TrendWhat rose yesterday, every day at 07:30 KST · 한국어

GitHub · as of October 8, 2026 · View on GitHub →

Netw0rkNoob/VulnClaw

AI penetration testing agent

Automate the full penetration testing workflow with natural language commands

Type 'run a penetration test on this address' in the terminal, and the AI handles everything from information gathering to vulnerability discovery, exploitation, and report generation. VulnClaw combines large language models (LLMs) with a tool chain to create a penetration testing environment where users do not need to type commands for every step. It allows you to reduce repetitive manual tasks in CTF competitions or educational targets and experience a workflow where results are verified based on evidence collected by the AI.

Model-led autonomous exploration

Unlike approaches that follow fixed scripts or step-by-step templates, VulnClaw uses a structure where the model decides its next action. The framework provides only the goal, past conversations, evidence memory, and a list of available tools; the model then determines which tool to call, when to stop, and when to ask the user questions. During this process, all tool execution results are stored as-is in AgentState.evidence, and the model re-checks past data via evidence_search or evidence_view only when necessary. This design balances keeping the model's context intact while preventing massive output data from clouding current judgments.

Blocking false results and handling failures

To prevent the 'hallucination' phenomenon where the AI invents non-existent flags or vulnerabilities, VulnClaw applies an evidence-based verification gate. A conclusion or flag claimed by the model is accepted only if it exists literally in the actual tool output or explicitly cites a stored evidence number. The process does not end just because the model says it 'found' something; if there is no basis, the model is given the reason for rejection and prompted to continue exploring. Additionally, if the model repeatedly reads the same evidence or searches for evidence without new discoveries, a 'stall guard' activates, forcing the model to use a different tool or make a final judgment. This serves as a safety mechanism to prevent the AI from falling into infinite loops or reporting false successes.

Tool chain and extensibility

VulnClaw integrates with various external services through an MCP (Model Context Protocol)-based tool chain. In addition to the default fetch and memory services, you can connect chrome-devtools for browser automation and the burp service for HTTP traffic analysis. It also includes 29 encoding/decoding and encryption tools, local shell command execution, Python code execution, and over 50 specialized security skills (CTF, web, network, etc.). Skills are provided as reference materials loaded via load_skill_reference only when the model deems them necessary, rather than being forcibly injected into the system prompt, which efficiently manages the context window. It supports 13 LLM providers, allowing flexible selection of models suited to the user's environment, such as OpenAI, Anthropic, DeepSeek, or local Ollama.

Execution environment and safety boundaries

VulnClaw is written in Python and can be installed with pip install vulnclaw; it can be used via CLI, TUI (Terminal User Interface), or Web UI. Using the Web UI requires Node.js 18 or higher and a frontend build process. When running via Docker, localhost inside the container refers to the container itself, so you must use host.docker.internal to scan services on the host machine. The most important point is that this tool should only be used in 'authorized' environments. Using full_access mode allows the model to execute shell commands without approval, exposing it to the risk of prompt injection attacks from malicious input. Therefore, it is recommended to use it in isolated CTF environments, educational targets, or disposable virtual machines rather than actual production environments. Using auto_review mode allows only read-only commands to be executed automatically, while dangerous commands still require user approval, enabling safer operation.

By the numbers

Language
Python
Topics
ai · ai-agent · ai-tools · ctf · cybersecurity · openclaw · penetration-testing · penetration-testing-tools
Latest release
v0.4.0 · September 16, 2026
Last commit
September 16, 2026
Open issues
8
Open pull requests
0

Related repositories

Written by AI from this repository's README on October 6, 2026. GitHub's original is the reference.

View on GitHub → · Homepage