<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Penetration-Testing on Text Matrix</title><link>https://txtmix.com/tags/penetration-testing/</link><description>Recent content in Penetration-Testing on Text Matrix</description><generator>Hugo</generator><language>zh-cn</language><lastBuildDate>Tue, 21 Jul 2026 20:06:14 +0800</lastBuildDate><atom:link href="https://txtmix.com/tags/penetration-testing/index.xml" rel="self" type="application/rss+xml"/><item><title>VulnClaw：从「固定轮数循环」到「目标驱动求解」的 AI 渗透测试 Agent</title><link>https://txtmix.com/posts/tech/unclecheng-li-vulnclaw-ai-pentest-agent-solver/</link><pubDate>Mon, 29 Jun 2026 21:02:57 +0800</pubDate><guid>https://txtmix.com/posts/tech/unclecheng-li-vulnclaw-ai-pentest-agent-solver/</guid><description>&lt;h2 id="它在解决什么具体问题">它在解决什么具体问题&lt;/h2>
&lt;p>AI 类渗透工具最近一年最大的痛点不是&amp;quot;能不能跑&amp;quot;，而是&lt;strong>跑起来后会陷入循环&lt;/strong>——弱模型经常在同一页面反复请求、嘴上说要测注入但不发请求包，或者反过来：擅自猜到下一步发现了什么 flag，但工具输出里其实根本没有那段字符串。&lt;code>Unclecheng-li/VulnClaw&lt;/code>（v0.3.x）的 README 把这两类问题都列成了&amp;quot;必须修&amp;quot;的设计目标，并在 0.3 系列做了底层引擎重构。&lt;/p></description></item></channel></rss>