How to Configure VulnClaw: Complete Setup Guide for the AI Security Agent
VulnClaw stores configuration in ~/.vulnclaw/config.yaml and supports CLI-based editing, provider presets, and environment variable overrides loaded via Pydantic models in vulnclaw/config/schema.py.
VulnClaw is an open-source AI-powered security testing framework that requires specific configuration before executing vulnerability scans. The repository Unclecheng-li/VulnClaw manages settings through a layered system combining YAML files, provider presets, and runtime environment variables. Understanding how to configure VulnClaw properly ensures secure LLM integration and proper MCP service activation.
Where VulnClaw Stores Configuration
By default, VulnClaw creates a user-specific configuration directory at ~/.vulnclaw. This path can be overridden by setting the VULNCLAW_CONFIG_DIR environment variable before running the tool.
The configuration directory contains the following structure:
CONFIG_FILE(~/.vulnclaw/config.yaml) – The persistent YAML configuration fileSESSIONS_DIR– Runtime session data storageTARGETS_DIR– Target specifications and metadataKB_DIR– Knowledge base storageSKILLS_DIR– Skill definitions and templates
The directories are created automatically when the first configuration operation runs via the ensure_dirs() function in vulnclaw/config/settings.py.
Editing Configuration via CLI
While you can edit the YAML file manually, VulnClaw provides a safe, typed CLI interface that validates inputs against Pydantic schemas defined in vulnclaw/config/schema.py.
Use the vulnclaw config set command with dot-notation to modify nested values:
# Set LLM API credentials
vulnclaw config set llm.api_key sk-xxxxxxxxxxxxxxxxxxxx
# Adjust session limits
vulnclaw config set session.max_rounds 30
# Disable Python execution for safety
vulnclaw config set safety.enable_python_execute false
The CLI parses the key, coerces the value to the appropriate type (int, bool, str), and persists changes through set_config_value() → save_config() in vulnclaw/config/settings.py.
Configuring LLM Providers
VulnClaw ships with built-in support for 13 OpenAI-compatible providers defined in the PROVIDER_PRESETS constant within vulnclaw/config/schema.py. The apply_provider_preset() function in vulnclaw/config/settings.py automatically configures the base URL and default model for your chosen provider.
Switch providers using the preset command:
# Auto-configure MiniMax (fills base_url and model)
vulnclaw config provider minimax
# Override with custom endpoint if needed
vulnclaw config set llm.base_url https://my-api.example.com/v1
vulnclaw config set llm.model my-custom-model
Setting Up MCP (Model-Context-Protocol) Services
MCP servers extend VulnClaw's capabilities with external tools like Chrome DevTools or Burp Suite. Built-in servers are defined in BUILTIN_MCP_SERVERS in vulnclaw/config/schema.py.
Enable services via the CLI:
vulnclaw config set mcp.servers.chrome-devtools.enabled true
vulnclaw config set mcp.servers.burp.enabled true
Each server configuration includes a transport field supporting three types defined in MCPTransportConfig: stdio, sse, or streamable-http. The transport specifies how VulnClaw communicates with the MCP server, including command paths, arguments, or URLs.
Overriding Settings with Environment Variables
Any configuration field can be overridden at runtime using environment variables prefixed with VULNCLAW_. The _overlay_env() function in vulnclaw/config/settings.py processes these variables after loading the YAML file, ensuring the precedence order: environment variables > config file > built-in defaults.
Common environment overrides:
export VULNCLAW_LLM_API_KEY=sk-xxxx
export VULNCLAW_SESSION_MAX_ROUNDS=20
export VULNCLAW_SAFETY_PYTHON_EXECUTE_ENABLED=false
For reconnaissance services like FOFA or Shodan, export the standard key names (FOFA_KEY, SHODAN_KEY) and the loader will map them into config.recon automatically.
Configuring Safety and Sandbox Options
The safety section in vulnclaw/config/schema.py controls the python_execute tool used by the agent for dynamic code execution. Configure these carefully based on your risk tolerance:
enable_python_execute– Defaulttrue; set tofalseto disable the tool entirelypython_execute_mode– Defaulttrusted-local; options includesafe,lab, ortrusted-localpython_execute_max_lines– Default50; limits code length per executionpython_execute_audit_enabled– Defaulttrue; logs all executions topython_execute_audit.jsonl
Modify via CLI:
vulnclaw config set safety.python_execute_mode safe
vulnclaw config set safety.python_execute_max_lines 25
Loading Configuration Programmatically
Access the merged configuration in Python using the load_config() function from vulnclaw/config/settings.py:
from vulnclaw.config.settings import load_config
cfg = load_config()
print("LLM provider:", cfg.llm.provider)
print("Base URL:", cfg.llm.base_url)
print("Session dir:", cfg.session.output_dir)
This returns the final configuration object with all defaults, file values, and environment overlays applied.
Summary
- Configuration location:
~/.vulnclaw/config.yaml(override withVULNCLAW_CONFIG_DIR) - CLI editing: Use
vulnclaw config set <key> <value>for type-safe updates viaset_config_value() - Provider setup: Run
vulnclaw config provider <name>to apply presets fromPROVIDER_PRESETS - MCP services: Enable built-in servers in
BUILTIN_MCP_SERVERSusing dot-notation keys - Environment overrides: Prefix any config key with
VULNCLAW_and export; processed by_overlay_env() - Safety controls: Adjust
python_executesettings through thesafetysection in schema.py
Frequently Asked Questions
Where is the VulnClaw configuration file located?
VulnClaw stores its configuration in ~/.vulnclaw/config.yaml by default. The directory is created automatically by ensure_dirs() in vulnclaw/config/settings.py when you first run a configuration command. You can relocate this directory by setting the VULNCLAW_CONFIG_DIR environment variable before executing VulnClaw.
How do I switch between different LLM providers?
Use the vulnclaw config provider <name> command to switch between the 13 built-in OpenAI-compatible providers. This invokes apply_provider_preset() in vulnclaw/config/settings.py, which automatically populates the base_url and model fields in config.yaml based on the PROVIDER_PRESETS definition in vulnclaw/config/schema.py.
Can I configure VulnClaw using only environment variables without editing YAML?
Yes. Any configuration field supports environment variable overrides using the VULNCLAW_ prefix (e.g., VULNCLAW_LLM_API_KEY). The _overlay_env() function loads these after the YAML file, ensuring environment variables take precedence. For CI/CD deployments, you can rely entirely on environment variables without creating a config.yaml file.
How do I disable Python code execution for security hardening?
Set vulnclaw config set safety.enable_python_execute false or export VULNCLAW_SAFETY_ENABLE_PYTHON_EXECUTE=false. This disables the python_execute tool entirely. Alternatively, use vulnclaw config set safety.python_execute_mode safe to restrict execution to sandboxed environments, as defined in the Pydantic models in vulnclaw/config/schema.py.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →