What Vulnerabilities Does VulnClaw Detect? A Complete Analysis of the AI-Driven Framework
VulnClaw detects injection flaws, known CVE exposures, security misconfigurations, weak HTTP headers, JWT vulnerabilities, and exposed JavaScript endpoints through a hybrid architecture combining LLM-driven analysis with deterministic security plugins.
VulnClaw is an AI-driven penetration-testing framework developed by Unclecheng-li that automates the discovery of security weaknesses in web applications. Understanding exactly what vulnerabilities VulnClaw detects requires examining its dual detection architecture, which pairs large language model reasoning with read-only security plugins. The system validates findings through real tool output to eliminate false positives before generating structured reports and executable proof-of-concept scripts.
LLM-Driven Vulnerability Discovery
The primary detection mechanism relies on a specialized vuln-discovery skill triggered by natural language queries such as "有什么漏洞" (what vulnerabilities exist). According to the Unclecheng-li/VulnClaw source code, the dispatcher in vulnclaw/skills/dispatcher.py (lines 15-17) maps these user intents to the vulnerability discovery skill.
This LLM-driven component identifies:
- Injection points – SQL injection (SQLi), cross-site scripting (XSS), and command injection vectors
- Known CVE exposures – Specific vulnerabilities like CVE-2024-1234 and similar disclosed weaknesses
- Security misconfigurations – Open administrative panels, default credentials, and insecure HTTP headers
- Logical flaws – Business logic vulnerabilities and authorization bypasses
- Platform-specific weaknesses – Targeted issues such as Tomcat authentication bypasses
The skill orchestrates LLM prompts against a knowledge base to surface these issues dynamically based on the target context.
Built-In Security Detection Plugins
Complementing the AI analysis, VulnClaw includes deterministic read-only plugins in vulnclaw/plugins/web/ that perform static vulnerability checks without generating network side effects. These plugins provide concrete evidence to ground the LLM's findings.
Security Header Hardening
The vulnclaw/plugins/web/headers.py file (lines 18-64) implements checks for missing or weak security headers. This plugin specifically validates:
- Content-Security-Policy – Flags unsafe directives like
"unsafe-inline"or"unsafe-eval", and validates presence ofdefault-srcorscript-srcdirectives - HTTP Strict Transport Security (HSTS) – Detects
max-age=0configurations that disable HSTS protection - X-Frame-Options – Identifies missing clickjacking protection
- Referrer-Policy – Checks for data leakage via referrer headers
JWT Configuration Validation
JWT security issues are detected in vulnclaw/plugins/web/jwt.py (lines 46-61). This plugin reports:
- Missing
alg(algorithm) headers - Weak signing algorithms that could facilitate token forgery
- Improper token validation logic
JavaScript Endpoint Discovery
The vulnclaw/plugins/web/js_endpoints.py module (lines 49-55) performs static analysis to uncover undocumented JavaScript API endpoints that may expose sensitive functionality or accept unauthenticated requests.
Knowledge Base Enrichment
For each identified vulnerability type, VulnClaw enriches findings with exploitation techniques and mitigation strategies. The vulnclaw/kb/retriever.py file (lines 291-300) implements a retrieval system that searches by vuln_type (e.g., "sqli", "xss", "rce") to return specific technique documentation and reference materials.
Report and Proof-of-Concept Generation
Once the system confirms a vulnerability through plugin evidence (preventing LLM hallucinations), it generates structured deliverables. The vulnclaw/report/generator.py file (lines 99-110) produces Markdown vulnerability reports, while vulnclaw/report/poc_builder.py constructs ready-to-run Python scripts that demonstrate the exploit.
# Trigger the LLM-driven discovery skill
from vulnclaw.agent import VulnClawAgent
agent = VulnClawAgent()
result = agent.run("帮我对 http://example.com 进行渗透测试")
# Dispatcher maps to vuln-discovery skill automatically
# Execute built-in security header plugin directly
from vulnclaw.plugins.runtime import PluginRuntime
runtime = PluginRuntime()
plugin_result = runtime.run_plugin(
plugin_id="builtin.web.headers",
options={"headers": {"server": "nginx", "content-type": "text/html"}}
)
# Returns PluginResult with CSP, HSTS, and X-Frame-Options findings
# Generate Python PoC for confirmed SQLi finding
from vulnclaw.report.poc_builder import PoCBuilder
poc = PoCBuilder().build(finding) # finding is a VulnerabilityFinding object
print(poc) # Executable Python script for verification
Summary
VulnClaw detects a comprehensive range of security issues through its hybrid architecture:
- Injection vulnerabilities (SQLi, XSS, command injection) via LLM analysis
- CVE exposures and platform-specific weaknesses through knowledge-base correlation
- Configuration flaws (admin panels, default credentials) via intelligent scanning
- Security header deficiencies (CSP, HSTS, X-Frame-Options) via
vulnclaw/plugins/web/headers.py - JWT weaknesses (missing algorithms, weak signing) via
vulnclaw/plugins/web/jwt.py - Hidden JavaScript endpoints via
vulnclaw/plugins/web/js_endpoints.py
The framework validates all findings against real plugin output before generating structured reports and executable proof-of-concept scripts.
Frequently Asked Questions
Does VulnClaw detect SQL injection and XSS vulnerabilities?
Yes. VulnClaw identifies injection flaws including SQL injection, cross-site scripting (XSS), and command injection through its LLM-driven vuln-discovery skill. The system maps natural language queries like "有什么漏洞" to this skill via vulnclaw/skills/dispatcher.py, which then analyzes the target for injection points and validates findings against its knowledge base.
How does VulnClaw avoid false positives when detecting vulnerabilities?
VulnClaw implements a "goal-driven" validation mechanism that requires concrete evidence from built-in plugins before confirming a finding. The LLM proposes potential vulnerabilities, but the system only reports issues verified by read-only plugins (such as those in vulnclaw/plugins/web/) that produce real tool output. This evidence-based approach prevents hallucinated vulnerabilities.
Can VulnClaw automatically generate proof-of-concept scripts?
Yes. For each confirmed vulnerability, VulnClaw produces both a structured Markdown report and an executable Python proof-of-concept script. The PoCBuilder class in vulnclaw/report/poc_builder.py constructs these scripts based on the specific VulnerabilityFinding object, allowing security researchers to verify or demonstrate the issue immediately.
What security headers does VulnClaw check for?
The framework specifically inspects for Content-Security-Policy (CSP) weaknesses, HTTP Strict Transport Security (HSTS) misconfigurations including max-age=0, X-Frame-Options for clickjacking protection, and Referrer-Policy settings. These checks are implemented in vulnclaw/plugins/web/headers.py (lines 18-64), which flags both missing headers and unsafe directive configurations.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →