How to Install VulnClaw: Complete Setup Guide for PyPI, Source, and Docker

Install VulnClaw by running pip install vulnclaw for the stable PyPI release, pip install -e . for editable source builds, or docker compose up --build for containerized deployment.

VulnClaw is an open-source vulnerability assessment framework distributed as a standard Python package on PyPI. This guide demonstrates how to install VulnClaw using the production wheel, build it from the source repository, or deploy via Docker, ensuring the Typer-based CLI at vulnclaw/cli/main.py is properly registered as the vulnclaw console entry point.

Prerequisites

Python Version Requirements

According to the pyproject.toml file in the Unclecheng-li/VulnClaw repository, Python 3.10 or newer is required. The requires-python field explicitly sets this minimum version to ensure compatibility with modern async features and the dependency resolution used by libraries like HTTPX and OpenAI.

The most straightforward method installs the latest released wheel (v0.3.2 at time of writing) together with all runtime dependencies including Typer, Rich, HTTPX, and OpenAI.


# Install the latest stable release

pip install vulnclaw

# Verify the console entry point is available

vulnclaw --version

This installation creates the vulnclaw console script mapped to the main function in vulnclaw/cli/main.py, as defined in pyproject.toml lines 66-68.

Install VulnClaw from Source (Development)

For contributors or security researchers needing the latest unreleased features, clone the repository and install in editable mode.


# Clone the repository

git clone https://github.com/Unclecheng-li/VulnClaw.git
cd VulnClaw

# Install in editable mode for immediate source code reflection

pip install -e .

# Verify functionality with the built-in diagnostic

vulnclaw doctor

This approach wires the entry point directly to your local vulnclaw/cli/main.py without requiring rebuilds after source code edits.

Install VulnClaw Web UI (Optional)

To launch the FastAPI-based web interface accessible at http://127.0.0.1:7788, install with the web extras defined in pyproject.toml.

pip install "vulnclaw[web]"
vulnclaw web

This installs the additional ASGI server dependencies required to run the browser-based interface alongside the CLI.

Run VulnClaw with Docker

The repository ships a production-ready Dockerfile and docker-compose.yml for containerized deployment that bundles the CLI, web interface, and all dependencies.


# Build and start the containerized stack

docker compose up --build

# Access the web UI at http://127.0.0.1:7788

This method runs the vulnclaw entry point inside an isolated environment with all configuration managed through the container.

Verify Your Installation

After installation, validate the setup using built-in diagnostics to ensure the Typer CLI in vulnclaw/cli/main.py resolves correctly.


# Run environment sanity check

vulnclaw doctor

# View available subcommands (scan, recon, web, etc.)

vulnclaw --help

Successful execution confirms that the console script is properly registered and all dependencies in pyproject.toml resolve without conflicts.

Summary

  • PyPI installation via pip install vulnclaw provides the stable release with the vulnclaw console entry point mapped to vulnclaw/cli/main.py.
  • Source installation using pip install -e . enables development workflows with live code editing in the Unclecheng-li/VulnClaw repository.
  • Docker deployment via docker compose up --build offers a containerized environment accessible at http://127.0.0.1:7788.
  • Python 3.10+ is strictly required as specified in pyproject.toml.
  • The web UI requires the extra dependency group: pip install "vulnclaw[web]".

Frequently Asked Questions

What Python version does VulnClaw require?

VulnClaw requires Python 3.10 or newer, as declared in the requires-python field of pyproject.toml. This ensures compatibility with the async libraries and modern Python features used throughout the codebase, particularly in the HTTPX-based scanning modules.

Where is the CLI entry point defined?

The vulnclaw command is defined in pyproject.toml at lines 66-68, which maps the console script to the main function in vulnclaw/cli/main.py. This Typer-based entry point handles all subcommands including scan, recon, web, and the doctor diagnostic.

How do I install VulnClaw for development?

Clone the repository from https://github.com/Unclecheng-li/VulnClaw.git and run pip install -e . in the project root. This editable installation reflects code changes immediately without reinstallation, sourcing directly from vulnclaw/cli/main.py and the vulnclaw/config/settings.py configuration handler.

Can I run VulnClaw without installing Python dependencies locally?

Yes, use the Docker deployment option. Running docker compose up --build starts a container with all dependencies pre-installed according to the Dockerfile, including the web interface accessible at http://127.0.0.1:7788 and the CLI accessible via docker exec.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →