</>MCP Agents Market
Agent

VulnClaw

by Netw0rkNoob3.2kPythonUpdated 2026-09-01

基于 AI Agent + MCP 工具链 + 渗透 Skill 编排, 配合大语言模型, 自然语言输入 → 自动完成「信息收集 → 漏洞发现 → 漏洞利用 → 报告生成」全流程。

VulnClaw is an AI-driven penetration testing agent that combines large language models with the Model Context Protocol (MCP) toolchain to automate security assessments. It accepts natural-language objectives and autonomously executes the full penetration testing workflow: reconnaissance, vulnerability discovery, exploitation, and report generation. The agent uses a model-directed solve engine that lets the LLM decide which tools to call and when to stop, rather than following fixed playbooks. VulnClaw integrates with OpenAI-compatible APIs, Anthropic Claude, DeepSeek, and 10+ other LLM providers, and is designed for authorized security testing, CTF competitions, red-team exercises, and security education.

Key Features

Model-directed solve engine that lets the LLM autonomously choose tools and decide when objectives are met
Evidence-based memory system with anti-hallucination gates that reject claims not supported by actual tool output
14 LLM provider integrations including OpenAI, Anthropic, DeepSeek, MiniMax, Moonshot, and local Ollama
Four MCP servers: fetch (HTTP requests), memory, chrome-devtools (browser automation), and burp (traffic interception)
50+ specialized skill references covering CTF, web exploitation, reverse engineering, and authorized red-team techniques
Built-in tools for encoding/decoding (29 operations), Python/shell execution, batch HTTP probing, and runtime differential analysis
Structured reasoning with adaptive reflection that escalates payloads (L0-L4) when filters are detected
Automatic Markdown report generation with proof-of-concept Python scripts and curl replay commands

Use Cases

  • 01Automated penetration testing of authorized web applications and APIs
  • 02CTF competition automation for reconnaissance and flag discovery
  • 03Red-team exercises with continuous multi-cycle testing and incremental reporting
  • 04Security education and training labs with natural-language driven exploitation
  • 05Vulnerability research and PoC generation for known CVEs
  • 06Authorized security audits with structured evidence collection and compliance reporting

Related Agents

View more

VulnClaw — FAQ

What is VulnClaw?+

VulnClaw is an AI-powered penetration testing agent that uses large language models and the MCP toolchain to automate reconnaissance, vulnerability discovery, exploitation, and report generation from natural-language instructions. It is designed exclusively for authorized security testing scenarios.

How do I install VulnClaw?+

Install VulnClaw via pip with 'pip install vulnclaw', then configure an LLM provider using 'vulnclaw config provider <name>' and set your API key with 'vulnclaw config set llm.api_key <your-key>'. Run 'vulnclaw doctor' to verify your environment.

Which LLM providers does VulnClaw support?+

VulnClaw supports 14 providers: OpenAI, Anthropic Claude, MiniMax, DeepSeek, Zhipu GLM, Moonshot Kimi, Qwen, SiliconFlow, Doubao, Baichuan, StepFun, SenseTime, Yi, and local Ollama. You can switch providers with a single command.

Do I need API keys or other prerequisites?+

You need Python 3.10+, an API key from one of the supported LLM providers (or a local Ollama setup), and optionally Node.js for MCP browser automation. Nmap is recommended for port scanning features.

Is VulnClaw free to use?+

VulnClaw itself is free and open-source under the MIT license. However, you will incur costs from your chosen LLM provider's API usage. Local Ollama models are free but require compatible hardware.

Can VulnClaw run in a web interface?+

Yes, VulnClaw offers both CLI/REPL, a TUI workspace ('vulnclaw tui'), and a web UI accessible via 'vulnclaw web' (default http://127.0.0.1:7788). Docker deployment is also supported for containerized environments.

How do I install VulnClaw?+

Open the source repository on GitHub and follow its README. VulnClaw is a agent — MCP Agents Market links you directly to the official repo.

Is VulnClaw free?+

VulnClaw is an open-source project hosted on GitHub. Check the repository for its license and any usage requirements.

Related searches