Netw0rkNoob/VulnClaw

Based on AI Agent + MCP toolchain + penetration-testing Skill orchestration, combined with large language models, it automatically completes the entire process from natural-language input to information gathering, vulnerability discovery, exploitation, and report generation.

About the project

VulnClaw is an AI-driven command-line penetration-testing agent that turns natural-language instructions into an automated workflow for reconnaissance, vulnerability discovery, exploitation, and report generation. It is intended for authorized penetration tests, CTF competitions, security teaching, and red-team exercises, using LLMs and MCP tools. The catalogue contains its specialized skills for security-testing tasks.

3.3kStars on the repository
50Mods indexed here, across every type
6d agoLast push, which is what freshness is scored on
MITLicence, which decides whether bodies are shown

redteam-cve-lookup

25

Netw0rkNoob/VulnClaw

Skill Claude CodeCodex

CVE lookup and applicability assessment domain card. Use after reconnaissance has identified products, versions, services, or fingerprints and red-team mode needs evidence-based CVE matching before deeper testing.

not rated 3.3k +73 6d ago A SkillSpector: pass 43 tokens original MIT

Netw0rkNoob/VulnClaw

Skill Claude CodeCodex

CVE validation domain card. Use after CVE lookup has produced applicable or candidate CVEs and red-team mode needs scoped evidence to decide whether to continue, pivot, or report.

not rated 3.3k +73 6d ago A SkillSpector: pass 42 tokens original MIT

Netw0rkNoob/VulnClaw

Skill Claude CodeCodex

Domain routing and boundary guidance for authorized insecure deserialization testing, including Java, PHP, Python, .NET, and gadget-chain analysis. Use when a task belongs to the deserialization testing domain and needs scope, evidence, pivot, or exit criteria.

not rated 3.3k +73 6d ago A SkillSpector: pass 57 tokens original MIT

Netw0rkNoob/VulnClaw

Skill Claude CodeCodex

Domain routing and boundary guidance for authorized defense evasion and bypass testing, including WAF bypass, AV/EDR evasion, logging considerations, and traffic obfuscation. Use when a task belongs to the evasion domain and needs scope, evidence, pivot, or exit criteria.

not rated 3.3k +73 6d ago A SkillSpector: pass 64 tokens original MIT

Netw0rkNoob/VulnClaw

Skill Claude CodeCodex

Domain routing and boundary guidance for authorized file operation vulnerability testing, including path traversal, arbitrary file read/write/upload, and LFI/RFI. Use when a task belongs to the file vulnerability domain and needs scope, evidence, pivot, or exit criteria.

not rated 3.3k +73 6d ago A SkillSpector: warn 56 tokens original MIT

Netw0rkNoob/VulnClaw

Skill Claude CodeCodex

Domain routing and boundary guidance for authorized general injection testing outside SQL injection, including NoSQL, LDAP, XPath, and expression language injection. Use when a task belongs to the general injection domain and needs scope, evidence, pivot, or exit criteria.

not rated 3.3k +73 6d ago A SkillSpector: pass 56 tokens original MIT

Netw0rkNoob/VulnClaw

Skill Claude CodeCodex

Domain routing and boundary guidance for authorized business logic vulnerability testing, including race conditions, flow bypass, price tampering, permission logic errors, and bulk operation abuse. Use when a task belongs to the logic testing domain and needs scope, evidence, pivot, or exit criteria.

not rated 3.3k +73 6d ago A SkillSpector: pass 61 tokens original MIT

Netw0rkNoob/VulnClaw

Skill Claude CodeCodex

Domain routing and boundary guidance for authorized mobile application security testing, including insecure storage, certificate pinning bypass, exposed components, and binary reverse engineering. Use when a task belongs to the mobile testing domain and needs scope, evidence, pivot, or exit criteria.

not rated 3.3k +73 6d ago A SkillSpector: pass 57 tokens original MIT

Netw0rkNoob/VulnClaw

Skill Claude CodeCodex

Domain routing and boundary guidance for authorized network-layer security testing, including exposed services, protocol downgrade, man-in-the-middle risks, and segmentation bypasses. Use when a task belongs to the network testing domain and needs scope, evidence, pivot, or exit criteria.

not rated 3.3k +73 6d ago A SkillSpector: pass 58 tokens original MIT

Netw0rkNoob/VulnClaw

Skill Claude CodeCodex

Domain routing and boundary guidance for authorized open redirect testing, including parameter redirects, meta or JavaScript redirects, and OAuth redirecturi abuse. Use when a task belongs to the open redirect domain and needs scope, evidence, pivot, or exit criteria.

not rated 3.3k +73 6d ago A SkillSpector: pass 57 tokens original MIT

Netw0rkNoob/VulnClaw

Skill Claude CodeCodex

Domain routing and boundary guidance for authorized payload construction and weaponization analysis, including shellcode, file format payloads, phishing payloads, and staged or stageless payload choices. Use when a task belongs to the payload construction domain and needs scope, evidence, pivot, or exit criteria.

not rated 3.3k +73 6d ago A SkillSpector: pass 64 tokens original MIT

Netw0rkNoob/VulnClaw

Skill Claude CodeCodex

Domain routing and boundary guidance for authorized post-exploitation testing after initial access, including privilege escalation, persistence, lateral movement, data collection, and cleanup considerations. Use when a task belongs to the post-exploitation domain and needs scope, evidence, pivot, or exit criteria.

not rated 3.3k +73 6d ago A SkillSpector: pass 61 tokens original MIT

Netw0rkNoob/VulnClaw

Skill Claude CodeCodex

Domain routing and boundary guidance for authorized reconnaissance and information gathering, including subdomain enumeration, port scanning, directory discovery, fingerprinting, and OSINT. Use when a task belongs to the recon domain and needs scope, evidence, pivot, or exit criteria.

not rated 3.3k +73 6d ago A SkillSpector: pass 58 tokens original MIT

Netw0rkNoob/VulnClaw

Skill Claude CodeCodex

Recon intake skill for first contact with a bare domain, URL, or IP address. Use to build an initial reconprofile and provide factual inputs for CVE lookup and attack-path routing.

not rated 3.3k +73 6d ago A SkillSpector: pass 44 tokens original MIT

Netw0rkNoob/VulnClaw

Skill Claude CodeCodex

Domain routing and boundary guidance for authorized reverse engineering analysis, including decompilation, debugging, protocol reversing, firmware extraction, and deobfuscation. Use when a task belongs to the reverse engineering domain and needs scope, evidence, pivot, or exit criteria.

not rated 3.3k +73 6d ago A SkillSpector: pass 59 tokens original MIT

Netw0rkNoob/VulnClaw

Skill Claude CodeCodex

Domain routing and boundary guidance for authorized SQL injection testing, including union-based, blind, error-based, stacked query, and second-order SQL injection variants. Use when a task belongs to the SQL injection domain and needs scope, evidence, pivot, or exit criteria.

not rated 3.3k +73 6d ago A SkillSpector: pass 59 tokens original MIT

Netw0rkNoob/VulnClaw

Skill Claude CodeCodex

Domain routing and boundary guidance for authorized SSRF testing, including basic SSRF, blind SSRF, protocol smuggling, and cloud metadata access paths. Use when a task belongs to the SSRF domain and needs scope, evidence, pivot, or exit criteria.

not rated 3.3k +73 6d ago C SkillSpector: warn 60 tokens original MIT

Netw0rkNoob/VulnClaw

Skill Claude CodeCodex

Domain routing and boundary guidance for authorized server-side template injection testing, including Jinja2, Twig, Freemarker, Velocity, and Thymeleaf engines. Use when a task belongs to the SSTI domain and needs scope, evidence, pivot, or exit criteria.

not rated 3.3k +73 6d ago A SkillSpector: pass 61 tokens original MIT

Netw0rkNoob/VulnClaw

Skill Claude CodeCodex

Domain routing and boundary guidance for authorized subdomain takeover testing, including dangling CNAME records, NS takeover, and cloud service takeover paths such as S3, Azure, and Heroku. Use when a task belongs to the subdomain takeover domain and needs scope, evidence, pivot, or exit criteria.

not rated 3.3k +73 6d ago A SkillSpector: pass 70 tokens original MIT

Netw0rkNoob/VulnClaw

Skill Claude CodeCodex

Routing and boundary guidance for authorized general web application security testing. Use as a web testing router when the attack surface should be dispatched to more specific web vulnerability skills.

not rated 3.3k +73 6d ago A SkillSpector: pass 38 tokens original MIT

Netw0rkNoob/VulnClaw

Skill Claude CodeCodex

Domain routing and boundary guidance for authorized cross-site scripting testing, including reflected, stored, DOM-based, mXSS, and CSP bypass variants. Use when a task belongs to the XSS domain and needs scope, evidence, pivot, or exit criteria.

not rated 3.3k +73 6d ago A SkillSpector: pass 58 tokens original MIT

Netw0rkNoob/VulnClaw

Skill Claude CodeCodex

Domain routing and boundary guidance for authorized XXE testing, including file read, SSRF, blind XXE, and parameter entity variants. Use when a task belongs to the XXE domain and needs scope, evidence, pivot, or exit criteria.

not rated 3.3k +73 6d ago A SkillSpector: pass 57 tokens original MIT

secknowledge-skill

47

Netw0rkNoob/VulnClaw

Skill Claude CodeCodex

A knowledge base for testing the security of websites, software, and AI systems, including agents and language models.

not rated 3.3k +73 6d ago A SkillSpector: pass 321 tokens original MIT

web-pentest

48

Netw0rkNoob/VulnClaw

Skill Claude CodeCodex

A step-by-step guide for testing web applications, which are websites and online services that accept user requests and data.

not rated 3.3k +73 6d ago A SkillSpector: pass 43 tokens original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: