docs

Hugin Injection

Hugin — injection testing

Test injection vulnerabilities: SQLi, XSS, path traversal, CORS, open redirect, postMessage, sourcemap, secrets.

Load the tools

Call tools/list with _meta.bundle = "bugclass-injection". You get ~8 tools: sqli, xss, pathtraversal, open_redirect, cors, postmessage, sourcemap, secrets.

Load the skill fragment

Read MCP resource hugin://skill/bugclass-injection for the full workflow + gotchas.

Workflow

  1. Identify input-bearing parameters — from orient/paramhunter.
  2. Run the specific scanner — sqli for SQLi, xss for XSS, etc.
  3. Confirm — send the payload to repeater, verify the response.
  4. For blind bugs — load the oob bundle, plant an OOB payload, watch for callbacks.
  5. Prove it — capture the evidence, write the finding.

Rules

  • Authorised targets only. Stay in scope.
  • Each scanner targets one class — run the ones matching your hypothesis.
  • Re-encode payloads through the insertion point's encoding chain.
  • CORS errors are common — verify the browser would actually make the cross-origin request.
  • postmessage exposure is a source, not a bug — trace it to a sink (load bugclass-dom for DOM XSS).
  • Secrets in responses are findings — capture the response as evidence.