How to Configure Multiple LLM Providers in VulnClaw: A Complete Guide
VulnClaw supports seamless switching between 13+ LLM providers by maintaining separate configuration profiles and using the apply_provider_preset helper to auto-populate provider-specific defaults.
VulnClaw is an open-source vulnerability analysis framework that abstracts LLM interactions behind a unified configuration layer. To configure multiple LLM providers in VulnClaw, you maintain distinct configuration profiles while leveraging the LLMProvider enum and preset system to handle provider-specific endpoints and models automatically.
Understanding VulnClaw’s LLM Architecture
VulnClaw’s LLM subsystem centers on a single active configuration object (config.llm) that dynamically adapts to any supported provider. The architecture relies on three core components defined in vulnclaw/config/schema.py.
The LLMProvider Enum
The LLMProvider enumeration (lines 14-94) defines every supported provider key as a string value. Valid options include openai, minimax, deepseek, zhipu, moonshot, qwen, siliconflow, doubao, baichuan, stepfun, sensetime, yi, and custom.
Provider Presets and Default Configurations
The PROVIDER_PRESETS dictionary (lines 33-95) maps each provider to its default base_url and model. When you switch providers, VulnClaw references this preset to auto-configure the endpoint unless you explicitly override it.
The LLMConfig Schema
The LLMConfig class (lines 102-110) stores the active provider name, API key, authentication mode, and optional overrides. This schema serializes to YAML in the user’s config directory (default: ~/.config/vulnclaw/config.yaml).
Switching Between LLM Providers Programmatically
To configure multiple LLM providers in VulnClaw at runtime, use the apply_provider_preset helper in vulnclaw/config/settings.py (lines 311-350). This function safely swaps providers while preserving existing user overrides.
First, initialize the configuration:
from vulnclaw.config.schema import VulnClawConfig
cfg = VulnClawConfig() # Defaults to OpenAI
List available providers using list_providers (lines 352-364):
from vulnclaw.config.settings import list_providers
for provider in list_providers():
print(f"{provider['provider']} – {provider['label']} (default: {provider['default_model']})")
Apply a new provider preset:
from vulnclaw.config.settings import apply_provider_preset
cfg = apply_provider_preset(cfg, "zhipu")
# cfg.llm.provider == "zhipu"
# cfg.llm.base_url == "https://open.bigmodel.cn/api/paas/v4"
# cfg.llm.model == "glm-4"
Configure authentication credentials:
cfg.llm.api_key = "sk-REPLACE_WITH_YOUR_KEY"
cfg.llm.auth_mode = "static"
Override specific fields (optional):
cfg.llm.base_url = "https://custom.endpoint/v1"
cfg.llm.model = "custom-model-v2"
Querying Available Models
Before finalizing a configuration, validate accessible models using fetch_provider_models (lines 667-682 in vulnclaw/config/settings.py):
from vulnclaw.config.settings import fetch_provider_models
models = fetch_provider_models(cfg.llm.base_url, cfg.llm.api_key)
print("Available models:", models) # Returns sorted list from /v1/models endpoint
Managing Multiple Provider Profiles
Since VulnClaw maintains only one active LLMConfig at a time, managing multiple providers requires separate configuration files. Create distinct YAML profiles for each provider:
import yaml
from pathlib import Path
from vulnclaw.config.schema import VulnClawConfig
from vulnclaw.config.settings import apply_provider_preset
def save_profile(cfg, name):
config_dir = Path.home() / ".config" / "vulnclaw" / "profiles"
config_dir.mkdir(parents=True, exist_ok=True)
with open(config_dir / f"{name}.yaml", "w") as f:
yaml.safe_dump(cfg.model_dump(), f)
# Save ZhiPu profile
cfg_zhipu = apply_provider_preset(VulnClawConfig(), "zhipu")
cfg_zhipu.llm.api_key = "sk-zhipu-key"
save_profile(cfg_zhipu, "zhipu")
# Save OpenAI profile
cfg_openai = apply_provider_preset(VulnClawConfig(), "openai")
cfg_openai.llm.api_key = "sk-openai-key"
save_profile(cfg_openai, "openai")
Load the desired profile at runtime to switch contexts instantly.
Configuring Providers via the CLI and TUI
The interactive TUI (vulnclaw/cli/tui.py, lines 1190-1192) and Textual-based UI (vulnclaw/cli/tui_textual.py, lines 617-635) both consume config.llm fields. When you select "Configure LLM" from the menu:
- The UI displays the current provider from
config.llm.provider - It populates the selection list using
list_providers() - It calls
apply_provider_presetinternally when you confirm a switch - It persists changes to disk automatically
This provides a user-friendly alternative to manual YAML editing for non-technical users.
Summary
- VulnClaw uses a single active
LLMConfigobject stored inconfig.llmto manage provider settings. - The
LLMProviderenum andPROVIDER_PRESETSdictionary invulnclaw/config/schema.pydefine supported providers and their default endpoints. - Use
apply_provider_preset()fromvulnclaw/config/settings.pyto switch providers while auto-populating base URLs and default models. - Query available models per provider using
fetch_provider_models()to validate API access before configuration. - Maintain multiple provider setups by saving separate YAML profiles and loading them at runtime.
Frequently Asked Questions
Can I use multiple LLM providers simultaneously in one VulnClaw instance?
No. VulnClaw maintains a single active LLM configuration at runtime via the config.llm object. To work with multiple providers, you must maintain separate configuration profiles and switch between them by reloading the config object, or run separate VulnClaw instances with different config files.
How do I add a custom OpenAI-compatible endpoint that isn't in the preset list?
Set cfg.llm.provider to "custom" and manually specify cfg.llm.base_url and cfg.llm.model. The custom provider type uses the same OpenAI SDK backend but allows arbitrary endpoints, bypassing the preset defaults while maintaining compatibility with the configuration schema defined in vulnclaw/config/schema.py.
Where does VulnClaw store my API keys?
API keys are stored in the YAML configuration file at ~/.config/vulnclaw/config.yaml (or your platform's equivalent user config directory) when using auth_mode = "static". Ensure this file has restricted permissions (600) to prevent unauthorized access to your credentials.
Why does switching providers sometimes reset my model selection?
The apply_provider_preset function only updates base_url and model if you haven't explicitly overridden them already. If you manually set these fields before switching providers, VulnClaw preserves your custom values. If you rely on defaults, the function populates the new provider's preset values automatically.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →