docs

Hugin Orient

Hugin — get oriented

Starting point for every engagement. Read what's captured, know what's in scope, decide what to test.

Load the tools

Call tools/list with no bundle filter — you get the default set (orient + scope + meta), ~39 tools, ~24k tokens. That's everything you need to get oriented without loading the full 165-tool manifest.

Load the skill fragment

Read MCP resource hugin://skill/orient for the full workflow + gotchas. Read hugin://skill/scope for scope-handling details.

Workflow

  1. Read scope — call scope to see what hosts/URLs are in bounds. Stay in scope.
  2. List flows — call list_flows to see captured HTTP history. Filter by host, method, status.
  3. Search — use search_flows for structured queries. Find parameters, auth tokens, errors.
  4. Sitemap — call site_map to see traffic organized by host and path.
  5. Triage — flag interesting flows with annotate_flow, save to organizer.
  6. Pick targets — identify endpoints that take input or handle auth. Those are where bugs live.
  7. Decide — based on what you see, pick the next skill (recon, replay, fuzz, scan, a bug class).

Rules

  • Authorised targets only. Stay in scope.
  • Evidence over assertion — say what you actually saw, not what you assume.
  • Passive analysis (flow_analysis) sends no traffic — always safe.
  • Don't load more tools than you need. When you move to a new phase, load that bundle.