mrkeyoor.com_
Mon 28 Sept 00:15 UTC
Dev Toolsevaluationupdated 26 Aug 2026

shannon review

Shannon is an AI pentester that reads a web application's source, explores the running target, and attempts real exploits against its pages and APIs. It reports findings only when it can produce a proof of concept, with Markdown, JSON, and optional SARIF output.

+134stars / 7d
Verdict

Our Shannon run installed 413 packages and built in 12 seconds, but the repository supplied no test target, so build success is the strongest automated result we can report. Use it as a second set of hands for an authorized staging pentest when reproducible exploitation matters. Do not use it as a safety certificate, and do not let an autonomous attack touch production data.

We ran it

Lab card: what happened when we ran shannonScreenshot of shannon (keygraph.io)
Install✓ · 17s413 packages · 566 MB
Build✓ · 12s
Testsn/ano test script
Repo226 files~22,103 lines of source · 27.2 MB · 4 CI workflows · Dockerfile

Answers from our run

Does shannon build from source?

Dependencies installed in 17 seconds (413 packages), and the build succeeded in 12 seconds. We cloned commit 53118c6 into a clean Debian container with 3 CPUs and no project-specific setup.

Does shannon have tests you can run?

Not through a standard command: the project exposes no test script or target that our harness could run.

Who should not use shannon?

Anyone scanning production or a system without explicit written authorization: the README warns that exploits can create users, submit forms, mutate data, and trigger outbound requests.

What are the alternatives to shannon?

OWASP ZAP, Nuclei, Semgrep. Our Shannon run installed 413 packages and built in 12 seconds, but the repository supplied no test target, so build success is the strongest automated result we can report.

Setup3/5Short CLI path, with Docker, provider, source, and target required
Docs5/5Direct safety, provider, platform, resume, and coverage guidance
Community4/5Current release and focused issue activity
Maturity3/5Version 2 is active, but the repository exposes no test target

Discussed on

  1. hnShannon – Autonomous AI Hacker4 points
  2. hnShannon: Claude Code for Pen Testing: #1 on Github today3 points
  3. hnAutonomous AI hacker to find actual exploits in your web apps3 points

Who it’s for

Security teams testing an owned, disposable staging environment with written scope.
Developers who want source-guided evidence for injection, XSS, SSRF, authentication, and authorization flaws.
Teams able to review every finding and absorb provider cost for a long autonomous scan.
CI owners who want proven findings exported as SARIF 2.1.0.

Who it’s NOT for

Anyone scanning production or a system without explicit written authorization: the README warns that exploits can create users, submit forms, mutate data, and trigger outbound requests.
Teams wanting dependency, secret, IaC, container, or broad static-analysis coverage from the open-source edition; the edition table reserves that wider analysis for Keygraph's platform.
Users who treat proof by exploitation as proof of safety: Shannon targets named vulnerability classes and says findings still need human review.
People feeding it untrusted repositories without a prompt-injection review: the safety section explicitly warns against adversarial source code.
Operators expecting a free model: scans need provider credentials or a subscription path, and the README says a full run may take roughly 1 to 1.5 hours and incur API cost.

Setup reality

Our pnpm install succeeded in 17 seconds with 413 packages and used 566 MB on disk. The build passed in 12 seconds at commit 53118c6. There was no test script or target, so we skipped tests rather than treating the build as a test pass.

The recommended path needs Node.js 18 or newer, Docker for an ephemeral worker, an AI provider credential, a live target, and its source path. Providers may require cyber-safeguard clearance before legitimate testing.

Shannon mounts source read-only, but its agents actively attack the target. Use a disposable local or staging system with fake data, isolated credentials, outbound controls, a written scope, and authorization. Never point the quick start at production.

Shannon proves selected web flaws by attacking them

Shannon combines white-box planning with dynamic testing. It reads the target repository to identify frameworks, entry points, and likely data flows, then explores a running web application and its APIs. Specialist agents look for injection, cross-site scripting, server-side request forgery, broken authentication, and broken authorization. A candidate reaches the report only after an exploitation step produces a working proof of concept.

That workflow can reduce one common security-review problem: long lists of speculative warnings that developers cannot reproduce. The final report includes evidence and remediation guidance, with structured JSON and optional SARIF 2.1.0 for downstream systems. Authenticated scans can describe login steps, test users, TOTP, email flows, focus areas, and rules of engagement. Interrupted workspaces can resume without repeating completed agents.

The open-source edition is deliberately narrower than Keygraph's commercial platform. It performs source-aware white-box pentesting on demand. The platform adds broad code parsing, SAST, dependency reachability, secret scanning, infrastructure checks, finding management, automated remediation, and point retesting. Read that edition boundary before assuming Shannon replaces an AppSec program.

What happened when we ran it

Our install at commit 53118c6 completed in 17 seconds. Pnpm added 413 packages and occupied 566 MB on disk. The monorepo build succeeded in 12 seconds inside an unprivileged Node 22 Debian container with 3 CPUs and 8 GB of RAM.

There was no test script or target, so our harness skipped tests. That is different from a passing suite. The repository has 4 CI workflow files, a Dockerfile, a Compose file, and monorepo workspaces, but no tests directory. Its 226 files and about 22,103 lines of source make it the smallest measured checkout in this batch.

We did not run a pentest because the sandbox had no provider secrets or authorized target. Therefore, our result says the measured commit installed and built. It does not validate exploit accuracy, false-negative rate, report quality, scan duration, provider cost, or the safety of any live target. Those need a controlled evaluation against an intentionally vulnerable application.

Real exploitation makes staging mandatory

Shannon is not passive. The README says agents can create accounts, submit forms, alter application state, and trigger outbound requests. A successful proof may leave rows, files, sessions, email, or network effects behind. The project explicitly says to use local, sandboxed, or staging targets with disposable data, and never production.

Written authorization and scope are operational inputs, not paperwork added later. Define target hosts, repositories, test accounts, excluded paths, allowed vulnerability classes, time window, data handling, and a stop contact. Isolate the application from production services. Use fake credentials, resettable databases, bounded outbound access, and provider keys with spending limits. Snapshot the target so it can be restored after 1 autonomous run.

Source code creates another attack surface. Shannon's safety guide warns against untrusted or adversarial repositories because text read by an AI system can carry prompt injection. Review the code source and instructions before mounting it, even though the worker receives the repository read-only. Read-only source does not protect the live target or provider credential from harmful tool choices.

Provider access can interrupt legitimate scans

The quick start needs Node.js 18 or newer, Docker, a target URL, a repository path, and AI credentials. Shannon supports Anthropic, OpenAI, xAI, AWS Bedrock, compatible Anthropic or OpenAI endpoints, and gateways or local servers. Keygraph does not proxy the model traffic, so the chosen provider receives whatever the agent sends.

Anthropic and OpenAI apply cyber-safety controls that can stop a scan. The README tells legitimate testers to clear the provider's safeguard process before the first run. This matters because an interruption late in a test can spend money without producing a complete report. Resumable workspaces help, but provider permission and account status must be settled first.

The current version supports ChatGPT Plus and Pro through OpenAI Codex. Claude Code subscriptions require Shannon 1.9.0, the last release built on the Claude Agent SDK; current Shannon does not support that subscription route. Pinning an old security tool solely for subscription billing is a poor trade unless its fixes and behavior have been reviewed.

Proof reduces noise but does not measure coverage

A working exploit establishes that one path was vulnerable in one tested state. It does not establish that an unreported class is absent. Model choice, authentication, seed data, feature flags, network reachability, and source interpretation all affect what Shannon can explore. The README also says local models are technically supported but may follow tool constraints less reliably than frontier models.

Human review remains necessary. Verify the proof in a restored environment, inspect whether the evidence supports the headline, and check the suggested fix against the actual trust boundary. Issue 410 reports a case where the reporting stage can reintroduce finding classes excluded by the exploitation gate, which is a useful reminder that generated narrative and gated artifacts can diverge.

Pair Shannon with deterministic tools. Semgrep can inspect code without a live attack, Nuclei can replay known templates, and ZAP can support repeatable DAST and manual investigation. Dependency, secret, configuration, and infrastructure scanning remain separate jobs in the open-source edition.

Version 2 is active and still exposes seams

Shannon v2.5.3 was released on 2026-08-24, the same date as the last repository push. GitHub listed 30 open issues and PRs. Current activity includes a sub-session disposal bug, a proposed security policy, provider setup work, retry safety, and the reporting-gate mismatch. The project is active, and the small queue is navigable.

The AGPL-3.0 license fits local open-source use, while organizations needing private redistribution, managed service rights, or other terms can seek a commercial license. More important than licensing for the first trial is containment: use an intentionally vulnerable target, a capped provider account, and disposable state. Shannon earns a place beside other scanners only when its proven findings add evidence the team can reproduce.

Alternatives

ProjectWhat it isPick it when
OWASP ZAPA mature web application scanner and interception proxy with automation support.pick this instead when repeatable DAST checks and manual proxy work matter more than source-guided AI exploitation.
Nuclei gh↗A template-driven scanner for known patterns across web and infrastructure targets.pick this instead when speed, deterministic templates, and broad repeatable coverage are the priority.
SemgrepA static-analysis engine for finding code patterns without attacking a live application.pick this instead when source scanning must be safe for production code and live exploitation is out of scope.

What people are saying

  1. [github-trending] KeygraphHQ/shannon

Sources

  1. Shannon README
  2. Shannon safety guide
  3. Shannon releases
  4. Shannon issues and pull requests

More dev tools reviews

agent-manager · navi · exodium · Submarine · Madeira · mitmproxy · the whole board →