100100 Ideas AI
Submit Tool

VulnClaw

MCPOpen source

AI-driven penetration testing CLI that automates the full pentest workflow via natural language, MCP tools, and LLM agen

3.2kMIT

基于 AI Agent + MCP 工具链 + 渗透 Skill 编排, 配合大语言模型, 自然语言输入 → 自动完成「信息收集 → 漏洞发现 → 漏洞利用 → 报告生成」全流程。

Pros

  • +Automates full pentest lifecycle from recon to report generation
  • +Supports 14 LLM providers including local Ollama
  • +Includes 50 specialized skills and evidence-based anti-hallucination gates
  • +Offers CLI, TUI, and Web UI modes with Docker support

Cons

  • −Requires LLM API keys or subscription, adding cost
  • −Designed for authorized testing only; misuse risk
  • −Complex setup for custom MCP services like Burp or Chrome DevTools

Target audience: Security professionals, penetration testers, and CTF players seeking AI-assisted automation for authorized security assessments.

Related tools

Other open-source tools that share tags with VulnClaw.

headroom

MCPApache-2.0

Open-source context compression layer for AI agents, cutting tokens 60-95% for JSON and 15-20% for coding.

67k·LLM Ops·Open source