Skip to content

Security: JMAN730/VulnClaw

Security

SECURITY.md

Security Policy

Authorized Testing & Legal Warning

VulnClaw is designed for legal, authorized penetration testing, security auditing, and educational Capture the Flag (CTF) challenges. Running automated scans or exploit payloads against unauthorized targets is illegal. Ensure you have explicit written consent from target owners before initiating any operations.

Reporting a Vulnerability

If you identify a security vulnerability in the VulnClaw agent framework (e.g. command injections, logic bypasses, or unsafe payload executions), please do not open a public issue.

Please report vulnerabilities privately by emailing the repository owner or using GitHub's private vulnerability reporting system.

We will review your submission and coordinate a patch swiftly.

There aren't any published security advisories