# KeygraphHQ/shannon

Shannon is an AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities before they reach production.

Repository: https://github.com/KeygraphHQ/shannon
Canonical: https://ross.abutalabs.com/products/shannon
Homepage: https://keygraph.io/
Language: TypeScript
License: AGPL-3.0
License Family: copyleft
Topics: penetration-testing, pentesting, security-audit, security-automation, security-tools, ai-penetration-testing, ai-security, cybersecurity, ethical-hacking, offensive-security, pentesting-tools, red-teaming, security, security-testing, api-security, appsec, devsecops, owasp, sarif, ci-cd
Last push: 2026-08-26T18:19:04+00:00

## Health v2 (maintenance only)
Score: 84/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 99, release rhythm 99, longevity 24
- inputs: {"age_days": 341, "days_push": 7, "days_rel": 7, "gap_med": 5.5, "n_releases_24m": 21}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 47226, forks 5431 (observed 2026-08-28T04:12:11.188065+00:00)

## What it is
Shannon is an open-source, autonomous AI pentester for web applications and APIs that runs locally from the command line. It analyzes source code to form vulnerability hypotheses, then uses browser automation and CLI tools to execute real exploits, reporting only findings with working proof-of-concepts.

## Use cases
- run an automated penetration test against my web app before release
- find exploitable vulnerabilities in my API with proof-of-concept exploits
- scan my source code for attack vectors and validate them live
- test for OWASP Top 10 issues like IDOR, SSRF, and XSS automatically
- integrate agentic pentesting into my CI/CD pipeline
- audit authorization and business logic flaws in my codebase
- generate SARIF security findings for my appsec dashboard

## When to choose
- you want exploit-validated findings instead of noisy static scanner warnings
- you need a self-hosted, BYOK AI pentester you run yourself
- you want source-code-aware (whitebox) security testing of web apps and APIs
- you need penetration-test evidence with reproduction steps for each finding

## When to avoid
- you need a managed enterprise platform with dashboards, SSO, and SLA policies
- you require a permissive license for proprietary redistribution (it is AGPL-3.0)
- you need blackbox-only testing with no source access (that is a paid Keygraph add-on)
- you lack authorization to test the target application - this performs real exploits

## Facets
- artifact type: cli-tool
- maturity: active
- function: penetration-testing, vulnerability-scanning, agent-framework, security, web-scraping, developer-tools
- domain: security, penetration-testing, web-development, apis, artificial-intelligence
- platform: cli, cross-platform, self-hosted
- tags: ai-pentester, offensive-security, appsec, owasp, red-teaming, exploit-validation, sarif, devsecops, ethical-hacking, whitebox-pentesting, browser-automation, ai-agents, devops, nodejs, docker

## Member repositories
- KeygraphHQ/shannon (main) score 84

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:12:11.188065+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T16:21:10.169772+00:00, confidence not recorded.
  - readme: https://github.com/KeygraphHQ/shannon (fetched 2026-08-28T04:12:11.188065+00:00, sha da432f648bc9)
  - homepage: https://keygraph.io/ (fetched 2026-08-29T07:45:12.906263+00:00, sha bb1d133d3e1c)
  - site_page: https://keygraph.io/docs (fetched 2026-08-29T07:45:12.931158+00:00, sha aa0c895bfabb)
  - site_page: https://keygraph.io/pricing.html (fetched 2026-08-29T07:45:12.914282+00:00, sha 304f1335db5f)
  - site_page: https://keygraph.io/agentic-whitebox-pentester.html (fetched 2026-08-29T07:45:12.916922+00:00, sha 88828a902d45)
  - site_page: https://keygraph.io/agentic-sast.html (fetched 2026-08-29T07:45:12.919984+00:00, sha 24d101beee2b)
  - site_page: https://keygraph.io/agentic-blackbox-pentester.html (fetched 2026-08-29T07:45:12.922478+00:00, sha d647d28d167b)
  - site_page: https://keygraph.io/business-logic-testing.html (fetched 2026-08-29T07:45:12.924960+00:00, sha ae733c0a2f99)
  - site_page: https://keygraph.io/sca.html (fetched 2026-08-29T07:45:12.926919+00:00, sha e8b0478f102c)
  - site_page: https://keygraph.io/secrets-scanning.html (fetched 2026-08-29T07:45:12.928996+00:00, sha 0e641da5da7b)
- Data as of 2026-08-30T08:39:29.467469+00:00.
