Environment Variables That Override VulnClaw Config File Settings
Environment variables prefixed with VULNCLAW_ override any setting defined in the VulnClaw config.yaml file, with reconnaissance API keys also accepting short-form names like FOFA_KEY or HUNTER_KEY.
VulnClaw uses a hierarchical configuration system defined in the Unclecheng-li/VulnClaw repository that loads settings from built-in defaults, a user-provided YAML file, and environment variables. According to vulnclaw/config/settings.py, environment variables represent the highest-priority layer and can dynamically override any configuration field without modifying disk files.
How VulnClaw Configuration Loading Works
The configuration loader implements a three-step merge process in the load_config function within vulnclaw/config/settings.py:
- Built-in defaults establish base values for all settings.
- User-provided
config.yamloverlays user preferences if the file exists. - Environment variables apply the final override via the private helper
_overlay_envstarting at line 78.
This design ensures that any variable prefixed with VULNCLAW_ takes precedence over both defaults and YAML configuration values.
LLM Configuration Environment Variables
The following variables control Large Language Model connectivity and parameters, mapping directly to fields in the LLMConfig model:
VULNCLAW_LLM_API_KEY– Overridesconfig.llm.api_keyVULNCLAW_LLM_BASE_URL– Overridesconfig.llm.base_urlVULNCLAW_LLM_MODEL– Overridesconfig.llm.modelVULNCLAW_LLM_PROVIDER– Overridesconfig.llm.providerVULNCLAW_LLM_MAX_TOKENS– Overridesconfig.llm.max_tokensVULNCLAW_LLM_MAX_CONTEXT_TOKENS– Overridesconfig.llm.max_context_tokensVULNCLAW_LLM_TEMPERATURE– Overridesconfig.llm.temperatureVULNCLAW_LLM_AUTH_MODE– Overridesconfig.llm.auth_modeVULNCLAW_LLM_CHATGPT_AUTO_PROXY– Overridesconfig.llm.chatgpt_auto_proxy
Session Behavior Environment Variables
Session management settings can be overridden using these environment variables, which target fields in SessionConfig:
VULNCLAW_SESSION_OUTPUT_DIR– Overridesconfig.session.output_dirVULNCLAW_SESSION_AUTO_SAVE– Overridesconfig.session.auto_saveVULNCLAW_SESSION_REPORT_FORMAT– Overridesconfig.session.report_formatVULNCLAW_SESSION_MAX_ROUNDS– Overridesconfig.session.max_roundsVULNCLAW_SESSION_SHOW_THINKING– Overridesconfig.session.show_thinkingVULNCLAW_SESSION_STALE_ROUNDS_THRESHOLD– Overridesconfig.session.stale_rounds_thresholdVULNCLAW_SESSION_REASONING_STATE_ENABLED– Overridesconfig.session.reasoning_state_enabledVULNCLAW_SESSION_REFLEXION_ENABLED– Overridesconfig.session.reflexion_enabledVULNCLAW_SESSION_REFLEXION_MAX_SAME_VULN_FAILS– Overridesconfig.session.reflexion_max_same_vuln_failsVULNCLAW_SESSION_REFLEXION_MAX_TOTAL_NO_PROGRESS– Overridesconfig.session.reflexion_max_total_no_progressVULNCLAW_SESSION_ESCALATION_MAX_LEVEL– Overridesconfig.session.escalation_max_levelVULNCLAW_SESSION_PLUGIN_RUNTIME_ENABLED– Overridesconfig.session.plugin_runtime_enabledVULNCLAW_SESSION_PLUGIN_DEFAULT_TIMEOUT– Overridesconfig.session.plugin_default_timeoutVULNCLAW_SESSION_PLUGIN_MAX_REQUESTS_PER_TARGET– Overridesconfig.session.plugin_max_requests_per_targetVULNCLAW_SESSION_EVIDENCE_MIN_REPORT_LEVEL– Overridesconfig.session.evidence_min_report_level
Safety and Execution Controls
Security-related execution settings can be modified via:
