Netw0rkNoob/VulnClaw
基于 AI Agent + MCP 工具链 + 渗透 Skill 编排, 配合大语言模型, 自然语言输入 → 自动完成「信息收集 → 漏洞发现 → 漏洞利用 → 报告生成」全流程。 observed · 2026-08-28
Health v2 · maintenance only
80/100
- Activity 99
- Release rhythm 96
- Longevity 9
Flags: young
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.
- gap_med: 9.5
- age_days: 137
- days_rel: 24
- days_push: 10
- n_releases_24m: 7
Adoption not part of the score
2997 stars · 401 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
VulnClaw is an AI-driven penetration testing CLI tool that combines an LLM agent, MCP toolchain, and curated pentest skills to automate the full workflow from reconnaissance to vulnerability discovery, exploitation, and report generation from natural-language input. It supports 14 OpenAI-compatible LLM providers, evidence-level anti-hallucination checks, and CLI/REPL, TUI, Web UI, and Docker modes.
Use cases
- run an authorized penetration test on a target website from a natural language prompt
- automate CTF flag hunting with AI
- generate structured pentest reports with PoC scripts
- perform reconnaissance, subdomain enumeration, and directory brute-forcing automatically
- orchestrate MCP tools like Burp and Chrome DevTools for web exploitation
- teach security students AI-assisted offensive testing workflows
When to choose
- you want natural-language-driven automation of authorized pentest or CTF workflows
- you need an agent that grounds conclusions in real tool output to avoid hallucinated results
- you want flexible LLM backend choice including local Ollama
- you need both terminal and web interfaces plus Docker deployment
When to avoid
- you need a traditional deterministic vulnerability scanner with stable signatures
- your targets are not explicitly authorized for testing
- you cannot expose an LLM API key or local model to your testing environment
- you require compliance-audited enterprise scanning tooling
Facets
cli-tool · maturity active
agent-framework mcp penetration-testing llm-inference cli chatbot penetration-testing security artificial-intelligence developer-tools cli python cross-platform self-hosted ai-pentest mcp-toolchain ctf red-team vulnerability-scanning report-generation anti-hallucination llm-agent offensive-security ai-agents command-line docker
2 sources
- readme: https://github.com/Netw0rkNoob/VulnClaw · fetched 2026-08-28 · d94bb105becc
- homepage: https://unclecheng-li.github.io/vulnclaw.com · fetched 2026-08-29 · d661c6320365
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| Netw0rkNoob/VulnClaw | main | 80 |
For agents
markdown · JSON · MCP: product_card(name="Netw0rkNoob/VulnClaw")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem