Common Use Cases for VulnClaw: 9 AI-Powered Penetration Testing Workflows Explained

VulnClaw supports nine primary use cases including automated full-cycle penetration tests, continuous security monitoring, targeted reconnaissance, selective vulnerability scanning, exploit validation with PoC generation, and interactive modes for CTF competitions and red-team engagements.

VulnClaw is an extensible, AI-driven penetration testing platform developed by Unclecheng-li that combines a natural-language front-end with a goal-driven OODA solver engine. Understanding the common use cases for VulnClaw helps security teams leverage its architecture—implemented across vulnclaw/agent/solver.py, vulnclaw/agent/blackboard.py, and the plugin subsystem—to automate everything from quick vulnerability assessments to long-term continuous security operations.

Automated Full-Cycle and Continuous Testing

One-Click Full-Cycle Penetration Testing

The vulnclaw run <target> command initiates a complete assessment workflow that automatically triggers the solve engine in vulnclaw/agent/solver.py. This engine performs information gathering, vulnerability discovery, exploitation, and report generation without manual intervention. The solver uses a Fact/Intent blackboard implemented in vulnclaw/agent/blackboard.py to track progress and avoid exploration loops, while an evidence-level hallucination gate verifies claims before they are recorded as Facts.


# Execute a complete penetration test cycle

vulnclaw run https://target.example.com

Continuous and Periodic Security Monitoring

For long-running assessments, vulnclaw persistent <target> executes multiple cycles (defaulting to 100 rounds per cycle for up to 10 cycles) and automatically emits Markdown reports after each completion. This mode reuses the same blackboard across cycles and persists failure memory via the reflexion engine located in vulnclaw/agent/reflexion.py, enabling the system to learn from previous unsuccessful attempts.


# Run continuous testing with 200 rounds per cycle for 5 cycles

vulnclaw persistent 10.0.0.5 --rounds 200 --cycles 5

Targeted Testing and Validation

Reconnaissance-Only Information Gathering

When exploitation is not required, vulnclaw recon <target> invokes only the recon Skill from vulnclaw/skills/core/recon.py, orchestrating MCP services such as fetch, subdomain_enum, and dir_enum without triggering exploit tools. This use case is ideal for initial asset discovery and mapping network attack surfaces.


# Perform reconnaissance without exploitation

vulnclaw recon http://intranet.local

Selective Vulnerability Scanning

The vulnclaw scan command runs specific vulnerability detection plugins via the plugin runtime in vulnclaw/plugins/registry.py, which loads each plugin once per stage and merges results into SessionState.findings. Users can specify ports and targets to constrain the scan scope.


# Scan specific ports using available plugins

vulnclaw scan <target> --ports 80,443

Exploit Validation and PoC Generation

Security teams use vulnclaw exploit <target> --cve CVE-2024-1234 to validate specific vulnerabilities. Upon successful exploitation, the system generates a proof-of-concept script using report/poc_builder.py and adds structured results to the final report via report/generator.py. The exploitation Skill calls the python_execute tool when needed to verify exploitability.


# Validate a specific CVE and generate PoC

vulnclaw exploit 192.168.1.10 --cve CVE-2024-5678

Interactive Interfaces and Specialized Workflows

Interactive REPL and Terminal UI

Launching vulnclaw (default REPL) or vulnclaw tui starts a terminal-graphical workbench that displays the current origin → goal blackboard, safety budget, and recent findings. These UI components in cli/main.py and cli/tui.py are thin wrappers around the core agent, providing real-time visibility into the AI's decision-making process.


# Launch the terminal UI workbench

vulnclaw tui --target https://app.internal --mode quick

Web-Based Interface

The vulnclaw web command starts a local FastAPI server on 127.0.0.1:7788, exposing the entire workflow through a browser-based interface. The web UI code resides under frontend/ and provides the same goal-driven engine access as the CLI but through a graphical interface.


# Start the web UI server

vulnclaw web

# Access at http://127.0.0.1:7788

CTF and Security Training

VulnClaw includes built-in CTF Skills (ctf-web, ctf-crypto, ctf-misc) that automatically load reference documents from secknowledge-skill/references/ via the secknowledge-skill loader. This use case triggers payload-generation helpers and leverages external knowledge bases to solve capture-the-flag challenges.

Red-Team and Long-Term Engagements

For advanced simulations, teams combine persistent mode with custom MCP services defined in mcp/registry.py, such as Chrome DevTools or Burp Suite integration. This configuration simulates realistic web application attacks while persisting findings across multiple cycles using the reflexion engine's adaptive failure memory.


# Enable Chrome DevTools MCP for browser automation

vulnclaw config set mcp.servers.chrome-devtools.enabled true
vulnclaw config set mcp.servers.chrome-devtools.transport.command npx
vulnclaw config set mcp.servers.chrome-devtools.transport.args '["-y","chrome-devtools-mcp@latest"]'

Summary

  • One-click automation: The vulnclaw run command leverages the OODA solver in vulnclaw/agent/solver.py to execute complete penetration tests from reconnaissance to reporting.
  • Continuous monitoring: vulnclaw persistent uses the reflexion engine in vulnclaw/agent/reflexion.py to maintain context across multiple testing cycles.
  • Targeted operations: Reconnaissance, scanning, and exploitation modes allow selective engagement via specific Skills and plugins.
  • Flexible interfaces: Both terminal (cli/tui.py) and web (frontend/) interfaces provide access to the core goal-driven engine.
  • Extensible architecture: MCP services and the plugin registry in vulnclaw/plugins/registry.py support custom tools for CTF and red-team scenarios.

Frequently Asked Questions

What is the difference between vulnclaw run and vulnclaw persistent?

vulnclaw run executes a single, complete penetration testing cycle and terminates upon completion or budget exhaustion, making it ideal for point-in-time assessments. In contrast, vulnclaw persistent runs multiple cycles (defaulting to 100 rounds per cycle for up to 10 cycles) while maintaining state across iterations via the reflexion engine, making it suitable for continuous monitoring and long-term red-team operations.

How does VulnClaw prevent false positives during vulnerability scanning?

The platform implements an evidence-level hallucination gate within the solve engine (vulnclaw/agent/solver.py) that requires verified Facts to be backed by tool output before being recorded on the blackboard (vulnclaw/agent/blackboard.py). This ensures that only validated findings from actual tool execution—such as those from vulnclaw/skills/core/recon.py or exploitation plugins—are included in the final report.

Can VulnClaw integrate with existing security tools like Burp Suite?

Yes, VulnClaw supports integration with external tools through its MCP toolchain configured in mcp/registry.py. Users can enable services such as Chrome DevTools or Burp Suite via vulnclaw config set mcp.servers.<service>.enabled true, allowing the AI agent to leverage existing browser automation and HTTP proxy capabilities during testing workflows.

What file generates the PoC scripts after successful exploitation?

Upon successful exploitation, the PoC builder located in report/poc_builder.py generates proof-of-concept scripts. These are then incorporated into the structured final report by report/generator.py, which produces both Markdown and HTML outputs documenting the vulnerability and validation steps.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →