Hugin Vurl
Hugin — vurl offensive toolkit
Pro offensive toolkit: 35+ specialized attack tools for HTTP desync, SSRF, MCP/LLM framework attacks, cloud metadata, and more. Pro only.
Load the tools
Call tools/list with _meta.bundle = "vurl". You get all 36 vurl_* tools.
Load the skill fragment
Read MCP resource hugin://skill/vurl for the full workflow + gotchas.
Workflow
- Identify the attack surface — from recon, find endpoints that process URLs, headers, or external input.
- Generate payloads — call the relevant
vurl_*tool to generate attack payloads for the specific class. - Inject — place payloads via repeater or intruder.
- Confirm — use
vurl_oastifyfor OOB confirmation, orvurl_http_comparefor response diffs. - Prove it — capture the evidence.
Key tools
vurl_smuggle/vurl_harvest— HTTP request smuggling (CL.TE, TE.CL, TE.TE)vurl_cloud— cloud metadata SSRF (AWS, Azure, GCP, k8s, Docker)vurl_mcp_rce— MCP/AI agent RCE (Langflow, CrewAI, AutoGPT, LangChain)vurl_rebind— DNS rebindingvurl_waf_evade— WAF evasion payload variantsvurl_modules— enumerate every available attack module
Rules
- Authorised targets only. Stay in scope.
- These are aggressive tools — ensure you're authorized before using them.
vurltools generate payloads — you still inject them via repeater/intruder.- Evidence over assertion — capture the exact request/response or OOB callback.