Hugin Replay
Hugin — replay
Replay and tamper requests. This is where you turn "I wonder if this is injectable" into a confirmed answer.
Load the tools
Call tools/list with _meta.bundle = "replay". You get ~10 tools, ~18k tokens:
repeater, intercept, macros, hackvertor, comparer, decoder, sequencer, collections,
shadow_repeater, smart_decode, rules.
Load the skill fragment
Read MCP resource hugin://skill/replay for the full workflow + gotchas.
Workflow
- Pick a flow — from orient, choose one that takes input or handles auth.
- Send to repeater — load it, modify one thing, send.
- Read the response — what changed? Status, body, headers, timing.
- Compare — use
comparerto diff responses for blind bugs. - Iterate — tamper one variable at a time.
shadow_repeatersuggests variants after 3+ sends. - Encode — use
hackvertorordecoderto re-encode payloads through the insertion point's chain.
Rules
- Authorised targets only. Stay in scope.
- Change one thing at a time — if you change three and the response differs, you don't know which caused it.
- Use
comparerfor blind bugs — the body may look identical but differ in length, headers, or timing. - Re-encode payloads through the existing encoding chain so they survive the wrapper.
- Evidence over assertion — capture the exact request/response that proves the bug.