What Are the Dependencies for VulnClaw? Complete Package Guide

VulnClaw depends on 12 core Python packages including Typer, Rich, HTTPX, and OpenAI, with optional extras for Web UI and knowledge-base features, all declared in pyproject.toml.

VulnClaw is an AI-driven penetration testing CLI built in Python. Understanding the dependencies for VulnClaw is essential for installation troubleshooting and custom development. This article breaks down every required package, optional extra, and how they integrate with the source code.

Core Runtime Dependencies

The required dependencies for VulnClaw are specified in [project.dependencies] within pyproject.toml (lines 27-44). These packages handle everything from command-line parsing to asynchronous HTTP requests.

CLI Framework and Terminal Output

  • Typer (≥0.12.0): Powers the command-line interface defined in vulnclaw/cli/main.py.
  • Rich (≥13.0.0): Provides colored tables, progress bars, and formatted console output.
  • Prompt Toolkit (≥3.0.0): Handles interactive REPL input and TUI interactions.
  • Textual (≥0.40.0): Supports the optional TUI mode accessible via vulnclaw tui.

HTTP and AI Integration

  • HTTPX (≥0.27.0): Asynchronous HTTP client used by the built-in fetch MCP tool in vulnclaw/mcp/registry.py.
  • OpenAI (≥1.30.0): Communicates with OpenAI-compatible endpoints for LLM inference and tool calling, implemented in vulnclaw/agent/core.py.

Data Validation and Configuration

  • Pydantic (≥2.0.0): Defines strongly-typed models like Config and SessionState.
  • Pydantic-Settings (≥2.0.0): Loads YAML and environment variables into Pydantic models.
  • PyYAML (≥6.0): Parses the user-editable config.yaml configuration files.
  • TOML (≥0.10.0): Reads metadata from pyproject.toml.

Reporting and Sandbox Execution

  • Jinja2 (≥3.1.0): Template engine for generating markdown reports and PoC scripts in vulnclaw/report/generator.py.
  • BeautifulSoup4 (≥4.12.0): HTML parsing for sandboxed Python execution.
  • LXML (≥4.9.0): High-performance XML/HTML parsing for the same sandbox environment.
  • PyCryptodome (≥3.19.0): Cryptographic primitives for built-in crypto tools.

Optional Dependencies and Extras

VulnClaw defines optional features via [project.optional-dependencies] in pyproject.toml.

  • Web Extra: fastapi and uvicorn for the Web UI interface.
  • KB Extra: chromadb for knowledge-base storage capabilities.
  • Dev Extra: Testing and linting tools including pytest and ruff.

Installing VulnClaw with Specific Dependencies

Install core dependencies only:

pip install vulnclaw

Install with Web UI support:

pip install "vulnclaw[web]"

Install with knowledge base features:

pip install "vulnclaw[kb]"

Install all development tools:

pip install "vulnclaw[dev]"

How Dependencies Power VulnClaw Features

Async HTTP Requests with HTTPX

The httpx package powers network scanning capabilities. The built-in fetch tool in vulnclaw/mcp/registry.py relies on this library:

import httpx

async def fetch_target(url: str) -> str:
    async with httpx.AsyncClient() as client:
        resp = await client.get(url, timeout=10)
        resp.raise_for_status()
        return resp.text

LLM Integration via OpenAI

The openai package connects to LLM endpoints in vulnclaw/agent/core.py:

import openai

client = openai.OpenAI(api_key="sk-...", base_url="https://api.openai.com/v1")
resp = client.chat.completions.create(
    model="gpt-4o",
    messages=[{"role": "user", "content": "Analyze the security of https://example.com"}]
)
print(resp.choices[0].message.content)

Report Generation with Jinja2

The vulnclaw/report/generator.py file uses Jinja2 to render vulnerability reports:

from jinja2 import Environment, FileSystemLoader

env = Environment(loader=FileSystemLoader("vulnclaw/report/templates"))
template = env.get_template("report.md.j2")
rendered = template.render(session=session_data)
print(rendered)

Summary

  • VulnClaw requires 12 core packages defined in pyproject.toml lines 27-44.
  • Typer, Rich, and Textual handle CLI and TUI interfaces.
  • HTTPX and OpenAI enable network scanning and AI-driven analysis.
  • Pydantic and PyYAML manage configuration and data validation.
  • Jinja2, BeautifulSoup4, and PyCryptodome support reporting and sandboxed execution.
  • Optional extras include web (FastAPI), kb (ChromaDB), and dev (pytest/ruff).

Frequently Asked Questions

Where are VulnClaw dependencies defined?

All dependencies for VulnClaw are declared in the pyproject.toml file at the repository root. The core runtime dependencies occupy lines 27-44, while optional extras are listed under [project.optional-dependencies].

What Python version is required for VulnClaw?

While the analysis focuses on package dependencies, VulnClaw typically requires Python 3.9+ based on the dependency specifications. Pydantic v2 and Typer 0.12+ require modern Python versions. Check the requires-python field in pyproject.toml for exact version constraints.

Can I install VulnClaw without optional dependencies?

Yes. Running pip install vulnclaw installs only the 12 core dependencies. Optional packages like fastapi or chromadb are only installed when explicitly requested using extras notation (e.g., pip install "vulnclaw[web]").

Which dependency handles the AI chat features?

The OpenAI package (≥1.30.0) handles all LLM communication. It is imported in vulnclaw/agent/core.py and powers the AI-driven penetration testing commands like vulnclaw run.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →