How to Install VulnClaw: Complete Setup Guide for PyPI, Source, and Docker
Install VulnClaw by running pip install vulnclaw for the stable PyPI release, pip install -e . for editable source builds, or docker compose up --build for containerized deployment.
VulnClaw is an open-source vulnerability assessment framework distributed as a standard Python package on PyPI. This guide demonstrates how to install VulnClaw using the production wheel, build it from the source repository, or deploy via Docker, ensuring the Typer-based CLI at vulnclaw/cli/main.py is properly registered as the vulnclaw console entry point.
Prerequisites
Python Version Requirements
According to the pyproject.toml file in the Unclecheng-li/VulnClaw repository, Python 3.10 or newer is required. The requires-python field explicitly sets this minimum version to ensure compatibility with modern async features and the dependency resolution used by libraries like HTTPX and OpenAI.
Install VulnClaw from PyPI (Recommended)
The most straightforward method installs the latest released wheel (v0.3.2 at time of writing) together with all runtime dependencies including Typer, Rich, HTTPX, and OpenAI.
# Install the latest stable release
pip install vulnclaw
# Verify the console entry point is available
vulnclaw --version
This installation creates the vulnclaw console script mapped to the main function in vulnclaw/cli/main.py, as defined in pyproject.toml lines 66-68.
Install VulnClaw from Source (Development)
For contributors or security researchers needing the latest unreleased features, clone the repository and install in editable mode.
# Clone the repository
git clone https://github.com/Unclecheng-li/VulnClaw.git
cd VulnClaw
# Install in editable mode for immediate source code reflection
pip install -e .
# Verify functionality with the built-in diagnostic
vulnclaw doctor
This approach wires the entry point directly to your local vulnclaw/cli/main.py without requiring rebuilds after source code edits.
Install VulnClaw Web UI (Optional)
To launch the FastAPI-based web interface accessible at http://127.0.0.1:7788, install with the web extras defined in pyproject.toml.
pip install "vulnclaw[web]"
vulnclaw web
This installs the additional ASGI server dependencies required to run the browser-based interface alongside the CLI.
Run VulnClaw with Docker
The repository ships a production-ready Dockerfile and docker-compose.yml for containerized deployment that bundles the CLI, web interface, and all dependencies.
# Build and start the containerized stack
docker compose up --build
# Access the web UI at http://127.0.0.1:7788
This method runs the vulnclaw entry point inside an isolated environment with all configuration managed through the container.
Verify Your Installation
After installation, validate the setup using built-in diagnostics to ensure the Typer CLI in vulnclaw/cli/main.py resolves correctly.
# Run environment sanity check
vulnclaw doctor
# View available subcommands (scan, recon, web, etc.)
vulnclaw --help
Successful execution confirms that the console script is properly registered and all dependencies in pyproject.toml resolve without conflicts.
Summary
- PyPI installation via
pip install vulnclawprovides the stable release with thevulnclawconsole entry point mapped tovulnclaw/cli/main.py. - Source installation using
pip install -e .enables development workflows with live code editing in the Unclecheng-li/VulnClaw repository. - Docker deployment via
docker compose up --buildoffers a containerized environment accessible athttp://127.0.0.1:7788. - Python 3.10+ is strictly required as specified in
pyproject.toml. - The web UI requires the extra dependency group:
pip install "vulnclaw[web]".
Frequently Asked Questions
What Python version does VulnClaw require?
VulnClaw requires Python 3.10 or newer, as declared in the requires-python field of pyproject.toml. This ensures compatibility with the async libraries and modern Python features used throughout the codebase, particularly in the HTTPX-based scanning modules.
Where is the CLI entry point defined?
The vulnclaw command is defined in pyproject.toml at lines 66-68, which maps the console script to the main function in vulnclaw/cli/main.py. This Typer-based entry point handles all subcommands including scan, recon, web, and the doctor diagnostic.
How do I install VulnClaw for development?
Clone the repository from https://github.com/Unclecheng-li/VulnClaw.git and run pip install -e . in the project root. This editable installation reflects code changes immediately without reinstallation, sourcing directly from vulnclaw/cli/main.py and the vulnclaw/config/settings.py configuration handler.
Can I run VulnClaw without installing Python dependencies locally?
Yes, use the Docker deployment option. Running docker compose up --build starts a container with all dependencies pre-installed according to the Dockerfile, including the web interface accessible at http://127.0.0.1:7788 and the CLI accessible via docker exec.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →