# VulnClaw | Unclecheng | Knowledge Base | Instagit

基于 AI Agent + MCP 工具链 + 渗透 Skill 编排， 配合大语言模型， 自然语言输入 → 自动完成「信息收集 → 漏洞发现 → 漏洞利用 → 报告生成」全流程。

GitHub Stars: 1.4k

Repository: https://github.com/Unclecheng-li/VulnClaw

---

## Articles

### [Where Is the Main Entry Point for the VulnClaw Application?](/Unclecheng-li/VulnClaw/vulnclaw-main-entry-point)

Discover the main entry point for the VulnClaw application. Find the Typer CLI instance in vulnclaw/cli/main.py and learn how to invoke it.

- Tags: deep-dive
- Published: 2026-07-03

### [Benefits of Using VulnClaw: AI-Driven Automated Penetration Testing Framework](/Unclecheng-li/VulnClaw/benefits-of-using-vulnclaw)

Discover the benefits of VulnClaw, an AI-driven automated penetration testing framework. Eliminate manual scripting and phantom findings with target-driven, evidence-verified security testing.

- Tags: getting-started
- Published: 2026-07-03

### [How to Get Support for VulnClaw: Official Channels and Troubleshooting Guide](/Unclecheng-li/VulnClaw/how-to-get-vulnclaw-support)

Get fast VulnClaw support via GitHub Issues, QQ groups, and comprehensive documentation. Resolve issues and report bugs efficiently with our official channels.

- Tags: how-to-guide
- Published: 2026-07-03

### [VulnClaw Roadmap: AI-Driven Penetration Testing Framework Evolution](/Unclecheng-li/VulnClaw/vulnclaw-project-roadmap)

Explore the VulnClaw roadmap. Discover how this AI-driven penetration testing framework evolves with advanced session orchestration, expanded security skills, and a community plugin marketplace.

- Tags: roadmap
- Published: 2026-07-03

### [How to Troubleshoot Common VulnClaw Errors: A Complete Guide](/Unclecheng-li/VulnClaw/troubleshoot-vulnclaw-errors)

Troubleshoot common VulnClaw errors like missing API keys or corrupted snapshots. Learn to fix these issues with vulnclaw doctor and configuration checks. Resolve VulnClaw problems fast.

- Tags: how-to-guide
- Published: 2026-07-03

### [VulnClaw Usage Examples: 6 Practical Ways to Run AI-Driven Penetration Tests](/Unclecheng-li/VulnClaw/vulnclaw-usage-examples)

Explore VulnClaw usage examples for AI-driven penetration tests. Discover 6 practical ways to leverage VulnClaw's CLI, REPL, and web interfaces for advanced security testing.

- Tags: getting-started
- Published: 2026-07-03

### [What is VulnClaw? An AI-Powered Penetration Testing Framework Explained](/Unclecheng-li/VulnClaw/meaning-of-vulnclaw)

Discover VulnClaw, the AI-powered open-source pen testing framework. Uncover vulnerabilities from recon to exploit with LLM orchestration and evidence validation. Learn more!

- Tags: getting-started
- Published: 2026-07-03

### [Can VulnClaw Be Integrated With Other Tools? A Technical Guide to AI-Driven Security Orchestration](/Unclecheng-li/VulnClaw/can-vulnclaw-integrate-with-other-tools)

Discover how VulnClaw integrates with other security tools using its MCP toolchain plugin subsystem and builtin tool wrappers. Streamline your security orchestration today.

- Tags: how-to-guide
- Published: 2026-07-03

### [How VulnClaw Performs Vulnerability Analysis: Inside the LLM-Driven Penetration Testing Workflow](/Unclecheng-li/VulnClaw/how-vulnclaw-performs-analysis)

Discover how VulnClaw performs vulnerability analysis with its autonomous LLM-driven loop. Explore its automated security tool execution and structured report generation.

- Tags: internals
- Published: 2026-07-03

### [What Are the Limitations of VulnClaw? A Technical Deep Dive](/Unclecheng-li/VulnClaw/vulnclaw-limitations)

Explore VulnClaw limitations: LLM dependency, API needs, reasoning caps, and external MCP service reliance. Understand the constraints for effective penetration testing.

- Tags: deep-dive
- Published: 2026-07-03

### [How to Update VulnClaw to the Latest Version: PyPI, Source, and Docker](/Unclecheng-li/VulnClaw/how-to-update-vulnclaw)

Update VulnClaw easily via PyPI pip install -U vulnclaw source git pull or Docker image rebuild. Keep your vulnerability scanner current.

- Tags: how-to-guide
- Published: 2026-07-03

### [Where to Find VulnClaw Documentation: Complete Guide to Setup and Usage](/Unclecheng-li/VulnClaw/vulnclaw-documentation-location)

Find comprehensive VulnClaw documentation for setup and usage in the Unclecheng-li/VulnClaw GitHub repository. Explore READMEs, docs, and code comments for complete guidance.

- Tags: getting-started
- Published: 2026-07-03

### [What License Does VulnClaw Use? Complete MIT License Guide](/Unclecheng-li/VulnClaw/vulnclaw-license)

Discover the VulnClaw license details. Learn about the permissive MIT License for commercial use, modification, and distribution of this open-source project.

- Tags: api-reference
- Published: 2026-07-03

### [How to Report a Bug in VulnClaw: A Step-by-Step Guide to GitHub Issues](/Unclecheng-li/VulnClaw/how-to-report-vulnclaw-bug)

Learn how to report a bug in VulnClaw with our step by step guide. Submit clear GitHub issues with diagnostic output and trace logs for quick issue resolution.

- Tags: how-to-guide
- Published: 2026-07-03

### [What Vulnerabilities Does VulnClaw Detect? A Complete Analysis of the AI-Driven Framework](/Unclecheng-li/VulnClaw/vulnclaw-vulnerability-detection)

Discover the vulnerabilities VulnClaw detects including injection flaws CVEs misconfigurations and more. Learn how this AI framework offers comprehensive security analysis.

- Tags: deep-dive
- Published: 2026-07-03

### [How to Contribute to the VulnClaw Project: A Complete Developer Guide](/Unclecheng-li/VulnClaw/how-to-contribute-to-vulnclaw)

Learn how to contribute to the VulnClaw project. Follow our developer guide to fork the repo, install dependencies, make changes, test, and submit a pull request.

- Tags: how-to-guide
- Published: 2026-07-03

### [Common Use Cases for VulnClaw: 9 AI-Powered Penetration Testing Workflows Explained](/Unclecheng-li/VulnClaw/vulnclaw-use-cases)

Discover common use cases for VulnClaw, an AI-powered penetration testing tool. Explore automated tests, security monitoring, reconnaissance, and more with 9 explained workflows.

- Tags: tutorial
- Published: 2026-07-03

### [How to Configure VulnClaw: Complete Setup Guide for the AI Security Agent](/Unclecheng-li/VulnClaw/how-to-configure-vulnclaw)

Learn how to configure VulnClaw, the AI security agent. Master settings via config.yaml, CLI, presets, and environment variables for robust security.

- Tags: how-to-guide
- Published: 2026-07-03

### [VulnClaw Scripts Directory: Automated Release Validation and Quality Checks](/Unclecheng-li/VulnClaw/vulnclaw-scripts-directory-purpose)

Discover the VulnClaw scripts directory purpose. Automate release validation, run unit tests, verify compilation, and confirm Python builds with these command-line utilities.

- Tags: how-to-guide
- Published: 2026-07-03

### [What Programming Languages Does VulnClaw Use? A Dual-Language Architecture Analysis](/Unclecheng-li/VulnClaw/vulnclaw-programming-languages)

Discover the programming languages VulnClaw uses. Its dual-language architecture combines Python 3 for the security engine and TypeScript for the React frontend.

- Tags: architecture
- Published: 2026-07-03

### [How to Run VulnClaw from Source: Complete Installation and Setup Guide](/Unclecheng-li/VulnClaw/how-to-run-vulnclaw-from-source)

Learn to run VulnClaw from source. Follow our guide to clone the repo, install the package, configure credentials, and use the CLI for powerful vulnerability analysis.

- Tags: how-to-guide
- Published: 2026-07-03

### [What Are the Dependencies for VulnClaw? Complete Package Guide](/Unclecheng-li/VulnClaw/vulnclaw-dependencies)

Discover VulnClaw dependencies. Explore essential Python packages like Typer, Rich, and HTTPX, plus optional extras. Learn more in our complete package guide.

- Tags: getting-started
- Published: 2026-07-03

### [How to Install VulnClaw: Complete Setup Guide for PyPI, Source, and Docker](/Unclecheng-li/VulnClaw/how-to-install-vulnclaw)

Install VulnClaw easily via PyPI with pip install vulnclaw, from source with pip install -e ., or use Docker. Get this complete setup guide now.

- Tags: how-to-guide
- Published: 2026-07-03

### [What Is VulnClaw? An AI-Powered Penetration Testing Framework](/Unclecheng-li/VulnClaw/what-is-vulnclaw)

Discover VulnClaw, the AI-powered penetration testing framework that automates security workflows using LLMs. Streamline reconnaissance, exploitation, and reporting effortlessly.

- Tags: getting-started
- Published: 2026-07-03

### [How to Configure API Keys for Reconnaissance Tools in VulnClaw: A Complete Guide](/Unclecheng-li/VulnClaw/how-to-configure-recon-api-keys-vulnclaw)

Learn to configure API keys for reconnaissance tools in VulnClaw. Utilize manual YAML editing or CLI commands for secure credential management. Get started today!

- Tags: how-to-guide
- Published: 2026-06-30

### [How to Use PluginStage for Vulnerability Discovery Phases in VulnClaw](/Unclecheng-li/VulnClaw/how-to-use-pluginstage-vulnclaw-discovery)

Learn how to use PluginStage in VulnClaw to model penetration testing workflows and orchestrate vulnerability discovery phases automatically. Master vulnerability research.

- Tags: how-to-guide
- Published: 2026-06-30

### [VulnClaw Plugin Context Model: Understanding PluginContext in the Unclecheng-li/VulnClaw Framework](/Unclecheng-li/VulnClaw/vulnclaw-plugin-context-model)

Explore the VulnClaw plugin context model, a Pydantic BaseModel that manages execution parameters for vulnerability scanning plugins. Understand target URLs, lifecycle stages, and more.

- Tags: internals
- Published: 2026-06-30

### [How to Integrate VulnClaw with External Tools Like Burp Suite and Frida](/Unclecheng-li/VulnClaw/how-to-integrate-vulnclaw-with-external-tools)

Integrate VulnClaw with Burp Suite and Frida using its Modular Control Protocol. Discover and register external tool APIs via SSE or stdio for enhanced security testing.

- Tags: how-to-guide
- Published: 2026-06-30

### [VulnClaw REPL TUI and Web UI Modes: Architecture and Usage Differences](/Unclecheng-li/VulnClaw/vulnclaw-repl-tui-web-ui-modes-comparison)

Explore VulnClaw REPL TUI and Web UI differences. Understand contrasting tech stacks and interaction models for this security tool while leveraging the same core engine.

- Tags: architecture
- Published: 2026-06-30

### [How VulnClaw's TUI Workbench Validates Testing Scope Boundaries](/Unclecheng-li/VulnClaw/how-vulnclaws-tui-scope-boundary-validation)

Learn how VulnClaw's TUI workbench validates testing scope boundaries using a three-layer system that parses user input, normalizes actions, and re-validates through the CLI for secure execution.

- Tags: how-to-guide
- Published: 2026-06-30

### [Environment Variables That Override VulnClaw Config File Settings](/Unclecheng-li/VulnClaw/vulnclaw-config-environment-variables-override)

Discover VulnClaw environment variables that override config settings. Learn how VULNCLAW_ and specific API keys like FOFA_KEY control your configurations efficiently.

- Tags: reference
- Published: 2026-06-30

### [How to Customize VulnClaw's Report Generation Template: 4 Proven Methods](/Unclecheng-li/VulnClaw/how-to-customize-vulnclaws-report-template)

Customize VulnClaw report generation templates using 4 proven methods. Edit source templates, load external files, or extend the rendering context for personalized penetration-test reports.

- Tags: how-to-guide
- Published: 2026-06-30

### [How VulnClaw Handles Target State Management and Rollbacks](/Unclecheng-li/VulnClaw/how-vulnclaws-target-state-management-rollbacks)

Learn how VulnClaw manages target states and handles rollbacks. Revert assessments to previous states using timestamped snapshots saved in JSON files.

- Tags: internals
- Published: 2026-06-30

### [Safety Boundaries in VulnClaw's Plugin Runtime: A Deep Dive into the Sandbox Architecture](/Unclecheng-li/VulnClaw/vulnclaws-plugin-runtime-safety-boundaries)

Explore VulnClaw's plugin runtime safety boundaries. Discover how its layered defense strategy validates registration, permissions, scopes, policies, and budgets before executing any code.

- Tags: deep-dive
- Published: 2026-06-30

### [Security Constraints in VulnClaw's Plugin Runtime: Execution Controls and Safety Mechanisms](/Unclecheng-li/VulnClaw/vulnclaws-plugin-runtime-security-constraints)

Explore VulnClaw's plugin runtime security constraints. Discover how execution controls and safety mechanisms safeguard your system before any code runs. Learn more!

- Tags: internals
- Published: 2026-06-30

### [How VulnClaw's Persistent Pentesting Mode Handles State Preservation Across Cycles](/Unclecheng-li/VulnClaw/how-vulnclaws-persistent-pentesting-state-preservation)

Discover how VulnClaw's persistent pentesting mode preserves state. Learn how it serializes session data to disk, ensuring findings and target information survive interruptions and accumulate across cycles.

- Tags: internals
- Published: 2026-06-30

### [VulnClaw MCP Services Integration: The 4 Built-in Tools Explained](/Unclecheng-li/VulnClaw/what-mcp-services-vulnclaw-integrates-with)

Explore VulnClaw's MCP services: fetch, memory, chrome-devtools, and burp. Enable HTTP testing, persistent storage, browser automation, and traffic interception with this powerful integration.

- Tags: deep-dive
- Published: 2026-06-30

### [How to Switch Between LLM Providers Programmatically in VulnClaw](/Unclecheng-li/VulnClaw/how-to-switch-llm-providers-programmatically-vulnclaw)

Easily switch LLM providers programmatically in VulnClaw using apply_provider_preset. Update global config, resolve provider names, and auto fill defaults without touching user settings.

- Tags: how-to-guide
- Published: 2026-06-30

### [How to Configure Multiple LLM Providers in VulnClaw: A Complete Guide](/Unclecheng-li/VulnClaw/how-to-configure-multiple-llm-providers-vulnclaw)

Learn how to configure multiple LLM providers in VulnClaw with our complete guide. Seamlessly switch between 13+ providers using separate configuration profiles for enhanced flexibility.

- Tags: how-to-guide
- Published: 2026-06-30

### [How VulnClaw's LLM Agent Orchestrates Pentest Skills: Dynamic Skill Dispatch and Execution Control](/Unclecheng-li/VulnClaw/how-vulnclaws-llm-agent-orchestrates-pentest-skills)

Discover how VulnClaw's LLM agent orchestrates pentest skills with its three-stage pipeline for intent analysis, dynamic skill injection, and autonomous execution control for efficient security testing.

- Tags: architecture
- Published: 2026-06-30

### [VulnClaw's LLM Agent Core Architecture: A Modular State-Driven Orchestration Layer](/Unclecheng-li/VulnClaw/vulnclaws-llm-agent-core-architecture)

Explore VulnClaw's LLM agent core architecture, a modular, state-driven orchestration system. Understand how it integrates LLMs, tools, and knowledge for efficient session management.

- Tags: architecture
- Published: 2026-06-30

