Common Use Cases for VulnClaw: 9 AI-Powered Penetration Testing Workflows Explained
VulnClaw supports nine primary use cases including automated full-cycle penetration tests, continuous security monitoring, targeted reconnaissance, selective vulnerability scanning, exploit validation with PoC generation, and interactive modes for CTF competitions and red-team engagements.
VulnClaw is an extensible, AI-driven penetration testing platform developed by Unclecheng-li that combines a natural-language front-end with a goal-driven OODA solver engine. Understanding the common use cases for VulnClaw helps security teams leverage its architecture—implemented across vulnclaw/agent/solver.py, vulnclaw/agent/blackboard.py, and the plugin subsystem—to automate everything from quick vulnerability assessments to long-term continuous security operations.
Automated Full-Cycle and Continuous Testing
One-Click Full-Cycle Penetration Testing
The vulnclaw run <target> command initiates a complete assessment workflow that automatically triggers the solve engine in vulnclaw/agent/solver.py. This engine performs information gathering, vulnerability discovery, exploitation, and report generation without manual intervention. The solver uses a Fact/Intent blackboard implemented in vulnclaw/agent/blackboard.py to track progress and avoid exploration loops, while an evidence-level hallucination gate verifies claims before they are recorded as Facts.
# Execute a complete penetration test cycle
vulnclaw run https://target.example.com
Continuous and Periodic Security Monitoring
For long-running assessments, vulnclaw persistent <target> executes multiple cycles (defaulting to 100 rounds per cycle for up to 10 cycles) and automatically emits Markdown reports after each completion. This mode reuses the same blackboard across cycles and persists failure memory via the reflexion engine located in vulnclaw/agent/reflexion.py, enabling the system to learn from previous unsuccessful attempts.
# Run continuous testing with 200 rounds per cycle for 5 cycles
vulnclaw persistent 10.0.0.5 --rounds 200 --cycles 5
Targeted Testing and Validation
Reconnaissance-Only Information Gathering
When exploitation is not required, vulnclaw recon <target> invokes only the recon Skill from vulnclaw/skills/core/recon.py, orchestrating MCP services such as fetch, subdomain_enum, and dir_enum without triggering exploit tools. This use case is ideal for initial asset discovery and mapping network attack surfaces.
# Perform reconnaissance without exploitation
vulnclaw recon http://intranet.local
Selective Vulnerability Scanning
The vulnclaw scan command runs specific vulnerability detection plugins via the plugin runtime in vulnclaw/plugins/registry.py, which loads each plugin once per stage and merges results into SessionState.findings. Users can specify ports and targets to constrain the scan scope.
# Scan specific ports using available plugins
vulnclaw scan <target> --ports 80,443
Exploit Validation and PoC Generation
Security teams use vulnclaw exploit <target> --cve CVE-2024-1234 to validate specific vulnerabilities. Upon successful exploitation, the system generates a proof-of-concept script using report/poc_builder.py and adds structured results to the final report via report/generator.py. The exploitation Skill calls the python_execute tool when needed to verify exploitability.
# Validate a specific CVE and generate PoC
vulnclaw exploit 192.168.1.10 --cve CVE-2024-5678
Interactive Interfaces and Specialized Workflows
Interactive REPL and Terminal UI
Launching vulnclaw (default REPL) or vulnclaw tui starts a terminal-graphical workbench that displays the current origin → goal blackboard, safety budget, and recent findings. These UI components in cli/main.py and cli/tui.py are thin wrappers around the core agent, providing real-time visibility into the AI's decision-making process.
# Launch the terminal UI workbench
vulnclaw tui --target https://app.internal --mode quick
Web-Based Interface
The vulnclaw web command starts a local FastAPI server on 127.0.0.1:7788, exposing the entire workflow through a browser-based interface. The web UI code resides under frontend/ and provides the same goal-driven engine access as the CLI but through a graphical interface.
# Start the web UI server
vulnclaw web
# Access at http://127.0.0.1:7788
CTF and Security Training
VulnClaw includes built-in CTF Skills (ctf-web, ctf-crypto, ctf-misc) that automatically load reference documents from secknowledge-skill/references/ via the secknowledge-skill loader. This use case triggers payload-generation helpers and leverages external knowledge bases to solve capture-the-flag challenges.
Red-Team and Long-Term Engagements
For advanced simulations, teams combine persistent mode with custom MCP services defined in mcp/registry.py, such as Chrome DevTools or Burp Suite integration. This configuration simulates realistic web application attacks while persisting findings across multiple cycles using the reflexion engine's adaptive failure memory.
# Enable Chrome DevTools MCP for browser automation
vulnclaw config set mcp.servers.chrome-devtools.enabled true
vulnclaw config set mcp.servers.chrome-devtools.transport.command npx
vulnclaw config set mcp.servers.chrome-devtools.transport.args '["-y","chrome-devtools-mcp@latest"]'
Summary
- One-click automation: The
vulnclaw runcommand leverages the OODA solver invulnclaw/agent/solver.pyto execute complete penetration tests from reconnaissance to reporting. - Continuous monitoring:
vulnclaw persistentuses the reflexion engine invulnclaw/agent/reflexion.pyto maintain context across multiple testing cycles. - Targeted operations: Reconnaissance, scanning, and exploitation modes allow selective engagement via specific Skills and plugins.
- Flexible interfaces: Both terminal (
cli/tui.py) and web (frontend/) interfaces provide access to the core goal-driven engine. - Extensible architecture: MCP services and the plugin registry in
vulnclaw/plugins/registry.pysupport custom tools for CTF and red-team scenarios.
Frequently Asked Questions
What is the difference between vulnclaw run and vulnclaw persistent?
vulnclaw run executes a single, complete penetration testing cycle and terminates upon completion or budget exhaustion, making it ideal for point-in-time assessments. In contrast, vulnclaw persistent runs multiple cycles (defaulting to 100 rounds per cycle for up to 10 cycles) while maintaining state across iterations via the reflexion engine, making it suitable for continuous monitoring and long-term red-team operations.
How does VulnClaw prevent false positives during vulnerability scanning?
The platform implements an evidence-level hallucination gate within the solve engine (vulnclaw/agent/solver.py) that requires verified Facts to be backed by tool output before being recorded on the blackboard (vulnclaw/agent/blackboard.py). This ensures that only validated findings from actual tool execution—such as those from vulnclaw/skills/core/recon.py or exploitation plugins—are included in the final report.
Can VulnClaw integrate with existing security tools like Burp Suite?
Yes, VulnClaw supports integration with external tools through its MCP toolchain configured in mcp/registry.py. Users can enable services such as Chrome DevTools or Burp Suite via vulnclaw config set mcp.servers.<service>.enabled true, allowing the AI agent to leverage existing browser automation and HTTP proxy capabilities during testing workflows.
What file generates the PoC scripts after successful exploitation?
Upon successful exploitation, the PoC builder located in report/poc_builder.py generates proof-of-concept scripts. These are then incorporated into the structured final report by report/generator.py, which produces both Markdown and HTML outputs documenting the vulnerability and validation steps.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →