Hugin Orient
Hugin — get oriented
Starting point for every engagement. Read what's captured, know what's in scope, decide what to test.
Load the tools
Call tools/list with no bundle filter — you get the default set (orient +
scope + meta), ~39 tools, ~24k tokens. That's everything you need to get
oriented without loading the full 165-tool manifest.
Load the skill fragment
Read MCP resource hugin://skill/orient for the full workflow + gotchas.
Read hugin://skill/scope for scope-handling details.
Workflow
- Read scope — call
scopeto see what hosts/URLs are in bounds. Stay in scope. - List flows — call
list_flowsto see captured HTTP history. Filter by host, method, status. - Search — use
search_flowsfor structured queries. Find parameters, auth tokens, errors. - Sitemap — call
site_mapto see traffic organized by host and path. - Triage — flag interesting flows with
annotate_flow, save toorganizer. - Pick targets — identify endpoints that take input or handle auth. Those are where bugs live.
- Decide — based on what you see, pick the next skill (recon, replay, fuzz, scan, a bug class).
Rules
- Authorised targets only. Stay in scope.
- Evidence over assertion — say what you actually saw, not what you assume.
- Passive analysis (flow_analysis) sends no traffic — always safe.
- Don't load more tools than you need. When you move to a new phase, load that bundle.