Shannon proves selected web flaws by attacking them
Shannon combines white-box planning with dynamic testing. It reads the target repository to identify frameworks, entry points, and likely data flows, then explores a running web application and its APIs. Specialist agents look for injection, cross-site scripting, server-side request forgery, broken authentication, and broken authorization. A candidate reaches the report only after an exploitation step produces a working proof of concept.
That workflow can reduce one common security-review problem: long lists of speculative warnings that developers cannot reproduce. The final report includes evidence and remediation guidance, with structured JSON and optional SARIF 2.1.0 for downstream systems. Authenticated scans can describe login steps, test users, TOTP, email flows, focus areas, and rules of engagement. Interrupted workspaces can resume without repeating completed agents.
The open-source edition is deliberately narrower than Keygraph's commercial platform. It performs source-aware white-box pentesting on demand. The platform adds broad code parsing, SAST, dependency reachability, secret scanning, infrastructure checks, finding management, automated remediation, and point retesting. Read that edition boundary before assuming Shannon replaces an AppSec program.
What happened when we ran it
Our install at commit 53118c6 completed in 17 seconds. Pnpm added 413 packages and occupied 566 MB on disk. The monorepo build succeeded in 12 seconds inside an unprivileged Node 22 Debian container with 3 CPUs and 8 GB of RAM.
There was no test script or target, so our harness skipped tests. That is different from a passing suite. The repository has 4 CI workflow files, a Dockerfile, a Compose file, and monorepo workspaces, but no tests directory. Its 226 files and about 22,103 lines of source make it the smallest measured checkout in this batch.
We did not run a pentest because the sandbox had no provider secrets or authorized target. Therefore, our result says the measured commit installed and built. It does not validate exploit accuracy, false-negative rate, report quality, scan duration, provider cost, or the safety of any live target. Those need a controlled evaluation against an intentionally vulnerable application.
Real exploitation makes staging mandatory
Shannon is not passive. The README says agents can create accounts, submit forms, alter application state, and trigger outbound requests. A successful proof may leave rows, files, sessions, email, or network effects behind. The project explicitly says to use local, sandboxed, or staging targets with disposable data, and never production.
Written authorization and scope are operational inputs, not paperwork added later. Define target hosts, repositories, test accounts, excluded paths, allowed vulnerability classes, time window, data handling, and a stop contact. Isolate the application from production services. Use fake credentials, resettable databases, bounded outbound access, and provider keys with spending limits. Snapshot the target so it can be restored after 1 autonomous run.
Source code creates another attack surface. Shannon's safety guide warns against untrusted or adversarial repositories because text read by an AI system can carry prompt injection. Review the code source and instructions before mounting it, even though the worker receives the repository read-only. Read-only source does not protect the live target or provider credential from harmful tool choices.
Provider access can interrupt legitimate scans
The quick start needs Node.js 18 or newer, Docker, a target URL, a repository path, and AI credentials. Shannon supports Anthropic, OpenAI, xAI, AWS Bedrock, compatible Anthropic or OpenAI endpoints, and gateways or local servers. Keygraph does not proxy the model traffic, so the chosen provider receives whatever the agent sends.
Anthropic and OpenAI apply cyber-safety controls that can stop a scan. The README tells legitimate testers to clear the provider's safeguard process before the first run. This matters because an interruption late in a test can spend money without producing a complete report. Resumable workspaces help, but provider permission and account status must be settled first.
The current version supports ChatGPT Plus and Pro through OpenAI Codex. Claude Code subscriptions require Shannon 1.9.0, the last release built on the Claude Agent SDK; current Shannon does not support that subscription route. Pinning an old security tool solely for subscription billing is a poor trade unless its fixes and behavior have been reviewed.
Proof reduces noise but does not measure coverage
A working exploit establishes that one path was vulnerable in one tested state. It does not establish that an unreported class is absent. Model choice, authentication, seed data, feature flags, network reachability, and source interpretation all affect what Shannon can explore. The README also says local models are technically supported but may follow tool constraints less reliably than frontier models.
Human review remains necessary. Verify the proof in a restored environment, inspect whether the evidence supports the headline, and check the suggested fix against the actual trust boundary. Issue 410 reports a case where the reporting stage can reintroduce finding classes excluded by the exploitation gate, which is a useful reminder that generated narrative and gated artifacts can diverge.
Pair Shannon with deterministic tools. Semgrep can inspect code without a live attack, Nuclei can replay known templates, and ZAP can support repeatable DAST and manual investigation. Dependency, secret, configuration, and infrastructure scanning remain separate jobs in the open-source edition.
Version 2 is active and still exposes seams
Shannon v2.5.3 was released on 2026-08-24, the same date as the last repository push. GitHub listed 30 open issues and PRs. Current activity includes a sub-session disposal bug, a proposed security policy, provider setup work, retry safety, and the reporting-gate mismatch. The project is active, and the small queue is navigable.
The AGPL-3.0 license fits local open-source use, while organizations needing private redistribution, managed service rights, or other terms can seek a commercial license. More important than licensing for the first trial is containment: use an intentionally vulnerable target, a capped provider account, and disposable state. Shannon earns a place beside other scanners only when its proven findings add evidence the team can reproduce.

