Hugin Skills
Pick the skill matching your task. Each skill loads only the tools you need.
Hugin skills — pick the one matching your task
Hugin exposes ~165 MCP tools. Loading all of them at once consumes ~115k tokens — nearly an entire context window. Skills solve this: each skill tells your agent which tools to load and how to work, so it never sees the tools it doesn't need.
How to use a skill
- Pick a skill from the table below that matches what you're trying to do.
- Drop the skill file into your agent's skills directory
(e.g.
~/.config/opencode/skills/for opencode, or your client's equivalent). - Start working. Your agent loads the skill, calls
tools/listwith the right bundle filter, and gets only the tools for that task.
The skills
| Skill | When to load | Bundle | Tier |
|---|---|---|---|
| hugin-orient | Starting any engagement — get oriented, read scope, see what's captured | orient + scope + meta | Community |
| hugin-recon | Map the target: crawl, discover, API spec, fingerprint | recon | Community |
| hugin-replay | Tamper a request, test a hunch | replay | Community |
| hugin-fuzz | Fuzz parameters, brute-force, enumerate | fuzz | Community |
| hugin-scan | Active + passive vulnerability scan | scan | Community |
| hugin-injection | Test injection (SQLi, XSS, path traversal, CORS) | bugclass-injection | Community |
| hugin-dom | Test DOM XSS, prototype pollution, postMessage | bugclass-dom | Pro |
| hugin-bac | Test broken access control (IDOR, BAC, authz) | bugclass-bac | Pro |
| hugin-oob | Confirm blind bugs out-of-band | oob | Community |
| hugin-browser | Drive Chrome through Hugin, anti-bot, screenshots | browser | Pro |
| hugin-vurl | Pro offensive toolkit (smuggling, SSRF, MCP RCE) | vurl | Pro |
| hugin-findings | Write up and export findings | findings | Community |
| hugin-automate | Workflows, campaigns, scheduled scans | automation | Pro |
Methodology skills
These are full engagement methodology skills for AI agents — not tool bundles, but step-by-step playbooks that compose Hugin's tools across an entire bug-bounty engagement.
| Skill | When to load |
|---|---|
| bug-bounty-recon | Starting recon on a bug-bounty program — drive Hugin-proxied Chrome to crawl, exercise client-side, capture evidence |
| bug-bounty-hunt | After recon — 22-phase attack methodology that tests every vulnerability class against the target |
How bundles work
When your agent calls tools/list, it sends _meta.bundle with the bundle name:
{"method": "tools/list", "params": {"_meta": {"bundle": "recon"}}}
Hugin returns only the tools in that bundle. No bundle → the default set (orient + scope + meta), enough to get started. Multiple bundles: comma-separated.
For the full workflow + gotchas for a bundle, your agent can read the MCP
resource hugin://skill/{bundle} (e.g. hugin://skill/recon).
Comprehensive flows
A full engagement chains skills as it progresses:
hugin-orient → hugin-recon → hugin-scan → hugin-injection → hugin-bac → hugin-oob → hugin-findings
Each transition is one tools/list call + one read_resource call. Your
agent's context window holds only the current phase's tools plus accumulated
findings from prior phases.