What Programming Languages Does VulnClaw Use? A Dual-Language Architecture Analysis

VulnClaw is built using Python 3 for its core penetration-testing engine and TypeScript for its modern React-based web frontend, creating a dual-language architecture that separates backend security logic from the user interface.

VulnClaw is an open-source penetration testing framework that leverages a strategic dual-language approach to deliver both powerful automation and modern user experiences. Understanding what programming languages VulnClaw uses is essential for contributors and security researchers who want to extend its capabilities or integrate it into existing workflows. The project combines Python's robust ecosystem for security tooling with TypeScript's type-safe frontend development to create a comprehensive vulnerability assessment platform.

Python 3: The Core Security Engine

The backbone of VulnClaw is written entirely in Python 3, serving as the primary runtime for all security automation, command-line interfaces, and AI agent logic. According to the Unclecheng-li/VulnClaw source code, the Python package is defined in pyproject.toml, which declares the entry point for the vulnclaw CLI command and manages the project's Python dependencies.

Entry Points and CLI Interface

The command-line interface is implemented using Typer in vulnclaw/cli/main.py, providing the primary entry point for users running scans from the terminal. The [project.scripts] section in pyproject.toml maps the vulnclaw command to this Python module, enabling direct invocation after installation.

Agent Logic and Penetration Testing

At the heart of the security engine lies vulnclaw/agent/solver.py, which implements the goal-driven solving loop for AI-powered penetration testing. This Python module handles the core automation logic, plugin orchestration, and MCP (Model Context Protocol) coordination that enables VulnClaw to perform vulnerability assessments programmatically.


# Example: programmatically invoke the CLI from Python

import subprocess

target = "http://example.com"
result = subprocess.run(
    ["vulnclaw", "run", target],
    capture_output=True,
    text=True,
)
print(result.stdout)

TypeScript: The Modern Web Frontend

Complementing the Python backend, VulnClaw employs TypeScript to power its React-based web interface built with Vite. The frontend runs in the browser and communicates with the Python backend via HTTP APIs, providing a graphical alternative to the CLI for managing scans and visualizing results.

Frontend Build Configuration

The frontend toolchain is configured in frontend/vite.config.ts, which handles the build process and development server setup for the React application. This TypeScript configuration ensures modern bundling standards while maintaining type safety throughout the development workflow.

API Integration and Type Safety

Type definitions for the REST API are centralized in frontend/src/types/api.ts, ensuring consistent interfaces between the Python FastAPI backend and the TypeScript frontend. The actual API communication layer resides in frontend/src/api/web.ts, which provides a thin type-safe wrapper around HTTP requests.

// Example: fetch a list of available plugins from the FastAPI server
import { apiClient } from "./api";

export async function loadPlugins() {
  const response = await apiClient.get<{ id: string; name: string }[]>(
    "/plugins/list"
  );
  return response.data;
}

Project Structure: Where Each Language Lives

The repository organizes code by language responsibility:

Summary

  • VulnClaw uses Python 3 for all backend security logic, CLI tools, and AI agent orchestration
  • TypeScript powers the frontend, providing type-safe React components that communicate with the Python backend via HTTP APIs
  • Key Python files include vulnclaw/cli/main.py for CLI entry points and vulnclaw/agent/solver.py for the penetration testing engine
  • Key TypeScript files include frontend/src/types/api.ts for API contracts and frontend/src/api/web.ts for HTTP client implementation
  • The dual-language approach separates concerns between security automation (Python) and user interface presentation (TypeScript)

Frequently Asked Questions

Is VulnClaw written entirely in Python?

No, VulnClaw is not written entirely in Python. While the core penetration-testing engine, CLI interface, and agent logic are implemented in Python 3, the project includes a modern web interface built with TypeScript, React, and Vite located in the frontend/ directory.

Why does VulnClaw use TypeScript for the frontend instead of Python?

TypeScript was chosen for the frontend to leverage modern browser capabilities, React's component model, and compile-time type safety for API communications. This separation allows the Python backend to focus exclusively on security automation while the TypeScript frontend handles the user interface and visualization layers.

How do the Python backend and TypeScript frontend communicate?

The Python backend exposes REST APIs via FastAPI, which the TypeScript frontend consumes through HTTP requests. The frontend/src/api/web.ts file implements the client-side HTTP wrapper, while frontend/src/types/api.ts ensures type-safe contracts between both languages.

Can I run VulnClaw without the TypeScript frontend?

Yes, you can run VulnClaw using only the Python components. The vulnclaw/cli/main.py module provides a full-featured command-line interface that operates independently of the web frontend. The TypeScript frontend is optional for users who prefer a graphical interface over terminal-based interaction.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →