What Are the Dependencies for VulnClaw? Complete Package Guide
VulnClaw depends on 12 core Python packages including Typer, Rich, HTTPX, and OpenAI, with optional extras for Web UI and knowledge-base features, all declared in pyproject.toml.
VulnClaw is an AI-driven penetration testing CLI built in Python. Understanding the dependencies for VulnClaw is essential for installation troubleshooting and custom development. This article breaks down every required package, optional extra, and how they integrate with the source code.
Core Runtime Dependencies
The required dependencies for VulnClaw are specified in [project.dependencies] within pyproject.toml (lines 27-44). These packages handle everything from command-line parsing to asynchronous HTTP requests.
CLI Framework and Terminal Output
- Typer (≥0.12.0): Powers the command-line interface defined in
vulnclaw/cli/main.py. - Rich (≥13.0.0): Provides colored tables, progress bars, and formatted console output.
- Prompt Toolkit (≥3.0.0): Handles interactive REPL input and TUI interactions.
- Textual (≥0.40.0): Supports the optional TUI mode accessible via
vulnclaw tui.
HTTP and AI Integration
- HTTPX (≥0.27.0): Asynchronous HTTP client used by the built-in
fetchMCP tool invulnclaw/mcp/registry.py. - OpenAI (≥1.30.0): Communicates with OpenAI-compatible endpoints for LLM inference and tool calling, implemented in
vulnclaw/agent/core.py.
Data Validation and Configuration
- Pydantic (≥2.0.0): Defines strongly-typed models like
ConfigandSessionState. - Pydantic-Settings (≥2.0.0): Loads YAML and environment variables into Pydantic models.
- PyYAML (≥6.0): Parses the user-editable
config.yamlconfiguration files. - TOML (≥0.10.0): Reads metadata from
pyproject.toml.
Reporting and Sandbox Execution
- Jinja2 (≥3.1.0): Template engine for generating markdown reports and PoC scripts in
vulnclaw/report/generator.py. - BeautifulSoup4 (≥4.12.0): HTML parsing for sandboxed Python execution.
- LXML (≥4.9.0): High-performance XML/HTML parsing for the same sandbox environment.
- PyCryptodome (≥3.19.0): Cryptographic primitives for built-in crypto tools.
Optional Dependencies and Extras
VulnClaw defines optional features via [project.optional-dependencies] in pyproject.toml.
- Web Extra:
fastapianduvicornfor the Web UI interface. - KB Extra:
chromadbfor knowledge-base storage capabilities. - Dev Extra: Testing and linting tools including
pytestandruff.
Installing VulnClaw with Specific Dependencies
Install core dependencies only:
pip install vulnclaw
Install with Web UI support:
pip install "vulnclaw[web]"
Install with knowledge base features:
pip install "vulnclaw[kb]"
Install all development tools:
pip install "vulnclaw[dev]"
How Dependencies Power VulnClaw Features
Async HTTP Requests with HTTPX
The httpx package powers network scanning capabilities. The built-in fetch tool in vulnclaw/mcp/registry.py relies on this library:
import httpx
async def fetch_target(url: str) -> str:
async with httpx.AsyncClient() as client:
resp = await client.get(url, timeout=10)
resp.raise_for_status()
return resp.text
LLM Integration via OpenAI
The openai package connects to LLM endpoints in vulnclaw/agent/core.py:
import openai
client = openai.OpenAI(api_key="sk-...", base_url="https://api.openai.com/v1")
resp = client.chat.completions.create(
model="gpt-4o",
messages=[{"role": "user", "content": "Analyze the security of https://example.com"}]
)
print(resp.choices[0].message.content)
Report Generation with Jinja2
The vulnclaw/report/generator.py file uses Jinja2 to render vulnerability reports:
from jinja2 import Environment, FileSystemLoader
env = Environment(loader=FileSystemLoader("vulnclaw/report/templates"))
template = env.get_template("report.md.j2")
rendered = template.render(session=session_data)
print(rendered)
Summary
- VulnClaw requires 12 core packages defined in
pyproject.tomllines 27-44. - Typer, Rich, and Textual handle CLI and TUI interfaces.
- HTTPX and OpenAI enable network scanning and AI-driven analysis.
- Pydantic and PyYAML manage configuration and data validation.
- Jinja2, BeautifulSoup4, and PyCryptodome support reporting and sandboxed execution.
- Optional extras include
web(FastAPI),kb(ChromaDB), anddev(pytest/ruff).
Frequently Asked Questions
Where are VulnClaw dependencies defined?
All dependencies for VulnClaw are declared in the pyproject.toml file at the repository root. The core runtime dependencies occupy lines 27-44, while optional extras are listed under [project.optional-dependencies].
What Python version is required for VulnClaw?
While the analysis focuses on package dependencies, VulnClaw typically requires Python 3.9+ based on the dependency specifications. Pydantic v2 and Typer 0.12+ require modern Python versions. Check the requires-python field in pyproject.toml for exact version constraints.
Can I install VulnClaw without optional dependencies?
Yes. Running pip install vulnclaw installs only the 12 core dependencies. Optional packages like fastapi or chromadb are only installed when explicitly requested using extras notation (e.g., pip install "vulnclaw[web]").
Which dependency handles the AI chat features?
The OpenAI package (≥1.30.0) handles all LLM communication. It is imported in vulnclaw/agent/core.py and powers the AI-driven penetration testing commands like vulnclaw run.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →