Hugin Scan
Hugin — scan
Active and passive vulnerability scanning. Let Hugin check an endpoint or corpus automatically.
Load the tools
Call tools/list with _meta.bundle = "scan". You get ~5 tools, ~3.2k tokens:
scanner, scanner_audit_items, scan_optimizer, synaps, live_audit.
Load the skill fragment
Read MCP resource hugin://skill/scan for the full workflow + gotchas.
Workflow
- Choose the target — a flow, a set of flows, or an endpoint.
- Pick a profile — quick, light, normal, thorough, critical-only, stealth.
- Run — call
scanner. It dispatches active checks with concurrency, rate limiting, OOB. - Monitor — findings appear in real-time. Use
scanner_audit_itemsto group by check. - Triage — confirm findings with repeater. False positives get marked.
Rules
- Authorised targets only. Stay in scope.
- Passive analysis (live_audit, flow_analysis) sends no traffic — always safe.
- Active checks send real requests — be deliberate, respect rate limits.
scan_optimizerprioritizes endpoints likely to have bugs — use it for large corpora.- The scanner marks tentative/false_positive findings — don't re-report without confirming.
- Evidence over assertion — reproduce every finding before claiming it.