# What Are the Dependencies for VulnClaw? Complete Package Guide

> Discover VulnClaw dependencies. Explore essential Python packages like Typer, Rich, and HTTPX, plus optional extras. Learn more in our complete package guide.

- Repository: [Unclecheng/VulnClaw](https://github.com/Unclecheng-li/VulnClaw)
- Tags: getting-started
- Published: 2026-07-03

---

**VulnClaw depends on 12 core Python packages including Typer, Rich, HTTPX, and OpenAI, with optional extras for Web UI and knowledge-base features, all declared in [`pyproject.toml`](https://github.com/Unclecheng-li/VulnClaw/blob/main/pyproject.toml).**

VulnClaw is an AI-driven penetration testing CLI built in Python. Understanding the dependencies for VulnClaw is essential for installation troubleshooting and custom development. This article breaks down every required package, optional extra, and how they integrate with the source code.

## Core Runtime Dependencies

The required dependencies for VulnClaw are specified in `[project.dependencies]` within [`pyproject.toml`](https://github.com/Unclecheng-li/VulnClaw/blob/main/pyproject.toml) (lines 27-44). These packages handle everything from command-line parsing to asynchronous HTTP requests.

### CLI Framework and Terminal Output

- **Typer** (≥0.12.0): Powers the command-line interface defined in [`vulnclaw/cli/main.py`](https://github.com/Unclecheng-li/VulnClaw/blob/main/vulnclaw/cli/main.py).
- **Rich** (≥13.0.0): Provides colored tables, progress bars, and formatted console output.
- **Prompt Toolkit** (≥3.0.0): Handles interactive REPL input and TUI interactions.
- **Textual** (≥0.40.0): Supports the optional TUI mode accessible via `vulnclaw tui`.

### HTTP and AI Integration

- **HTTPX** (≥0.27.0): Asynchronous HTTP client used by the built-in `fetch` MCP tool in [`vulnclaw/mcp/registry.py`](https://github.com/Unclecheng-li/VulnClaw/blob/main/vulnclaw/mcp/registry.py).
- **OpenAI** (≥1.30.0): Communicates with OpenAI-compatible endpoints for LLM inference and tool calling, implemented in [`vulnclaw/agent/core.py`](https://github.com/Unclecheng-li/VulnClaw/blob/main/vulnclaw/agent/core.py).

### Data Validation and Configuration

- **Pydantic** (≥2.0.0): Defines strongly-typed models like `Config` and `SessionState`.
- **Pydantic-Settings** (≥2.0.0): Loads YAML and environment variables into Pydantic models.
- **PyYAML** (≥6.0): Parses the user-editable [`config.yaml`](https://github.com/Unclecheng-li/VulnClaw/blob/main/config.yaml) configuration files.
- **TOML** (≥0.10.0): Reads metadata from [`pyproject.toml`](https://github.com/Unclecheng-li/VulnClaw/blob/main/pyproject.toml).

### Reporting and Sandbox Execution

- **Jinja2** (≥3.1.0): Template engine for generating markdown reports and PoC scripts in [`vulnclaw/report/generator.py`](https://github.com/Unclecheng-li/VulnClaw/blob/main/vulnclaw/report/generator.py).
- **BeautifulSoup4** (≥4.12.0): HTML parsing for sandboxed Python execution.
- **LXML** (≥4.9.0): High-performance XML/HTML parsing for the same sandbox environment.
- **PyCryptodome** (≥3.19.0): Cryptographic primitives for built-in crypto tools.

## Optional Dependencies and Extras

VulnClaw defines optional features via `[project.optional-dependencies]` in [`pyproject.toml`](https://github.com/Unclecheng-li/VulnClaw/blob/main/pyproject.toml).

- **Web Extra**: `fastapi` and `uvicorn` for the Web UI interface.
- **KB Extra**: `chromadb` for knowledge-base storage capabilities.
- **Dev Extra**: Testing and linting tools including `pytest` and `ruff`.

