docs

Hugin Skills

Pick the skill matching your task. Each skill loads only the tools you need.

Hugin skills — pick the one matching your task

Hugin exposes ~165 MCP tools. Loading all of them at once consumes ~115k tokens — nearly an entire context window. Skills solve this: each skill tells your agent which tools to load and how to work, so it never sees the tools it doesn't need.

How to use a skill

  1. Pick a skill from the table below that matches what you're trying to do.
  2. Drop the skill file into your agent's skills directory (e.g. ~/.config/opencode/skills/ for opencode, or your client's equivalent).
  3. Start working. Your agent loads the skill, calls tools/list with the right bundle filter, and gets only the tools for that task.

The skills

SkillWhen to loadBundleTier
hugin-orientStarting any engagement — get oriented, read scope, see what's capturedorient + scope + metaCommunity
hugin-reconMap the target: crawl, discover, API spec, fingerprintreconCommunity
hugin-replayTamper a request, test a hunchreplayCommunity
hugin-fuzzFuzz parameters, brute-force, enumeratefuzzCommunity
hugin-scanActive + passive vulnerability scanscanCommunity
hugin-injectionTest injection (SQLi, XSS, path traversal, CORS)bugclass-injectionCommunity
hugin-domTest DOM XSS, prototype pollution, postMessagebugclass-domPro
hugin-bacTest broken access control (IDOR, BAC, authz)bugclass-bacPro
hugin-oobConfirm blind bugs out-of-bandoobCommunity
hugin-browserDrive Chrome through Hugin, anti-bot, screenshotsbrowserPro
hugin-vurlPro offensive toolkit (smuggling, SSRF, MCP RCE)vurlPro
hugin-findingsWrite up and export findingsfindingsCommunity
hugin-automateWorkflows, campaigns, scheduled scansautomationPro

Methodology skills

These are full engagement methodology skills for AI agents — not tool bundles, but step-by-step playbooks that compose Hugin's tools across an entire bug-bounty engagement.

SkillWhen to load
bug-bounty-reconStarting recon on a bug-bounty program — drive Hugin-proxied Chrome to crawl, exercise client-side, capture evidence
bug-bounty-huntAfter recon — 22-phase attack methodology that tests every vulnerability class against the target

How bundles work

When your agent calls tools/list, it sends _meta.bundle with the bundle name:

{"method": "tools/list", "params": {"_meta": {"bundle": "recon"}}}

Hugin returns only the tools in that bundle. No bundle → the default set (orient + scope + meta), enough to get started. Multiple bundles: comma-separated.

For the full workflow + gotchas for a bundle, your agent can read the MCP resource hugin://skill/{bundle} (e.g. hugin://skill/recon).

Comprehensive flows

A full engagement chains skills as it progresses:

hugin-orient → hugin-recon → hugin-scan → hugin-injection → hugin-bac → hugin-oob → hugin-findings

Each transition is one tools/list call + one read_resource call. Your agent's context window holds only the current phase's tools plus accumulated findings from prior phases.

Last updated 2026-06-26.