KeygraphHQ/shannonPublic

Shannon is an AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities before they reach production.

AI summary: A high-performance, open-source knowledge graph engine optimized for fast querying and AI integration.

Stars
48.6K
+52 today
Forks
5.6K
Watchers
241
Open issues
11
Open PRs
13
Contributors
~8
Commits
298
Branches
8

TypeScriptAGPL-3.0Created Sep 27, 2025Last push 2d agoLatest release v3.3.0+187 stars this week+863 this month

Quick answers

What is shannon?
A high-performance, open-source knowledge graph engine optimized for fast querying and AI integration.
What does shannon do?
Shannon is a highly optimized knowledge graph engine built from the ground up to handle massive, complex graph datasets with extremely low latency. It leverages advanced indexing structures and a custom query execution engine to dramatically accelerate multi-hop queries and graph traversals. The system is specifically designed to integrate seamlessly with modern AI workflows, providing native support for vector embeddings and graph-augmented Retrieval-Augmented Generation (RAG). By combining traditional graph database capabilities with vector search, Shannon enables applications to reason over structured relational data and unstructured semantic data simultaneously.
Who is shannon for?
This engine is targeted at data engineers, backend developers, and AI practitioners who require a fast, scalable graph database.
How do I get started with shannon?
docker run -p 8080:8080 keygraphhq/shannon:latest
How popular is shannon on GitHub?
KeygraphHQ/shannon has 48,554 stars and 5,562 forks on GitHub, and gained 187 stars in the last 7 days.
What license does shannon use?
KeygraphHQ/shannon is released under the AGPL-3.0 license.

Star history

since Jul 28, 2026
020K40KJul 2026Aug 2026Sep 2026Oct 2026
48.6K stars as of Oct 3, 2026. Measured daily since Jul 28, 2026; GitHub no longer exposes earlier star timestamps.

Contribution activity

commits per day, last 52 weeks
OctNovDecJanFebMarAprMayJunJulAugSepMonWedFri2025-10-05: 0 commits2025-10-06: 4 commits2025-10-07: 7 commits2025-10-08: 1 commit2025-10-09: 1 commit2025-10-10: 0 commits2025-10-11: 0 commits2025-10-12: 0 commits2025-10-13: 0 commits2025-10-14: 0 commits2025-10-15: 0 commits2025-10-16: 0 commits2025-10-17: 2 commits2025-10-18: 0 commits2025-10-19: 0 commits2025-10-20: 0 commits2025-10-21: 1 commit2025-10-22: 8 commits2025-10-23: 8 commits2025-10-24: 0 commits2025-10-25: 0 commits2025-10-26: 0 commits2025-10-27: 3 commits2025-10-28: 1 commit2025-10-29: 0 commits2025-10-30: 2 commits2025-10-31: 1 commit2025-11-01: 0 commits2025-11-02: 0 commits2025-11-03: 11 commits2025-11-04: 2 commits2025-11-05: 0 commits2025-11-06: 0 commits2025-11-07: 0 commits2025-11-08: 0 commits2025-11-09: 0 commits2025-11-10: 0 commits2025-11-11: 0 commits2025-11-12: 0 commits2025-11-13: 7 commits2025-11-14: 0 commits2025-11-15: 0 commits2025-11-16: 0 commits2025-11-17: 0 commits2025-11-18: 0 commits2025-11-19: 1 commit2025-11-20: 3 commits2025-11-21: 0 commits2025-11-22: 1 commit2025-11-23: 0 commits2025-11-24: 1 commit2025-11-25: 0 commits2025-11-26: 1 commit2025-11-27: 0 commits2025-11-28: 0 commits2025-11-29: 0 commits2025-11-30: 0 commits2025-12-01: 1 commit2025-12-02: 1 commit2025-12-03: 0 commits2025-12-04: 0 commits2025-12-05: 0 commits2025-12-06: 0 commits2025-12-07: 0 commits2025-12-08: 0 commits2025-12-09: 1 commit2025-12-10: 1 commit2025-12-11: 0 commits2025-12-12: 0 commits2025-12-13: 0 commits2025-12-14: 0 commits2025-12-15: 3 commits2025-12-16: 3 commits2025-12-17: 0 commits2025-12-18: 0 commits2025-12-19: 0 commits2025-12-20: 1 commit2025-12-21: 0 commits2025-12-22: 0 commits2025-12-23: 0 commits2025-12-24: 0 commits2025-12-25: 0 commits2025-12-26: 0 commits2025-12-27: 0 commits2025-12-28: 0 commits2025-12-29: 0 commits2025-12-30: 0 commits2025-12-31: 0 commits2026-01-01: 0 commits2026-01-02: 0 commits2026-01-03: 0 commits2026-01-04: 0 commits2026-01-05: 1 commit2026-01-06: 0 commits2026-01-07: 0 commits2026-01-08: 2 commits2026-01-09: 0 commits2026-01-10: 0 commits2026-01-11: 0 commits2026-01-12: 1 commit2026-01-13: 0 commits2026-01-14: 0 commits2026-01-15: 6 commits2026-01-16: 2 commits2026-01-17: 0 commits2026-01-18: 0 commits2026-01-19: 0 commits2026-01-20: 4 commits2026-01-21: 0 commits2026-01-22: 1 commit2026-01-23: 0 commits2026-01-24: 0 commits2026-01-25: 0 commits2026-01-26: 0 commits2026-01-27: 1 commit2026-01-28: 0 commits2026-01-29: 0 commits2026-01-30: 0 commits2026-01-31: 0 commits2026-02-01: 0 commits2026-02-02: 0 commits2026-02-03: 0 commits2026-02-04: 0 commits2026-02-05: 0 commits2026-02-06: 0 commits2026-02-07: 2 commits2026-02-08: 0 commits2026-02-09: 1 commit2026-02-10: 2 commits2026-02-11: 8 commits2026-02-12: 1 commit2026-02-13: 4 commits2026-02-14: 3 commits2026-02-15: 0 commits2026-02-16: 14 commits2026-02-17: 2 commits2026-02-18: 0 commits2026-02-19: 2 commits2026-02-20: 2 commits2026-02-21: 1 commit2026-02-22: 0 commits2026-02-23: 0 commits2026-02-24: 3 commits2026-02-25: 0 commits2026-02-26: 0 commits2026-02-27: 0 commits2026-02-28: 0 commits2026-03-01: 0 commits2026-03-02: 0 commits2026-03-03: 3 commits2026-03-04: 12 commits2026-03-05: 3 commits2026-03-06: 6 commits2026-03-07: 1 commit2026-03-08: 0 commits2026-03-09: 1 commit2026-03-10: 0 commits2026-03-11: 0 commits2026-03-12: 0 commits2026-03-13: 0 commits2026-03-14: 0 commits2026-03-15: 0 commits2026-03-16: 0 commits2026-03-17: 0 commits2026-03-18: 2 commits2026-03-19: 2 commits2026-03-20: 0 commits2026-03-21: 0 commits2026-03-22: 0 commits2026-03-23: 0 commits2026-03-24: 0 commits2026-03-25: 0 commits2026-03-26: 0 commits2026-03-27: 1 commit2026-03-28: 0 commits2026-03-29: 0 commits2026-03-30: 0 commits2026-03-31: 0 commits2026-04-01: 1 commit2026-04-02: 2 commits2026-04-03: 1 commit2026-04-04: 0 commits2026-04-05: 0 commits2026-04-06: 1 commit2026-04-07: 0 commits2026-04-08: 0 commits2026-04-09: 0 commits2026-04-10: 1 commit2026-04-11: 0 commits2026-04-12: 0 commits2026-04-13: 0 commits2026-04-14: 0 commits2026-04-15: 0 commits2026-04-16: 4 commits2026-04-17: 0 commits2026-04-18: 0 commits2026-04-19: 0 commits2026-04-20: 2 commits2026-04-21: 1 commit2026-04-22: 0 commits2026-04-23: 1 commit2026-04-24: 0 commits2026-04-25: 0 commits2026-04-26: 0 commits2026-04-27: 0 commits2026-04-28: 2 commits2026-04-29: 0 commits2026-04-30: 0 commits2026-05-01: 1 commit2026-05-02: 0 commits2026-05-03: 0 commits2026-05-04: 1 commit2026-05-05: 0 commits2026-05-06: 2 commits2026-05-07: 0 commits2026-05-08: 0 commits2026-05-09: 0 commits2026-05-10: 0 commits2026-05-11: 0 commits2026-05-12: 0 commits2026-05-13: 0 commits2026-05-14: 0 commits2026-05-15: 0 commits2026-05-16: 0 commits2026-05-17: 0 commits2026-05-18: 0 commits2026-05-19: 0 commits2026-05-20: 1 commit2026-05-21: 2 commits2026-05-22: 0 commits2026-05-23: 0 commits2026-05-24: 0 commits2026-05-25: 0 commits2026-05-26: 0 commits2026-05-27: 1 commit2026-05-28: 2 commits2026-05-29: 0 commits2026-05-30: 0 commits2026-05-31: 0 commits2026-06-01: 0 commits2026-06-02: 0 commits2026-06-03: 1 commit2026-06-04: 0 commits2026-06-05: 1 commit2026-06-06: 0 commits2026-06-07: 0 commits2026-06-08: 0 commits2026-06-09: 0 commits2026-06-10: 0 commits2026-06-11: 0 commits2026-06-12: 2 commits2026-06-13: 0 commits2026-06-14: 0 commits2026-06-15: 0 commits2026-06-16: 0 commits2026-06-17: 1 commit2026-06-18: 0 commits2026-06-19: 4 commits2026-06-20: 0 commits2026-06-21: 0 commits2026-06-22: 0 commits2026-06-23: 3 commits2026-06-24: 0 commits2026-06-25: 0 commits2026-06-26: 0 commits2026-06-27: 0 commits2026-06-28: 0 commits2026-06-29: 0 commits2026-06-30: 0 commits2026-07-01: 0 commits2026-07-02: 0 commits2026-07-03: 0 commits2026-07-04: 1 commit2026-07-05: 0 commits2026-07-06: 0 commits2026-07-07: 0 commits2026-07-08: 0 commits2026-07-09: 0 commits2026-07-10: 0 commits2026-07-11: 0 commits2026-07-12: 0 commits2026-07-13: 0 commits2026-07-14: 0 commits2026-07-15: 0 commits2026-07-16: 2 commits2026-07-17: 0 commits2026-07-18: 0 commits2026-07-19: 0 commits2026-07-20: 1 commit2026-07-21: 0 commits2026-07-22: 0 commits2026-07-23: 0 commits2026-07-24: 0 commits2026-07-25: 1 commit2026-07-26: 0 commits2026-07-27: 0 commits2026-07-28: 1 commit2026-07-29: 0 commits2026-07-30: 4 commits2026-07-31: 0 commits2026-08-01: 0 commits2026-08-02: 0 commits2026-08-03: 0 commits2026-08-04: 1 commit2026-08-05: 0 commits2026-08-06: 0 commits2026-08-07: 2 commits2026-08-08: 0 commits2026-08-09: 0 commits2026-08-10: 1 commit2026-08-11: 0 commits2026-08-12: 1 commit2026-08-13: 0 commits2026-08-14: 0 commits2026-08-15: 0 commits2026-08-16: 0 commits2026-08-17: 0 commits2026-08-18: 1 commit2026-08-19: 3 commits2026-08-20: 0 commits2026-08-21: 0 commits2026-08-22: 0 commits2026-08-23: 0 commits2026-08-24: 1 commit2026-08-25: 1 commit2026-08-26: 1 commit2026-08-27: 1 commit2026-08-28: 2 commits2026-08-29: 0 commits2026-08-30: 0 commits2026-08-31: 0 commits2026-09-01: 0 commits2026-09-02: 3 commits2026-09-03: 1 commit2026-09-04: 0 commits2026-09-05: 0 commits2026-09-06: 0 commits2026-09-07: 0 commits2026-09-08: 1 commit2026-09-09: 2 commits2026-09-10: 0 commits2026-09-11: 0 commits2026-09-12: 0 commits2026-09-13: 0 commits2026-09-14: 0 commits2026-09-15: 0 commits2026-09-16: 0 commits2026-09-17: 0 commits2026-09-18: 0 commits2026-09-19: 0 commits2026-09-20: 0 commits2026-09-21: 2 commits2026-09-22: 0 commits2026-09-23: 0 commits2026-09-24: 0 commits2026-09-25: 0 commits2026-09-26: 0 commits2026-09-27: 0 commits2026-09-28: 0 commits2026-09-29: 0 commits2026-09-30: 2 commits2026-10-01: 0 commits2026-10-02: 0 commits2026-10-03: 0 commits
245 commits in the last yearLessMore

Signals and awards

derived from tracked data
  • Widely adopted

    48,554 stars

  • Continuous integration

    Automated checks passing

  • Repeat trending

    13 trending appearances

What shannon does

Shannon is a highly optimized knowledge graph engine built from the ground up to handle massive, complex graph datasets with extremely low latency. It leverages advanced indexing structures and a custom query execution engine to dramatically accelerate multi-hop queries and graph traversals. The system is specifically designed to integrate seamlessly with modern AI workflows, providing native support for vector embeddings and graph-augmented Retrieval-Augmented Generation (RAG). By combining traditional graph database capabilities with vector search, Shannon enables applications to reason over structured relational data and unstructured semantic data simultaneously.

This engine is targeted at data engineers, backend developers, and AI practitioners who require a fast, scalable graph database.

  • Hybrid Query Engine: Executes complex graph traversals and high-dimensional vector similarity searches within the same unified query.
  • Ultra-Low Latency Traversals: Utilizes memory-optimized data structures to ensure multi-hop relationship queries return in milliseconds.
  • Native AI Integration: Provides built-in connectors for popular LLM frameworks to facilitate Graph-RAG architectures natively.
  • Scalable Storage Architecture: Designed to scale horizontally, handling billions of nodes and edges across distributed clusters efficiently.
  • Flexible Schema Management: Allows for dynamic schema evolution without requiring significant downtime or complex migrations.

Where teams use it

Graph-Augmented RAG (GraphRAG)

For AI applications requiring deep context and factual grounding, combining vector search with structured entity relationship traversals.

Complex Fraud Detection

For financial institutions needing to rapidly trace complex, multi-layered transaction networks in real-time to identify anomalous patterns.

Enterprise Knowledge Discovery

For organizations building internal search tools that must connect disparate data silos into a unified, queryable relationship graph.

Recommendation Systems

For e-commerce platforms generating real-time product recommendations based on complex user interactions and item relationships.

Getting started: docker run -p 8080:8080 keygraphhq/shannon:latest

README

main branch

Note

Shannon 3.0 is live: deeper security code analysis, more thoroughly vetted findings, a rebuilt CLI, native CI/CD, professional PDF reports, and SARIF.

Shannon, AI Pentester for Web Apps and APIs, by Keygraph

KeygraphHQ%2Fshannon | Trendshift

Shannon is an autonomous, AI pentester for web applications and APIs.

It analyzes your source code, identifies attack paths, and executes real exploits to prove vulnerabilities before they reach production. No exploit, no report.

This repository is Shannon Open Source: the full agent, run locally from your command line.

Launch Shannon

npx @keygraph/shannon@latest

The interactive launcher will guide you through setup and your first pentest.


Join Discord      Visit Keygraph.io


Tip

AI agents and LLMs: start with llms.txt for a concise map of this repository, or use llms-full.txt for the README and docs combined into one file.

Table of Contents

What is Shannon?

Shannon is an autonomous AI pentester developed by Keygraph. It performs security testing of web applications and their underlying APIs by combining source-code analysis with live exploitation.

Shannon analyzes your web application's source code to identify potential attack vectors, then uses browser automation and command-line tools to execute real exploits against the running application and its APIs. Only vulnerabilities with a working proof-of-concept are included in the final report.

Shannon is the agent. This repository is Shannon Open Source, the standalone pentester you run yourself. The same Shannon also powers the Keygraph platform, Keygraph's commercial pentesting product. See Editions for how the two compare.

Why Shannon Exists

Thanks to tools like Claude Code and Cursor, your team ships code non-stop. But your penetration test? That happens once a year. This creates a massive security gap. For the other 364 days, you could be unknowingly shipping vulnerabilities to production.

Shannon closes that gap by providing on-demand, automated penetration testing that can run against every build or release.

Why "Shannon"?

It's named after Claude Shannon, the father of information theory. At its core, pentesting is an information problem: every probe reduces uncertainty about a system's state. The best tools maximize the signal gained from every request, turning those bits of knowledge into an exploit path.

Also, we wanted you to be able to say, "Hey Claude, run Shannon" to find all the security flaws in your vibe-coded app.

Not a replacement for human pentesters

Shannon is built to work alongside expert pentesters and red teamers, not replace them. Great pentesters understand the business, chain attacks in ways nobody anticipated, and bring years of judgment that current models can't match.

Shannon solves a different problem: there is far more software to test than security teams have time to cover. Critical systems get periodic expert assessments, while the long tail of internal apps, APIs, and fast-moving services rarely gets tested at all.

Shannon shifts pentesting left into the software development lifecycle (SDLC). Use it to run exploitation-backed tests against staging environments and releases at the cadence they actually ship, and save expert human time for the risks that need someone who knows the organization.

Shannon in Action

Shannon running an autonomous pentest

These reports are from Shannon Open Source scans of Photoview 2.4.0, one of the applications in Doyensec's comparison of Aikido and XBOW. We ran Shannon against the same application version and evaluated its results separately. Read the Doyensec study and our Shannon follow-up comparison for the methodology, limitations, costs, and results.

Model Report SARIF
DeepSeek v4 Flash View report SARIF
Grok 4.6 View report SARIF
Claude Opus 5 View report SARIF

Quick Start

Prerequisites

  • Docker: required for the worker container.
  • Node.js 18+: required for the recommended npx workflow.
  • AI provider credentials: Shannon runs on Anthropic, OpenAI, xAI, AWS Bedrock, and any other provider in the harness catalogue — each of which you can point at a proxy or LLM gateway through a custom base URL, and a model the catalogue does not carry can be described with a custom model configuration. You bring your own key, and Keygraph never proxies your model traffic. Shannon is provider-agnostic. See AI providers for suggested model IDs.
  • Cyber safeguards cleared with your provider: Anthropic and OpenAI apply real-time safeguards to cyber-security workloads, which can interrupt a scan mid-run. Complete their guidance for legitimate security testers before your first run - see AI providers.

Run Shannon

Warning

Shannon actively executes exploits. Run it only against applications and environments you own or have explicit written authorization to test. Do not run Shannon against production systems.

# Configure credentials with the interactive wizard.
npx @keygraph/shannon@latest setup

# Run a pentest against a source-available target.
npx @keygraph/shannon@latest start \
  -u https://your-app.com \
  -r /path/to/your/repo

Shannon pulls the worker image from Docker Hub, starts the required local infrastructure, mounts the target repository read-only inside an ephemeral worker container, and writes results to a local workspace.

For source builds, authenticated scans, provider-specific setup, and platform notes, see Documentation.

Tip

Prefer to use a subscription instead of API credits?

Key Capabilities

  • No exploit, no report: Reports only vulnerabilities confirmed with a reproducible proof of concept, reducing speculative scanner noise.
  • Advanced code analysis: Maps architecture, trust boundaries, interfaces, data flows, and critical assets before sending credible attack paths to live pentesting agents.
  • Autonomous execution: Runs reconnaissance, analysis, exploitation, and reporting from a single command.
  • Live terminal experience: Simplifies scan setup and shows agent progress and results without exposing orchestration logs.
  • Authenticated testing: Supports credentials, login flows, TOTP, email authentication, focus areas, and rules of engagement through configuration.
  • OWASP-focused coverage: Tests for exploitable injection, XSS, SSRF, broken authentication, and broken authorization.
  • Resumable workspaces: Resumes interrupted scans without repeating completed work.
  • Native CI/CD integrations: Runs through the official GitHub Action or GitLab CI/CD component, preserves artifacts, publishes findings, and gates releases on proven vulnerabilities.
  • Multi-format reports: Produces evidence-rich PDF and Markdown reports plus JSON and SARIF 2.1.0. SARIF is enabled by default for exploit-mode scans.
  • Provider agnostic and BYOK: Supports Anthropic, OpenAI, xAI, AWS Bedrock, compatible APIs and LLM gateways, and local models served through Ollama, vLLM, or LM Studio.
  • Private by design: Runs in your infrastructure, stores results locally, and sends model requests directly to your chosen endpoint. A local endpoint keeps data inside your environment.

CI/CD Integrations

Shannon can run continuously against deployed staging and development environments through official integrations for GitHub Actions and GitLab CI/CD.

Both integrations:

  • analyze the checked-out source repository while attacking a running target;
  • preserve PDF, Markdown, and SARIF reports as pipeline artifacts;
  • preserve scan and agent logs for debugging, including incomplete runs;
  • support pull-request, release, and scheduled pentests;
  • distinguish an incomplete assessment from a completed scan with no findings; and
  • optionally fail the pipeline when Shannon exploits a vulnerability at or above a configured severity threshold.

A code-analysis hypothesis does not fail the pipeline. Severity gates count only findings with status: exploited.

GitHub Actions

name: Shannon Pentest

on:
  workflow_dispatch:

permissions:
  security-events: write

jobs:
  pentest:
    runs-on: ubuntu-latest

    steps:
      - uses: actions/checkout@v4

      - name: Run Shannon
        uses: KeygraphHQ/shannon-action@v1
        with:
          url: https://staging.example.com
          api-key: ${{ secrets.SHANNON_AI_API_KEY }}
          fail-on-severity: high
          upload-sarif: true

The Action defaults repo to the checked-out GitHub workspace. It uploads one artifact containing the security assessment reports and SARIF, plus a separate run artifact containing scan and agent logs. Enabling upload-sarif publishes supported findings to GitHub code scanning.

Requirements:

  • a private repository;
  • a runner with Docker and Docker Compose v2;
  • access to the running staging or development target; and
  • a model-provider credential stored as a GitHub Actions secret.

See the Shannon GitHub Action documentation and GitHub Marketplace listing.

Editions

Shannon Open Source is a complete autonomous pentester, especially well suited to individual developers and small teams running focused security tests locally or in CI/CD.

Keygraph Enterprise Platform is for organizations that need a shared platform for continuous agentic pentesting/AppSec across many teams, repositories, and environments. It centralizes deeper analysis, vulnerability management, remediation, verification, governance, and reporting so teams do not have to assemble and maintain those workflows themselves.

Learn about the Keygraph Enterprise Platform and compare editions →

Architecture

Shannon combines multi-stage security code analysis with live reconnaissance and exploitation:

flowchart TD
    S["Source code"] --> EXISTING["Recon + vulnerability analysis"]
    S --> SAST["Agentic security code analysis"]

    EXISTING -- "Pentest candidates" --> REC["Finding reconciliation<br/>(merge + deduplicate)"]
    SAST -- "SAST candidates" --> REC

    REC -- "Reconciled exploitation queue" --> EXP["Exploitation agents"]
    APP["Running application"] --> EXP

    EXP -- "Exploit demonstrated" --> REPORT["Reporting<br/>PDF · Markdown · SARIF"]
    EXP -- "No exploit demonstrated" --> DROP["Discard"]

    REPORT --> CICD["CI/CD gate"]
Loading

Stage by stage:

  1. Recon and vulnerability analysis explores the running application, ties runtime behavior back to the source, and runs specialized agents across Injection, XSS, SSRF, Authentication, and Authorization.
  2. Agentic security code analysis maps the application's architecture, trust boundaries, exposed interfaces, dependencies, data flows, and high-risk assets, then opens targeted investigations against them.
  3. Finding reconciliation merges both streams of candidates, deduplicates the overlap, and groups what remains into an exploitation queue.
  4. Exploitation agents attempt real proof-of-concept attacks against the running application.
  5. Validation throws out every candidate Shannon can't demonstrate.
  6. Reporting produces PDF and Markdown reports with the evidence attached, plus structured JSON and SARIF for downstream systems.

Only live-validated vulnerabilities become Shannon pentest findings or count toward CI/CD severity gates.

Each scan runs in an ephemeral Docker container with an isolated workspace and per-invocation orchestration.

Documentation

Use these guides for operational detail:

Guide Use it for
Source build and CLI commands Cloning, building, common commands, output paths, and local development.
Configuration Authenticated testing, login flows, rules of engagement, and report filters.
AI providers Selecting the model, the supported providers (Anthropic, OpenAI, xAI, AWS Bedrock, and any other Pi-supported provider), and custom LLM gateways.
Platforms and networking Windows/WSL2, Linux, macOS, Docker networking, local apps, and custom hostnames.
Workspaces and resuming Naming workspaces, resuming interrupted scans, and workspace storage.
Safety and limitations Authorized-use requirements, non-production guidance, mutative effects, cost, and model caveats.
Coverage and roadmap Current vulnerability coverage and planned work.
Keygraph Enterprise Platform Exhaustive agentic SAST, continuous pentesting, full-lifecycle finding management, remediation, targeted verification, enterprise governance, and on-premises deployment.

Safety, Scope, and Limitations

Shannon is not a passive scanner. Its exploitation agents can create users, submit forms, mutate application state, trigger outbound requests, and otherwise affect the target system. Use sandboxed, staging, or local development environments with disposable data.

You are responsible for using Shannon legally and ethically. Do not point Shannon at systems, repositories, or applications you do not own or do not have explicit authorization to test.

Important limitations:

  • Shannon Open Source is tuned for fast, code-informed pentesting in everyday development and CI/CD. Exhaustive agentic SAST, broader scanner coverage, centralized governance, and full-lifecycle vulnerability management are delivered through the Keygraph Enterprise Platform.
  • Findings still require human review. LLM-generated reports can contain weakly supported or incorrect details.
  • Anthropic, OpenAI, xAI, and AWS Bedrock are built-in providers, and any other provider in the harness catalogue works too — each reachable through a custom base URL that points it at a proxy or LLM gateway. Model capability varies, and a model that does not follow Shannon's instructions or tool-use constraints reliably will produce weaker results.
  • A full run can take roughly 1 to 1.5 hours and may incur LLM API costs depending on model pricing and application complexity.
  • Do not scan untrusted or adversarial codebases. AI-powered tools that read source code can be exposed to prompt injection.

Read the full Safety and limitations guide before running Shannon in a new environment.

License

Shannon Open Source is licensed under the GNU Affero General Public License v3.0.

Commercial and enterprise licensing is available for organizations that need different license terms, commercial support, private redistribution, managed-service use, or broader deployment options, including the Keygraph platform.

For commercial licensing, contact [email protected].

Acknowledgements

Thanks to Pi, Playwright CLI, and Mantis.

See THIRD_PARTY_NOTICES.md for licensing and attribution details.

About Keygraph

Keygraph is the company behind Shannon. It also builds the Keygraph platform, the commercial agentic pentesting product that closes the full AppSec lifecycle and runs an enhanced build of Shannon as its pentesting engine.

Community and Support

Community office hours are available for hands-on help with bugs, deployments, and configuration questions.

  • US/EU: Thursday, 10:00 AM PT
  • Asia: Thursday, 2:00 PM IST
  • Book a slot

Join Discord to ask questions, share feedback, and connect with other Shannon users.

At this time, Keygraph is not accepting external code contributions. Issues are welcome for bug reports and feature requests:

Stay connected:

Common Questions

Can I self-host Shannon?

Yes. Shannon Open Source runs inside your infrastructure in an ephemeral worker container. It mounts the repository read-only and writes results to a local workspace.

Keygraph never receives your source code and never proxies your model traffic. Your model requests go straight to the provider or endpoint you configure, and they carry source and application context with them. Point Shannon at a locally hosted endpoint and that traffic stays inside your environment too.

Does Shannon support bring your own key (BYOK)?

Yes, always. You provide the LLM credentials Shannon uses to run a pentest, in every deployment, open source and commercial. Keygraph never proxies your model traffic.

Does Shannon output SARIF?

Yes. Shannon emits SARIF 2.1.0, the OASIS standard format for static analysis results, alongside structured JSON. Any SARIF consumer reads it: code scanning services, vulnerability management platforms, security dashboards, and CI/CD pipelines. It is written by default on exploit-mode scans; set report.sarif to "false" in your configuration file to opt out.

Which AI providers does Shannon support?

Anthropic, OpenAI, xAI, and AWS Bedrock are built in and configured directly by provider ID. Beyond those, Shannon runs on any provider in the Pi harness catalogue, named the same <provider>:<model-id> way. Any provider can be pointed at a proxy or LLM gateway through a custom base URL, which overrides only the endpoint and keeps that provider's API dialect. A model the catalogue does not carry, such as one a router or gateway serves under its own ID, or a self-hosted model, is described in a custom model configuration file and passed with --models-config. Shannon uses a single unified model setting throughout a pentest.

Can I run Shannon on a local or self-hosted model?

Shannon works with local models served through Ollama, vLLM, or LM Studio, which expose an OpenAI-compatible endpoint, as well as routers such as OpenRouter and LLM gateways such as LiteLLM. A model the harness catalogue does not carry, which most self-hosted models are, is described in a custom model configuration file passed with --models-config; routers and gateways can also be reached with a custom base URL. Capability varies, and a model that does not follow Shannon's instructions or tool-use constraints reliably will produce weaker pentests than a frontier model, so take this path only if you know how your chosen model behaves. See Local and self-hosted models.

Does Shannon actually exploit vulnerabilities, or just scan?

Shannon executes real exploits. It reports a finding only when it has produced a working proof-of-concept, and discards hypotheses it cannot prove. It is a pentester, not a passive scanner.

Built by Keygraph

View on GitHub

Recent activity

commits and pull requests

Releases and announcements

27 total
  1. v3.3.0v3.3.0Sep 21, 2026

    # [3.3.0](https://github.com/KeygraphHQ/shannon/compare/v3.2.0...v3.3.0) (2026-09-21) ### Features * refresh the model catalogue over the network at scan start ([#466](https://github.com/KeygraphHQ/shannon/issues/466)) ([22b093a](https://github.com/KeygraphHQ/shannon/commit/22b093aac5f9c4e01c9ddd8e74f5ebae8aa80397))

  2. v3.2.0v3.2.0Sep 8, 2026

    # [3.2.0](https://github.com/KeygraphHQ/shannon/compare/v3.1.0...v3.2.0) (2026-09-08) ### Features * support custom pi model configs, with registry-resolvable model IDs and distinct model error codes ([#450](https://github.com/KeygraphHQ/shannon/issues/450)) ([d41d52f](https://github.com/KeygraphHQ/shannon/commit/d41d52f17d822c3e846787cac289af5f6dde2bd2)) * surface startup and preflight failures ([#454](https://github.com/KeygraphHQ/shannon/issues/454)) ([2786f9a](https://github.com/KeygraphHQ/shannon/commit/2786f9aa2d12f7d4799e33fa0187ba3c911c6956))

  3. v3.1.0v3.1.0Sep 3, 2026

    # [3.1.0](https://github.com/KeygraphHQ/shannon/compare/v3.0.0...v3.1.0) (2026-09-03) ### Features * per-provider custom base URL, OpenAI Responses only ([#445](https://github.com/KeygraphHQ/shannon/issues/445)) ([4b8131f](https://github.com/KeygraphHQ/shannon/commit/4b8131fdd5262a91474bb39cef376c084088bca3))

  4. v3.0.0v3.0.0Sep 2, 2026

    # [3.0.0](https://github.com/KeygraphHQ/shannon/compare/v2.7.0...v3.0.0) (2026-09-02) ### Features * Shannon 3.0 Agentic SAST ([#433](https://github.com/KeygraphHQ/shannon/issues/433)) ([9767ebe](https://github.com/KeygraphHQ/shannon/commit/9767ebe633fe4c1cc73a7a74e8a7798c128b7e57))

  5. v2.7.0v2.7.0Aug 28, 2026

    # [2.7.0](https://github.com/KeygraphHQ/shannon/compare/v2.6.0...v2.7.0) (2026-08-28) ### Features * bump pi harness to 0.84.2 to enable xAI subscription auth ([#435](https://github.com/KeygraphHQ/shannon/issues/435)) ([6108de3](https://github.com/KeygraphHQ/shannon/commit/6108de3cfc1af975417097e591db691c39232cfa)) * support pentests with xAI (Grok) subscription auth ([#434](https://github.com/KeygraphHQ/shannon/issues/434)) ([7e0464b](https://github.com/KeygraphHQ/shannon/commit/7e0464bf79fb0e3a68eea578afdbd6213d20b4fb))

Code frequency

additions and deletions
+1.2M-1.2MWeek of 2025-10-05: +116 linesWeek of 2025-10-05: -178 linesWeek of 2025-10-12: +166 linesWeek of 2025-10-12: -4 linesWeek of 2025-10-19: +4,631 linesWeek of 2025-10-19: -3,315 linesWeek of 2025-10-26: +147 linesWeek of 2025-10-26: -151 linesWeek of 2025-11-02: +1,187,243 linesWeek of 2025-11-02: -89 linesWeek of 2025-11-09: +3,123 linesWeek of 2025-11-09: -94 linesWeek of 2025-11-16: +20 linesWeek of 2025-11-16: -22 linesWeek of 2025-11-23: +914 linesWeek of 2025-11-23: -2,397 linesWeek of 2025-11-30: +7 linesWeek of 2025-11-30: -3 linesWeek of 2025-12-07: +36 linesWeek of 2025-12-07: -8 linesWeek of 2025-12-14: +49 linesWeek of 2025-12-14: -12 linesWeek of 2025-12-21: +0 linesWeek of 2025-12-21: -0 linesWeek of 2025-12-28: +0 linesWeek of 2025-12-28: -0 linesWeek of 2026-01-04: +8,410 linesWeek of 2026-01-04: -7,177 linesWeek of 2026-01-11: +7,508 linesWeek of 2026-01-11: -5,129 linesWeek of 2026-01-18: +64 linesWeek of 2026-01-18: -113 linesWeek of 2026-01-25: +0 linesWeek of 2026-01-25: -1 linesWeek of 2026-02-01: +3 linesWeek of 2026-02-01: -1 linesWeek of 2026-02-08: +2,188 linesWeek of 2026-02-08: -707 linesWeek of 2026-02-15: +5,315 linesWeek of 2026-02-15: -4,961 linesWeek of 2026-02-22: +150 linesWeek of 2026-02-22: -14 linesWeek of 2026-03-01: +780 linesWeek of 2026-03-01: -348 linesWeek of 2026-03-08: +16,055 linesWeek of 2026-03-08: -21,259 linesWeek of 2026-03-15: +343 linesWeek of 2026-03-15: -11 linesWeek of 2026-03-22: +20,383 linesWeek of 2026-03-22: -1,201,689 linesWeek of 2026-03-29: +617 linesWeek of 2026-03-29: -498 linesWeek of 2026-04-05: +623 linesWeek of 2026-04-05: -113 linesWeek of 2026-04-12: +4 linesWeek of 2026-04-12: -4 linesWeek of 2026-04-19: +329 linesWeek of 2026-04-19: -440 linesWeek of 2026-04-26: +2,092 linesWeek of 2026-04-26: -384 linesWeek of 2026-05-03: +155 linesWeek of 2026-05-03: -126 linesWeek of 2026-05-10: +0 linesWeek of 2026-05-10: -0 linesWeek of 2026-05-17: +771 linesWeek of 2026-05-17: -150 linesWeek of 2026-05-24: +247 linesWeek of 2026-05-24: -12 linesWeek of 2026-05-31: +6,046 linesWeek of 2026-05-31: -2,396 linesWeek of 2026-06-07: +249 linesWeek of 2026-06-07: -122 linesWeek of 2026-06-14: +361 linesWeek of 2026-06-14: -365 linesWeek of 2026-06-21: +94 linesWeek of 2026-06-21: -147 linesWeek of 2026-06-28: +445 linesWeek of 2026-06-28: -172 linesWeek of 2026-07-05: +0 linesWeek of 2026-07-05: -0 linesWeek of 2026-07-12: +6,248 linesWeek of 2026-07-12: -4,996 linesWeek of 2026-07-19: +4 linesWeek of 2026-07-19: -1 linesWeek of 2026-07-26: +3,194 linesWeek of 2026-07-26: -1,436 linesWeek of 2026-08-02: +363 linesWeek of 2026-08-02: -228 linesWeek of 2026-08-09: +1,304 linesWeek of 2026-08-09: -37 linesWeek of 2026-08-16: +2,796 linesWeek of 2026-08-16: -869 linesWeek of 2026-08-23: +530 linesWeek of 2026-08-23: -211 linesWeek of 2026-08-30: +39,511 linesWeek of 2026-08-30: -3,550 linesWeek of 2026-09-06: +892 linesWeek of 2026-09-06: -403 linesWeek of 2026-09-13: +0 linesWeek of 2026-09-13: -0 linesWeek of 2026-09-20: +45 linesWeek of 2026-09-20: -30 linesWeek of 2026-09-27: +26 linesWeek of 2026-09-27: -5 linesOct 5, 2025Sep 27, 2026
+1.3M lines added, -1.3M removed over the last year.

Commits per week

last 52 weeks
250Week of 2025-10-05: 13 commitsWeek of 2025-10-12: 2 commitsWeek of 2025-10-19: 17 commitsWeek of 2025-10-26: 7 commitsWeek of 2025-11-02: 13 commitsWeek of 2025-11-09: 7 commitsWeek of 2025-11-16: 5 commitsWeek of 2025-11-23: 2 commitsWeek of 2025-11-30: 2 commitsWeek of 2025-12-07: 2 commitsWeek of 2025-12-14: 7 commitsWeek of 2025-12-21: 0 commitsWeek of 2025-12-28: 0 commitsWeek of 2026-01-04: 3 commitsWeek of 2026-01-11: 9 commitsWeek of 2026-01-18: 5 commitsWeek of 2026-01-25: 1 commitsWeek of 2026-02-01: 2 commitsWeek of 2026-02-08: 19 commitsWeek of 2026-02-15: 21 commitsWeek of 2026-02-22: 3 commitsWeek of 2026-03-01: 25 commitsWeek of 2026-03-08: 1 commitsWeek of 2026-03-15: 4 commitsWeek of 2026-03-22: 1 commitsWeek of 2026-03-29: 4 commitsWeek of 2026-04-05: 2 commitsWeek of 2026-04-12: 4 commitsWeek of 2026-04-19: 4 commitsWeek of 2026-04-26: 3 commitsWeek of 2026-05-03: 3 commitsWeek of 2026-05-10: 0 commitsWeek of 2026-05-17: 3 commitsWeek of 2026-05-24: 3 commitsWeek of 2026-05-31: 2 commitsWeek of 2026-06-07: 2 commitsWeek of 2026-06-14: 5 commitsWeek of 2026-06-21: 3 commitsWeek of 2026-06-28: 1 commitsWeek of 2026-07-05: 0 commitsWeek of 2026-07-12: 2 commitsWeek of 2026-07-19: 2 commitsWeek of 2026-07-26: 5 commitsWeek of 2026-08-02: 3 commitsWeek of 2026-08-09: 2 commitsWeek of 2026-08-16: 4 commitsWeek of 2026-08-23: 6 commitsWeek of 2026-08-30: 4 commitsWeek of 2026-09-06: 3 commitsWeek of 2026-09-13: 0 commitsWeek of 2026-09-20: 2 commitsWeek of 2026-09-27: 2 commitsOct 5, 2025Sep 27, 2026
245 commits in the last 52 weeks.

