docs

Hugin Replay

Hugin — replay

Replay and tamper requests. This is where you turn "I wonder if this is injectable" into a confirmed answer.

Load the tools

Call tools/list with _meta.bundle = "replay". You get ~10 tools, ~18k tokens: repeater, intercept, macros, hackvertor, comparer, decoder, sequencer, collections, shadow_repeater, smart_decode, rules.

Load the skill fragment

Read MCP resource hugin://skill/replay for the full workflow + gotchas.

Workflow

  1. Pick a flow — from orient, choose one that takes input or handles auth.
  2. Send to repeater — load it, modify one thing, send.
  3. Read the response — what changed? Status, body, headers, timing.
  4. Compare — use comparer to diff responses for blind bugs.
  5. Iterate — tamper one variable at a time. shadow_repeater suggests variants after 3+ sends.
  6. Encode — use hackvertor or decoder to re-encode payloads through the insertion point's chain.

Rules

  • Authorised targets only. Stay in scope.
  • Change one thing at a time — if you change three and the response differs, you don't know which caused it.
  • Use comparer for blind bugs — the body may look identical but differ in length, headers, or timing.
  • Re-encode payloads through the existing encoding chain so they survive the wrapper.
  • Evidence over assertion — capture the exact request/response that proves the bug.