Hugin Recon
Hugin — recon
Map the target's attack surface before testing. Crawl, discover, API spec, fingerprint.
Load the tools
Call tools/list with _meta.bundle = "recon". You get ~6 tools, ~6.7k tokens:
crawler, discover, api_spec, api_map, fingerprint, assets, bundle, intelligence.
Load the skill fragment
Read MCP resource hugin://skill/recon for the full workflow + gotchas.
Workflow
- Confirm scope — call
scope(from the default set) to know what's in bounds. - Crawl — call
crawlerwith seed URLs. Use headless mode for JS-heavy targets. - Discover — call
discoverto brute-force directories and files. Setdetect_sinks=trueto flag DOM XSS sinks at zero extra request cost. - API spec — call
api_specto probe for OpenAPI/Swagger/GraphQL. Parse into routes + parameters. - API map — call
api_mapon captured traffic to reconstruct the API surface (free — works on flows you already have). - Fingerprint — call
fingerprintto identify the tech stack. Get attack recommendations. - Bundle — call
bundleto deminify and mine JS for hidden endpoints and secrets. - Triage — feed results into
organizer. Pick high-signal endpoints for replay/scan.
Rules
- Authorised targets only. Stay in scope.
- Passive first (no new traffic), active second (discover sends requests).
discoverwiththen_scan=truechains into active scanning automatically.- Evidence over assertion — a discovered path is not a finding until confirmed reachable.