VulnClaw
A CLI agent for authorized pentesting: from a natural-language brief it runs recon, finds and verifies vulnerabilities and prepares a report
High risk
We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.
Why this level
- Actively attacks targets: scans, verifies and exploits vulnerabilities
- Runs arbitrary shell commands and Python code, gated by confirmation by default but with a full-access mode
Install
In your terminal, with SkillFoxx CLI
npx skillfoxx add cli/vulnclawDetects the agents on your machine, checks the risk and pins the version.
Other ways to install
Install the tool
pipx install vulnclawWithout pipx, pip install vulnclaw works too.
Install: pip install vulnclaw. Pick a provider, for example vulnclaw config provider ollama, set a key if needed via vulnclaw config set llm.api_key, check the environment with vulnclaw doctor and run vulnclaw. Work only on authorized targets.
Other ways from the author
pip install vulnclawInstall from PyPI. Then pick a provider and set a key via vulnclaw config.
This is third-party code. Review the repository files before installing.
What it does
VulnClaw is a standalone command-line pentest agent that takes a target and task in plain words and runs the loop itself: recon, vulnerability discovery, verification and a report with a ready Python PoC. By default it uses the solve engine, where the model decides the next step rather than following fixed rounds. Every tool result is written to an evidence store, and a claimed flag or finding is accepted only if it appears verbatim in real output, which guards against fabricated results. Dangerous tools, the shell, Python execution and exploit checks, require confirmation by default, and the approval modes are configurable from strict to full access. It connects to various LLMs and offers MCP tools, built-in reference skills, a CLI, a TUI and a local web interface.
Who it is for. For security professionals and CTF players who test only authorized targets and lab environments.
Good fit when
- You have written authorization for the target and want an agent that runs the whole loop
- You need to quickly run recon and vulnerability checks on an authorized range
- You are in a CTF or training and need a helper for web, crypto and task solving
- You need a structured report and a reproducible PoC after the check
Not a fit when
- You have no written authorization to test the target
- You need production defense rather than active vulnerability testing
- You cannot run arbitrary commands and exploits in your environment
Example request
Run a pentest of my authorized range 192.168.1.100 and produce a report with a PoCLimitations
The tool is only for authorized testing, CTF and labs; the user is responsible for legality, and it is public alpha, not a production defense control. It needs LLM access: some providers such as OpenAI and Anthropic are not reachable from Russia without a VPN, but local Ollama and providers reachable from Russia are supported. The built-in python_execute is a high-risk experiment, not a strict sandbox. The full web interface requires building the frontend from source; it is not in the PyPI package. Some MCP services, the browser and traffic capture, need a separate install.
How to disable. Remove the package with pip uninstall vulnclaw. Config and data live in the ~/.vulnclaw directory, which you can delete manually. If you ran it in Docker, stop the containers and remove the data volume.
Security check
- Actively attacks targets: scans, verifies and exploits vulnerabilities
- Runs arbitrary shell commands and Python code, gated by confirmation by default but with a full-access mode
README in short
The README describes VulnClaw as a standalone CLI pentest agent that runs recon, discovery, vulnerability verification and report generation from natural language. Its core is the solve engine, where the model drives the loop itself, with an evidence store and a gate against fabricated conclusions: a claimed result is accepted only on a verbatim match with real output. It supports many LLM providers, including local Ollama, MCP tools fetch, memory, chrome-devtools and burp, built-in tools for the shell, Python execution, scanning and encoding, and a set of reference skills for web, intranet, crypto and CTF. Installation is via pip or Docker, with CLI, REPL, TUI and a local web interface. Separate sections cover execution approval modes from confirming every command to full access. The security section stresses that the tool is for authorized testing only, is public alpha, and MIT licensed.
FAQ
Is it a legal tool?
Yes, when used only on authorized targets. The author explicitly requires written permission from the system owner, the tool targets pentesting, CTF, training and labs, and model-restriction bypass material is not included.
Can I avoid foreign LLMs?
Yes. Local Ollama and several providers are supported, along with a custom Base URL, so you can pick a model reachable without a VPN.
Related
A code security audit skill by Cloudflare: the agent runs recon, coverage-led hunting and independent verification of findings, then produces a structured repor
NVIDIA's open stack for running OpenClaw, Hermes and LangChain Deep Agents in OpenShell sandboxes with network policy and managed inference
Security scanner for agent skills and MCP servers: finds prompt injection, data exfiltration and supply chain risks before install
Static code analysis with rules that look like source code, plus a built-in MCP server for AI agents