VulnClaw Roadmap: AI-Driven Penetration Testing Framework Evolution

VulnClaw's roadmap progresses from a stable CLI/TUI/Web UI core with MCP services toward advanced session orchestration, expanded security skills, and a community plugin marketplace.

VulnClaw is an open-source AI-driven penetration testing framework that combines natural language interfaces with a modular MCP (Model Context Protocol) toolchain. The project roadmap, documented across the repository's architecture files and specialized skill documents, outlines a clear evolution from current stable features to long-term innovations in automated security testing.

Current Stable Features

The foundation of the VulnClaw roadmap rests on a robust set of production-ready capabilities documented in README_EN.md (lines 66-70).

Core interfaces include a natural-language CLI, REPL, TUI, and Web UI that provide multiple interaction modes for security researchers. The stable pentest flow implements a complete reconnaissance-to-reporting pipeline: recon → vulnerability discovery → exploitation → report generation.

MCP services currently in stable status include the fetch and memory tools, which handle web retrieval and context persistence. The framework also ships with 29 built-in encode/decode/crypto operations defined in the crypto-toolkit skill, accessible via vulnclaw/skills/specialized/crypto-toolkit/SKILL.md.

Near-Term Enhancements (P0/P1 Priority)

The immediate development phase focuses on promoting preview services to stable status and expanding the knowledge base.

MCP service stabilization targets the following preview tools for P0/P1 promotion: chrome-devtools, js-reverse, frida-mcp, adb-mcp, jadx, ida-pro-mcp, sequential-thinking, context7, and everything-search. These services extend the framework's capabilities into browser debugging, mobile analysis, and reverse engineering workflows.

Knowledge-base improvements include auto-loading reference materials and richer CVE lookup integrations. The Specialized Skills catalog will expand with additional CTF modules, AI-MCP capabilities, and intranet-pentest modules, as outlined in the MCP toolchain table in README_EN.md (lines 15-31).

Mid-Term Vision

The next major phase introduces sophisticated orchestration and reporting capabilities described in README_EN.md (lines 94-102).

Session lifecycle management will implement a full-cycle manager that orchestrates tool state, handles retries, and enables parallel execution across multiple targets. Dynamic prompt-assembly upgrades will leverage the sequential-thinking tool for context-rich reasoning and multi-step planning.

Enhanced reporting will introduce user-configurable auto-reporting with custom templates and HTML output formats. The Web UI will gain real-time log streaming and multi-target dashboards for managing complex engagements.

Long-Term Innovation

The strategic roadmap includes architectural shifts toward extensibility and on-device processing.

LLM provider expansion will support additional model providers and on-device inference capabilities. Sandboxed execution will introduce secure python_execute environments and WASM runners for safe code evaluation.

Community ecosystem development includes an open-source plugin marketplace for user-contributed tools and skills. Risk-matrix automation will map AI-MCP security testing results to automatic risk assessments, referencing the decision-tree methodology in vulnclaw/skills/specialized/crypto-toolkit/references/crypto-attacks-roadmap.md (lines 5-33).

Key Roadmap Documents

Crypto-Attack Decision Tree

The file vulnclaw/skills/specialized/crypto-toolkit/references/crypto-attacks-roadmap.md contains a concrete decision tree that determines which cryptographic attack to execute based on known parameters. This document exemplifies the roadmap's modular approach to specialized security tasks.

MCP Service Priority Matrix

The MCP toolchain table in README_EN.md lists current P0-P2 services, indicating which preview tools will be promoted to stable in upcoming releases.

Practical Roadmap Implementation

Executing the Current Stable Flow

Install the framework and trigger the autonomous pentest loop:


# Install from PyPI or source

pip install -U vulnclaw

# Execute one-shot pentest

vulnclaw run https://target.example.com

This command initiates the core workflow documented in the README's "What It Does" section.

Using Crypto-Toolkit Operations

Access the 29 built-in cryptographic operations programmatically:

from vulnclaw.tools import crypto_decode

# Decode Base64 strings

plain = crypto_decode(operation="base64_decode", input="TnNTY1RmLnBocA==")
print(plain)   # Output: "SnS5Rf.php"

Registering Future MCP Tools

The planned registration API for new tools follows this pattern from vulnclaw/mcp/registry.py:

from vulnclaw.mcp.registry import MCPRegistry

def my_custom_tool(args):
    # Implementation logic

    return result

# Register with priority level (planned for next release)

MCPRegistry.register(name="my_tool", func=my_custom_tool, priority=1)

Generating Persistent Reports

Execute long-running tests and automatically generate reports via vulnclaw/report/generator.py:

vulnclaw persistent 10.0.0.5 --rounds 150 --cycles 3

# Review generated Markdown report

cat ./vulnclaw-output/10.0.0.5_2024-07-03.md

Core Source Files

Summary

  • VulnClaw currently provides stable AI-driven pentesting through natural-language interfaces and core MCP services (fetch, memory).
  • Near-term development focuses on stabilizing preview tools including frida-mcp, adb-mcp, and sequential-thinking while expanding the knowledge base.
  • Mid-term goals introduce session lifecycle management, dynamic prompt assembly, and enhanced Web UI capabilities.
  • Long-term innovation targets sandboxed execution, a plugin marketplace, and multi-provider LLM support.
  • Source-backed planning is documented in crypto-attacks-roadmap.md and the MCP priority matrix within README_EN.md.

Frequently Asked Questions

What MCP services are currently stable in VulnClaw?

The fetch and memory services are currently in stable status, while tools like chrome-devtools, frida-mcp, and sequential-thinking remain in preview mode awaiting P0/P1 promotion. These services handle web retrieval, context persistence, and advanced debugging capabilities respectively.

How does the crypto-attack roadmap implementation work?

The roadmap is implemented as a decision tree in crypto-attacks-roadmap.md that evaluates known cryptographic parameters to determine attack strategies. This modular approach allows the framework to automatically select appropriate cryptanalysis techniques from the 29 available operations when encountering encoded or encrypted data.

What is the session lifecycle manager planned for mid-term development?

The session lifecycle manager will orchestrate tool state management, implement retry logic for failed operations, and enable parallel execution across multiple targets. This component, referenced in the agent architecture documentation, represents a shift from single-threaded execution to coordinated multi-target campaigning.

Will VulnClaw support community-developed plugins?

Yes, the long-term roadmap includes an open-source plugin marketplace that will allow security researchers to contribute custom tools and skills. The registration mechanism in vulnclaw/mcp/registry.py is designed to accommodate this extensibility, supporting dynamic tool registration with priority levels for execution ordering.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →