← All repos

shannon

Shannon is an AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities before they reach production.

agentsai-penetration-testingai-securitycybersecurityethical-hackingoffensive-securitypenetration-testingpentestingpentesting-toolsred-teamingsecuritysecurity-auditsecurity-automationsecurity-testingsecurity-tools
Browse cluster: Claude AI Agent Frameworks & MCP Tools
276commits
10contributors
5languages

Tech stack & purpose

Shannon is an autonomous AI pentester for web applications and APIs developed by Keygraph. It analyzes source code to identify attack vectors and executes real exploits to prove vulnerabilities before production deployment. The project is built as a TypeScript monorepo using pnpm workspaces and Turborepo for orchestration, with a CLI package published to npm that orchestrates Docker containers running Temporal workflows; the worker executes a five-phase penetration testing pipeline (pre-reconnaissance, reconnaissance, vulnerability analysis, exploitation, and reporting) using the pi harness agent framework with support for multiple AI providers including Anthropic, OpenAI, xAI, and AWS Bedrock, while employing browser automation via Playwright and TOTP generation for authenticated whitebox scans.

Community & reference links

Languages

TypeScript
92.6%
JavaScript
4.5%
Typst
2.1%
Dockerfile
0.7%
Shell
0.1%

Contributors