Hugin Injection
Hugin — injection testing
Test injection vulnerabilities: SQLi, XSS, path traversal, CORS, open redirect, postMessage, sourcemap, secrets.
Load the tools
Call tools/list with _meta.bundle = "bugclass-injection". You get ~8 tools:
sqli, xss, pathtraversal, open_redirect, cors, postmessage, sourcemap, secrets.
Load the skill fragment
Read MCP resource hugin://skill/bugclass-injection for the full workflow + gotchas.
Workflow
- Identify input-bearing parameters — from orient/paramhunter.
- Run the specific scanner —
sqlifor SQLi,xssfor XSS, etc. - Confirm — send the payload to repeater, verify the response.
- For blind bugs — load the
oobbundle, plant an OOB payload, watch for callbacks. - Prove it — capture the evidence, write the finding.
Rules
- Authorised targets only. Stay in scope.
- Each scanner targets one class — run the ones matching your hypothesis.
- Re-encode payloads through the insertion point's encoding chain.
- CORS errors are common — verify the browser would actually make the cross-origin request.
postmessageexposure is a source, not a bug — trace it to a sink (loadbugclass-domfor DOM XSS).- Secrets in responses are findings — capture the response as evidence.