VULNCLAW_SAFETY_PYTHON_EXECUTE_ENABLED– Overridesconfig.safety.enable_python_executeVULNCLAW_SAFETY_PYTHON_EXECUTE_RESTRICTED– Overridesconfig.safety.python_execute_restrictedVULNCLAW_SAFETY_PYTHON_EXECUTE_MODE– Overridesconfig.safety.python_execute_modeVULNCLAW_SAFETY_PYTHON_EXECUTE_MAX_LINES– Overridesconfig.safety.python_execute_max_linesVULNCLAW_SAFETY_PYTHON_EXECUTE_SHOW_WARNING– Overridesconfig.safety.python_execute_show_warningVULNCLAW_SAFETY_PYTHON_EXECUTE_MAX_OUTPUT_CHARS– Overridesconfig.safety.python_execute_max_output_charsVULNCLAW_SAFETY_PYTHON_EXECUTE_AUDIT_ENABLED– Overridesconfig.safety.python_execute_audit_enabled
Reconnaissance API Keys
VulnClaw accepts external reconnaissance service credentials in two formats. The short-form names are recognized for backward compatibility, while the VULNCLAW_ prefixed versions follow the standard naming convention:
- FOFA:
FOFA_EMAILorVULNCLAW_RECON_FOFA_EMAIL;FOFA_KEYorVULNCLAW_RECON_FOFA_KEY - Hunter:
HUNTER_KEYorVULNCLAW_RECON_HUNTER_KEY - Quake:
QUAKE_KEYorVULNCLAW_RECON_QUAKE_KEY - ZoomEye:
ZOOMEYE_KEYorVULNCLAW_RECON_ZOOMEYE_KEY - Shodan:
SHODAN_KEYorVULNCLAW_RECON_SHODAN_KEY - ZeroZone:
ZEROZONE_KEYorVULNCLAW_RECON_ZEROZONE_KEY
Practical Usage Examples
To override the LLM model and API key without editing config.yaml:
export VULNCLAW_LLM_PROVIDER=openai
export VULNCLAW_LLM_API_KEY=sk-REDACTED
export VULNCLAW_LLM_MODEL=gpt-4o-mini
vulnclaw run
To change session behavior for temporary execution:
export VULNCLAW_SESSION_MAX_ROUNDS=5
export VULNCLAW_SESSION_SHOW_THINKING=true
export VULNCLAW_SESSION_OUTPUT_DIR=$HOME/.vulnclaw/custom_sessions
vulnclaw start
To disable Python execution safety guards:
export VULNCLAW_SAFETY_PYTHON_EXECUTE_ENABLED=false
vulnclaw run --plugin my_custom_plugin.py
To use FOFA reconnaissance with the short-form variable:
export FOFA_KEY=abcd1234efgh5678
vulnclaw recon fofa --query 'app="Apache"'
Summary
- VulnClaw applies a three-layer configuration system where environment variables take precedence over both built-in defaults and
config.yamlvalues. - The
_overlay_envfunction invulnclaw/config/settings.pyprocesses all variables beginning with theVULNCLAW_prefix. - LLM, Session, Safety, and Recon sections each expose specific environment variables that map directly to Pydantic model fields.
- Reconnaissance API keys support dual naming conventions, accepting both
VULNCLAW_RECON_*prefixed variables and legacy short-form names likeFOFA_KEY. - No file modification is required to override configuration—simply export the appropriate variables before invoking the CLI.
Frequently Asked Questions
What prefix must environment variables use to override VulnClaw settings?
All environment variables must begin with VULNCLAW_ to be recognized by the configuration loader in vulnclaw/config/settings.py. The exception is reconnaissance API keys, which also accept short-form names like FOFA_KEY or SHODAN_KEY for backward compatibility.
Do environment variables override the config.yaml file completely?
Yes. According to the implementation in the _overlay_env function, environment variables represent the highest-priority layer. If a VULNCLAW_* variable is set, it will overwrite the corresponding value from config.yaml regardless of the YAML content.
Can I disable Python code execution using environment variables?
Yes. Set VULNCLAW_SAFETY_PYTHON_EXECUTE_ENABLED=false to disable the Python execution feature, or use VULNCLAW_SAFETY_PYTHON_EXECUTE_MODE=restricted to enforce restricted execution mode without modifying the configuration file.
Where is the environment variable mapping logic implemented?
The mapping logic is implemented in the private helper function _overlay_env starting at line 78 of vulnclaw/config/settings.py. This function reads the OS environment and applies matching variables to the VulnClawConfig Pydantic model defined in vulnclaw/config/schema.py.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →