# What Vulnerabilities Does VulnClaw Detect? A Complete Analysis of the AI-Driven Framework

> Discover the vulnerabilities VulnClaw detects including injection flaws CVEs misconfigurations and more. Learn how this AI framework offers comprehensive security analysis.

- Repository: [Unclecheng/VulnClaw](https://github.com/Unclecheng-li/VulnClaw)
- Tags: deep-dive
- Published: 2026-07-03

---

**VulnClaw detects injection flaws, known CVE exposures, security misconfigurations, weak HTTP headers, JWT vulnerabilities, and exposed JavaScript endpoints through a hybrid architecture combining LLM-driven analysis with deterministic security plugins.**

VulnClaw is an AI-driven penetration-testing framework developed by Unclecheng-li that automates the discovery of security weaknesses in web applications. Understanding exactly what vulnerabilities VulnClaw detects requires examining its dual detection architecture, which pairs large language model reasoning with read-only security plugins. The system validates findings through real tool output to eliminate false positives before generating structured reports and executable proof-of-concept scripts.

## LLM-Driven Vulnerability Discovery

The primary detection mechanism relies on a specialized **vuln-discovery skill** triggered by natural language queries such as "有什么漏洞" (what vulnerabilities exist). According to the `Unclecheng-li/VulnClaw` source code, the dispatcher in [`vulnclaw/skills/dispatcher.py`](https://github.com/Unclecheng-li/VulnClaw/blob/main/vulnclaw/skills/dispatcher.py) (lines 15-17) maps these user intents to the vulnerability discovery skill.

This LLM-driven component identifies:

- **Injection points** – SQL injection (SQLi), cross-site scripting (XSS), and command injection vectors
- **Known CVE exposures** – Specific vulnerabilities like CVE-2024-1234 and similar disclosed weaknesses
- **Security misconfigurations** – Open administrative panels, default credentials, and insecure HTTP headers
- **Logical flaws** – Business logic vulnerabilities and authorization bypasses
- **Platform-specific weaknesses** – Targeted issues such as Tomcat authentication bypasses

The skill orchestrates LLM prompts against a knowledge base to surface these issues dynamically based on the target context.

## Built-In Security Detection Plugins

Complementing the AI analysis, VulnClaw includes deterministic **read-only plugins** in `vulnclaw/plugins/web/` that perform static vulnerability checks without generating network side effects. These plugins provide concrete evidence to ground the LLM's findings.

### Security Header Hardening

The [`vulnclaw/plugins/web/headers.py`](https://github.com/Unclecheng-li/VulnClaw/blob/main/vulnclaw/plugins/web/headers.py) file (lines 18-64) implements checks for missing or weak security headers. This plugin specifically validates:

- **Content-Security-Policy** – Flags unsafe directives like `"unsafe-inline"` or `"unsafe-eval"`, and validates presence of `default-src` or `script-src` directives
- **HTTP Strict Transport Security (HSTS)** – Detects `max-age=0` configurations that disable HSTS protection
- **X-Frame-Options** – Identifies missing clickjacking protection
- **Referrer-Policy** – Checks for data leakage via referrer headers

### JWT Configuration Validation

JWT security issues are detected in [`vulnclaw/plugins/web/jwt.py`](https://github.com/Unclecheng-li/VulnClaw/blob/main/vulnclaw/plugins/web/jwt.py) (lines 46-61). This plugin reports:

- Missing `alg` (algorithm) headers
- Weak signing algorithms that could facilitate token forgery
- Improper token validation logic

### JavaScript Endpoint Discovery

The [`vulnclaw/plugins/web/js_endpoints.py`](https://github.com/Unclecheng-li/VulnClaw/blob/main/vulnclaw/plugins/web/js_endpoints.py) module (lines 49-55) performs static analysis to uncover **undocumented JavaScript API endpoints** that may expose sensitive functionality or accept unauthenticated requests.

## Knowledge Base Enrichment

For each identified vulnerability type, VulnClaw enriches findings with exploitation techniques and mitigation strategies. The [`vulnclaw/kb/retriever.py`](https://github.com/Unclecheng-li/VulnClaw/blob/main/vulnclaw/kb/retriever.py) file (lines 291-300) implements a retrieval system that searches by `vuln_type` (e.g., `"sqli"`, `"xss"`, `"rce"`) to return specific technique documentation and reference materials.

