Ross ROSS = Recommend OSS · open-source software intelligence for agents

KeygraphHQ/shannon

Shannon is an AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities before they reach production. observed · 2026-08-28

github.com/KeygraphHQ/shannon · homepage · TypeScript · AGPL-3.0 (copyleft) observed · 2026-08-28

Health v2 · maintenance only

84/100

  • Activity 99
  • Release rhythm 99
  • Longevity 24
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 5.5
  • age_days: 341
  • days_rel: 7
  • days_push: 7
  • n_releases_24m: 21

Full methodology

Adoption not part of the score

47226 stars · 5431 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

Shannon is an open-source, autonomous AI pentester for web applications and APIs that runs locally from the command line. It analyzes source code to form vulnerability hypotheses, then uses browser automation and CLI tools to execute real exploits, reporting only findings with working proof-of-concepts.

Use cases

  • run an automated penetration test against my web app before release
  • find exploitable vulnerabilities in my API with proof-of-concept exploits
  • scan my source code for attack vectors and validate them live
  • test for OWASP Top 10 issues like IDOR, SSRF, and XSS automatically
  • integrate agentic pentesting into my CI/CD pipeline
  • audit authorization and business logic flaws in my codebase
  • generate SARIF security findings for my appsec dashboard

When to choose

  • you want exploit-validated findings instead of noisy static scanner warnings
  • you need a self-hosted, BYOK AI pentester you run yourself
  • you want source-code-aware (whitebox) security testing of web apps and APIs
  • you need penetration-test evidence with reproduction steps for each finding

When to avoid

  • you need a managed enterprise platform with dashboards, SSO, and SLA policies
  • you require a permissive license for proprietary redistribution (it is AGPL-3.0)
  • you need blackbox-only testing with no source access (that is a paid Keygraph add-on)
  • you lack authorization to test the target application - this performs real exploits

Facets

cli-tool · maturity active

penetration-testing vulnerability-scanning agent-framework security web-scraping developer-tools security penetration-testing web-development apis artificial-intelligence cli cross-platform self-hosted ai-pentester offensive-security appsec owasp red-teaming exploit-validation sarif devsecops ethical-hacking whitebox-pentesting browser-automation ai-agents devops nodejs docker

10 sources

Member repositories

RepositoryRoleHealth v2
KeygraphHQ/shannonmain84

For agents

markdown · JSON · MCP: product_card(name="KeygraphHQ/shannon")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem