docs

Hugin Recon

Hugin — recon

Map the target's attack surface before testing. Crawl, discover, API spec, fingerprint.

Load the tools

Call tools/list with _meta.bundle = "recon". You get ~6 tools, ~6.7k tokens: crawler, discover, api_spec, api_map, fingerprint, assets, bundle, intelligence.

Load the skill fragment

Read MCP resource hugin://skill/recon for the full workflow + gotchas.

Workflow

  1. Confirm scope — call scope (from the default set) to know what's in bounds.
  2. Crawl — call crawler with seed URLs. Use headless mode for JS-heavy targets.
  3. Discover — call discover to brute-force directories and files. Set detect_sinks=true to flag DOM XSS sinks at zero extra request cost.
  4. API spec — call api_spec to probe for OpenAPI/Swagger/GraphQL. Parse into routes + parameters.
  5. API map — call api_map on captured traffic to reconstruct the API surface (free — works on flows you already have).
  6. Fingerprint — call fingerprint to identify the tech stack. Get attack recommendations.
  7. Bundle — call bundle to deminify and mine JS for hidden endpoints and secrets.
  8. Triage — feed results into organizer. Pick high-signal endpoints for replay/scan.

Rules

  • Authorised targets only. Stay in scope.
  • Passive first (no new traffic), active second (discover sends requests).
  • discover with then_scan=true chains into active scanning automatically.
  • Evidence over assertion — a discovered path is not a finding until confirmed reachable.