## Report and Proof-of-Concept Generation

Once the system confirms a vulnerability through plugin evidence (preventing LLM hallucinations), it generates structured deliverables. The [`vulnclaw/report/generator.py`](https://github.com/Unclecheng-li/VulnClaw/blob/main/vulnclaw/report/generator.py) file (lines 99-110) produces Markdown vulnerability reports, while [`vulnclaw/report/poc_builder.py`](https://github.com/Unclecheng-li/VulnClaw/blob/main/vulnclaw/report/poc_builder.py) constructs ready-to-run Python scripts that demonstrate the exploit.

```python

# Trigger the LLM-driven discovery skill

from vulnclaw.agent import VulnClawAgent

agent = VulnClawAgent()
result = agent.run("帮我对 http://example.com 进行渗透测试")

# Dispatcher maps to vuln-discovery skill automatically

# Execute built-in security header plugin directly

from vulnclaw.plugins.runtime import PluginRuntime

runtime = PluginRuntime()
plugin_result = runtime.run_plugin(
    plugin_id="builtin.web.headers",
    options={"headers": {"server": "nginx", "content-type": "text/html"}}
)

# Returns PluginResult with CSP, HSTS, and X-Frame-Options findings

# Generate Python PoC for confirmed SQLi finding

from vulnclaw.report.poc_builder import PoCBuilder

poc = PoCBuilder().build(finding)  # finding is a VulnerabilityFinding object

print(poc)  # Executable Python script for verification

```

## Summary

VulnClaw detects a comprehensive range of security issues through its hybrid architecture:

- **Injection vulnerabilities** (SQLi, XSS, command injection) via LLM analysis
- **CVE exposures and platform-specific weaknesses** through knowledge-base correlation
- **Configuration flaws** (admin panels, default credentials) via intelligent scanning
- **Security header deficiencies** (CSP, HSTS, X-Frame-Options) via [`vulnclaw/plugins/web/headers.py`](https://github.com/Unclecheng-li/VulnClaw/blob/main/vulnclaw/plugins/web/headers.py)
- **JWT weaknesses** (missing algorithms, weak signing) via [`vulnclaw/plugins/web/jwt.py`](https://github.com/Unclecheng-li/VulnClaw/blob/main/vulnclaw/plugins/web/jwt.py)
- **Hidden JavaScript endpoints** via [`vulnclaw/plugins/web/js_endpoints.py`](https://github.com/Unclecheng-li/VulnClaw/blob/main/vulnclaw/plugins/web/js_endpoints.py)

The framework validates all findings against real plugin output before generating structured reports and executable proof-of-concept scripts.

## Frequently Asked Questions

### Does VulnClaw detect SQL injection and XSS vulnerabilities?

Yes. VulnClaw identifies injection flaws including SQL injection, cross-site scripting (XSS), and command injection through its LLM-driven vuln-discovery skill. The system maps natural language queries like "有什么漏洞" to this skill via [`vulnclaw/skills/dispatcher.py`](https://github.com/Unclecheng-li/VulnClaw/blob/main/vulnclaw/skills/dispatcher.py), which then analyzes the target for injection points and validates findings against its knowledge base.

### How does VulnClaw avoid false positives when detecting vulnerabilities?

VulnClaw implements a "goal-driven" validation mechanism that requires concrete evidence from built-in plugins before confirming a finding. The LLM proposes potential vulnerabilities, but the system only reports issues verified by read-only plugins (such as those in `vulnclaw/plugins/web/`) that produce real tool output. This evidence-based approach prevents hallucinated vulnerabilities.

### Can VulnClaw automatically generate proof-of-concept scripts?

Yes. For each confirmed vulnerability, VulnClaw produces both a structured Markdown report and an executable Python proof-of-concept script. The `PoCBuilder` class in [`vulnclaw/report/poc_builder.py`](https://github.com/Unclecheng-li/VulnClaw/blob/main/vulnclaw/report/poc_builder.py) constructs these scripts based on the specific `VulnerabilityFinding` object, allowing security researchers to verify or demonstrate the issue immediately.

### What security headers does VulnClaw check for?

The framework specifically inspects for Content-Security-Policy (CSP) weaknesses, HTTP Strict Transport Security (HSTS) misconfigurations including `max-age=0`, X-Frame-Options for clickjacking protection, and Referrer-Policy settings. These checks are implemented in [`vulnclaw/plugins/web/headers.py`](https://github.com/Unclecheng-li/VulnClaw/blob/main/vulnclaw/plugins/web/headers.py) (lines 18-64), which flags both missing headers and unsafe directive configurations.