## Installing VulnClaw with Specific Dependencies

Install core dependencies only:

```bash
pip install vulnclaw

```

Install with Web UI support:

```bash
pip install "vulnclaw[web]"

```

Install with knowledge base features:

```bash
pip install "vulnclaw[kb]"

```

Install all development tools:

```bash
pip install "vulnclaw[dev]"

```

## How Dependencies Power VulnClaw Features

### Async HTTP Requests with HTTPX

The `httpx` package powers network scanning capabilities. The built-in `fetch` tool in [`vulnclaw/mcp/registry.py`](https://github.com/Unclecheng-li/VulnClaw/blob/main/vulnclaw/mcp/registry.py) relies on this library:

```python
import httpx

async def fetch_target(url: str) -> str:
    async with httpx.AsyncClient() as client:
        resp = await client.get(url, timeout=10)
        resp.raise_for_status()
        return resp.text

```

### LLM Integration via OpenAI

The `openai` package connects to LLM endpoints in [`vulnclaw/agent/core.py`](https://github.com/Unclecheng-li/VulnClaw/blob/main/vulnclaw/agent/core.py):

```python
import openai

client = openai.OpenAI(api_key="sk-...", base_url="https://api.openai.com/v1")
resp = client.chat.completions.create(
    model="gpt-4o",
    messages=[{"role": "user", "content": "Analyze the security of https://example.com"}]
)
print(resp.choices[0].message.content)

```

### Report Generation with Jinja2

The [`vulnclaw/report/generator.py`](https://github.com/Unclecheng-li/VulnClaw/blob/main/vulnclaw/report/generator.py) file uses **Jinja2** to render vulnerability reports:

```python
from jinja2 import Environment, FileSystemLoader

env = Environment(loader=FileSystemLoader("vulnclaw/report/templates"))
template = env.get_template("report.md.j2")
rendered = template.render(session=session_data)
print(rendered)

```

## Summary

- VulnClaw requires 12 core packages defined in [`pyproject.toml`](https://github.com/Unclecheng-li/VulnClaw/blob/main/pyproject.toml) lines 27-44.
- **Typer**, **Rich**, and **Textual** handle CLI and TUI interfaces.
- **HTTPX** and **OpenAI** enable network scanning and AI-driven analysis.
- **Pydantic** and **PyYAML** manage configuration and data validation.
- **Jinja2**, **BeautifulSoup4**, and **PyCryptodome** support reporting and sandboxed execution.
- Optional extras include `web` (FastAPI), `kb` (ChromaDB), and `dev` (pytest/ruff).

## Frequently Asked Questions

### Where are VulnClaw dependencies defined?

All dependencies for VulnClaw are declared in the [`pyproject.toml`](https://github.com/Unclecheng-li/VulnClaw/blob/main/pyproject.toml) file at the repository root. The core runtime dependencies occupy lines 27-44, while optional extras are listed under `[project.optional-dependencies]`.

### What Python version is required for VulnClaw?

While the analysis focuses on package dependencies, VulnClaw typically requires Python 3.9+ based on the dependency specifications. **Pydantic** v2 and **Typer** 0.12+ require modern Python versions. Check the `requires-python` field in [`pyproject.toml`](https://github.com/Unclecheng-li/VulnClaw/blob/main/pyproject.toml) for exact version constraints.

### Can I install VulnClaw without optional dependencies?

Yes. Running `pip install vulnclaw` installs only the 12 core dependencies. Optional packages like `fastapi` or `chromadb` are only installed when explicitly requested using extras notation (e.g., `pip install "vulnclaw[web]"`).

### Which dependency handles the AI chat features?

The **OpenAI** package (≥1.30.0) handles all LLM communication. It is imported in [`vulnclaw/agent/core.py`](https://github.com/Unclecheng-li/VulnClaw/blob/main/vulnclaw/agent/core.py) and powers the AI-driven penetration testing commands like `vulnclaw run`.