. Confirm the finding — reproduce it, capture the exact request/response.
  2. Screenshot — call screenshot to capture a screenshot showing the vulnerability.
  3. Write the finding — describe the bug, impact, and reproduction steps.
  4. Export — call exports to export flows and project data (JSON, CSV, HAR).
  5. Report — call reporting for SARIF (CI/CD) or Markdown (bug bounty).

Rules

  • Evidence over assertion — every finding needs a real request/response or OOB callback.
  • Capture the screenshot before the state changes — some bugs are one-shot.
  • Include reproduction steps — the operator or triager needs to verify.
  • Export flows as HAR for completeness — it captures the full request/response chain.