VulnClaw MCP Services Integration: The 4 Built-in Tools Explained
VulnClaw ships with a built-in MCP (Modular Command Protocol) subsystem that supports four services—fetch, memory, chrome-devtools, and burp—enabling HTTP testing, persistent storage, browser automation, and traffic interception.
The Unclecheng-li/VulnClaw repository implements a modular MCP services architecture designed to unify external security tools under a single protocol. This subsystem allows security researchers to orchestrate network requests, browser automation, and proxy-based testing through standardized tool definitions exposed via the Web UI backend.
Understanding VulnClaw's MCP Architecture
At startup, VulnClaw initializes an MCPLifecycleManager that reads service definitions from the mcp.servers configuration block. According to the source code in vulnclaw/mcp/lifecycle.py, this manager handles the startup, monitoring, and shutdown of MCP server processes. The registry module at vulnclaw/mcp/registry.py maintains a catalog of available servers and the specific tools each exposes.
The diagnostics routine, implemented in vulnclaw/web/services/mcp_service.py, provides runtime visibility through the get_mcp_diagnostics() function. This builds a MCPDiagnosticsView containing service states, tool counts, and health information accessible via the Web UI. For human-readable setup instructions, refer to docs/mcp-deployment.md in the repository root.
The Four Built-in MCP Services
VulnClaw supports four distinct MCP service execution modes, ranging from built-in local handlers to external stdio and sse-based servers.
Fetch Service (HTTP Testing)
The fetch service operates in local mode using httpx for simple HTTP requests and API testing. Built-in and enabled by default, this service requires no external dependencies. It provides immediate network probing capabilities without additional configuration.
Memory Service (Persistent Storage)
The memory service maintains cross-session persistent storage using local JSON files. Also built-in and enabled by default, this service allows tools to retain state between VulnClaw sessions, storing data in the user's configuration directory.
Chrome DevTools Service (Browser Automation)
The chrome-devtools service enables browser automation, JavaScript execution, screenshot capture, and performance analysis. This service runs as an stdio MCP server using Node.js and auto-installs via npx when enabled. It exposes 31+ tools, including chrome-open-and-screenshot for automated page capture.
Unlike the built-in services, chrome-devtools requires an external Chrome instance running with remote debugging enabled on port 9222.
Burp Service (Traffic Interception)
The burp service provides HTTP traffic interception, replay, and scanning capabilities as a drop-in replacement for Yakit. Implemented as an sse MCP server using Java, this service requires an external Burp Suite extension to be installed and running. It connects via Server-Sent Events to integrate Burp's proxy functionality into VulnClaw workflows.
Configuring MCP Services in VulnClaw
Service configurations reside in the user configuration file under the mcp.servers key, typically located at ~/.vulnclaw/config.yaml.
Service Definitions and Configuration Files
To enable the Chrome DevTools service, add the following configuration block:
mcp:
servers:
chrome-devtools:
enabled: true
transport:
type: stdio
command: npx
args:
- "-y"
- "chrome-devtools-mcp@latest"
- "--browser-url=http://127.0.0.1:9222"
The burp service follows a similar pattern but uses sse transport type and requires connection details for the Burp Suite extension.
Enabling Services via CLI
VulnClaw provides a command-line interface for quick configuration changes without editing YAML files directly:
vulnclaw config set mcp.servers.burp.enabled true
Accessing MCP Diagnostics Programmatically
The vulnclaw/web/services/mcp_service.py module exposes the get_mcp_diagnostics() function for runtime inspection of service health:
from vulnclaw.web.services.mcp_service import get_mcp_diagnostics
diagnostics = get_mcp_diagnostics()
print(f"Total services: {diagnostics.total_services}")
for svc in diagnostics.services:
print(f"- {svc.name} (enabled={svc.enabled}) – "
f"mode={svc.execution_mode}, tools={svc.tool_count}")
This returns a MCPDiagnosticsView object containing the total service count, individual service states, execution modes, and available tool counts for each registered MCP service.
Executing MCP Tools in Security Workflows
Once services are enabled, VulnClaw exposes their tools through the task service. For example, to capture a screenshot using the Chrome DevTools service:
from vulnclaw.web.services.task_service import run_task
run_task("chrome-open-and-screenshot", {"url": "http://example.com"})
This executes the chrome-open-and-screenshot tool provided by the chrome-devtools MCP server, returning the screenshot data through VulnClaw's standard task pipeline.
Summary
- VulnClaw integrates four MCP services: fetch (local HTTP), memory (JSON persistence), chrome-devtools (browser automation), and burp (traffic interception).
- Service definitions live in
mcp.serversconfiguration, managed byMCPLifecycleManagerinvulnclaw/mcp/lifecycle.py. - Runtime diagnostics are available via
get_mcp_diagnostics()invulnclaw/web/services/mcp_service.py. - Chrome DevTools requires Node.js and external Chrome debugging port; Burp requires the Burp Suite MCP extension.
- Tools from enabled services are accessible programmatically through
run_task()invulnclaw/web/services/task_service.py.
Frequently Asked Questions
What MCP services does VulnClaw support by default?
VulnClaw supports four MCP services out-of-the-box: fetch for HTTP testing via httpx, memory for JSON-based persistent storage, chrome-devtools for browser automation via Node.js stdio, and burp for HTTP interception via SSE. The fetch and memory services are built-in and enabled by default, while chrome-devtools and burp require external dependencies.
How do I enable the Chrome DevTools MCP service in VulnClaw?
Enable the Chrome DevTools service by setting mcp.servers.chrome-devtools.enabled to true in ~/.vulnclaw/config.yaml with stdio transport configured to run npx chrome-devtools-mcp@latest. You must also have Chrome running with remote debugging enabled on http://127.0.0.1:9222 for the service to function.
Where are MCP service configurations stored in VulnClaw?
MCP service configurations are stored in the user configuration file under the mcp.servers key, typically located at ~/.vulnclaw/config.yaml. The MCPLifecycleManager reads these definitions at startup to initialize the appropriate server processes.
Can I use Burp Suite Professional with VulnClaw's MCP integration?
Yes, the burp service acts as a drop-in replacement for Yakit and supports Burp Suite Professional through the MCP extension. Configure it by enabling mcp.servers.burp with sse transport type, ensuring the Burp Suite MCP extension is installed and running to handle the Server-Sent Events connection.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →