VulnClaw
An AI-powered penetration testing tool that automates information gathering, vulnerability discovery, exploitation, and report generation.
- Region
- Domestic
- Pricing
- Free
- Open source
- Yes
- GitHub Stars
- ★ 2.7k
- Source
- GitHub
- Added
- 2026-08-10
- Last verified
- 2026-08-10
Overview
VulnClaw is an AI-driven command-line penetration testing tool that automatically executes the full workflow—from information gathering to vulnerability exploitation and report generation—via natural language input. It combines large language models with an MCP toolchain, supports 14 LLM providers, and comes with 50 built-in skills and tools. Suitable for authorized penetration testing, CTF competitions, and security education. Users only need to configure API keys and enter a target website to start automated penetration testing.
Key features
- ▪Natural language-driven penetration testing
- ▪Supports 14 LLM providers
- ▪Built-in 50 specialized Skills
- ▪Automatically generates structured reports
- ▪Offers Web UI mode
Use cases
Pros
- +Highly automated
- +Multi-model compatibility
- +Rich set of built-in tools
- +Detailed report output
Limitations / notes
- -Requires API keys
- -Higher learning curve
- -Requires internet connection
Who it's for
This overview was compiled by AI from public sources and may contain inaccuracies — please refer to the official site.
FAQ
Is it free?
Yes, VulnClaw is an open-source project and free to use, but you may need to pay for the API fees charged by LLM providers.
Does it support Chinese?
Yes, documentation and interface are primarily in Chinese, but English is also supported.
Can it be used commercially?
Yes, it can be used commercially, but must comply with the MIT license.
Do I need scientific internet access?
Some LLM providers may require scientific internet access; this depends on the selected provider.
Something wrong? Let us know on the About page and we'll fix it.