When work happens

weekday and hour
SunMonTueWedThuFriSat036912151821Sun 0:00 — 0 commitsSun 1:00 — 0 commitsSun 2:00 — 0 commitsSun 3:00 — 0 commitsSun 4:00 — 0 commitsSun 5:00 — 0 commitsSun 6:00 — 0 commitsSun 7:00 — 0 commitsSun 8:00 — 0 commitsSun 9:00 — 0 commitsSun 10:00 — 0 commitsSun 11:00 — 0 commitsSun 12:00 — 0 commitsSun 13:00 — 0 commitsSun 14:00 — 0 commitsSun 15:00 — 0 commitsSun 16:00 — 0 commitsSun 17:00 — 0 commitsSun 18:00 — 0 commitsSun 19:00 — 0 commitsSun 20:00 — 0 commitsSun 21:00 — 0 commitsSun 22:00 — 0 commitsSun 23:00 — 0 commitsMon 0:00 — 0 commitsMon 1:00 — 0 commitsMon 2:00 — 0 commitsMon 3:00 — 0 commitsMon 4:00 — 0 commitsMon 5:00 — 0 commitsMon 6:00 — 0 commitsMon 7:00 — 0 commitsMon 8:00 — 0 commitsMon 9:00 — 2 commitsMon 10:00 — 8 commitsMon 11:00 — 3 commitsMon 12:00 — 4 commitsMon 13:00 — 3 commitsMon 14:00 — 1 commitsMon 15:00 — 1 commitsMon 16:00 — 3 commitsMon 17:00 — 2 commitsMon 18:00 — 10 commitsMon 19:00 — 1 commitsMon 20:00 — 9 commitsMon 21:00 — 1 commitsMon 22:00 — 2 commitsMon 23:00 — 0 commitsTue 0:00 — 3 commitsTue 1:00 — 2 commitsTue 2:00 — 2 commitsTue 3:00 — 1 commitsTue 4:00 — 0 commitsTue 5:00 — 0 commitsTue 6:00 — 0 commitsTue 7:00 — 0 commitsTue 8:00 — 2 commitsTue 9:00 — 5 commitsTue 10:00 — 2 commitsTue 11:00 — 1 commitsTue 12:00 — 4 commitsTue 13:00 — 6 commitsTue 14:00 — 4 commitsTue 15:00 — 1 commitsTue 16:00 — 4 commitsTue 17:00 — 0 commitsTue 18:00 — 0 commitsTue 19:00 — 1 commitsTue 20:00 — 0 commitsTue 21:00 — 2 commitsTue 22:00 — 1 commitsTue 23:00 — 1 commitsWed 0:00 — 5 commitsWed 1:00 — 1 commitsWed 2:00 — 4 commitsWed 3:00 — 1 commitsWed 4:00 — 2 commitsWed 5:00 — 0 commitsWed 6:00 — 0 commitsWed 7:00 — 0 commitsWed 8:00 — 0 commitsWed 9:00 — 0 commitsWed 10:00 — 1 commitsWed 11:00 — 3 commitsWed 12:00 — 2 commitsWed 13:00 — 7 commitsWed 14:00 — 0 commitsWed 15:00 — 1 commitsWed 16:00 — 5 commitsWed 17:00 — 2 commitsWed 18:00 — 11 commitsWed 19:00 — 6 commitsWed 20:00 — 1 commitsWed 21:00 — 0 commitsWed 22:00 — 1 commitsWed 23:00 — 2 commitsThu 0:00 — 3 commitsThu 1:00 — 2 commitsThu 2:00 — 0 commitsThu 3:00 — 1 commitsThu 4:00 — 2 commitsThu 5:00 — 0 commitsThu 6:00 — 0 commitsThu 7:00 — 0 commitsThu 8:00 — 0 commitsThu 9:00 — 0 commitsThu 10:00 — 3 commitsThu 11:00 — 3 commitsThu 12:00 — 4 commitsThu 13:00 — 2 commitsThu 14:00 — 2 commitsThu 15:00 — 4 commitsThu 16:00 — 6 commitsThu 17:00 — 9 commitsThu 18:00 — 2 commitsThu 19:00 — 5 commitsThu 20:00 — 5 commitsThu 21:00 — 0 commitsThu 22:00 — 2 commitsThu 23:00 — 2 commitsFri 0:00 — 3 commitsFri 1:00 — 0 commitsFri 2:00 — 2 commitsFri 3:00 — 0 commitsFri 4:00 — 1 commitsFri 5:00 — 0 commitsFri 6:00 — 0 commitsFri 7:00 — 1 commitsFri 8:00 — 0 commitsFri 9:00 — 0 commitsFri 10:00 — 1 commitsFri 11:00 — 6 commitsFri 12:00 — 0 commitsFri 13:00 — 3 commitsFri 14:00 — 2 commitsFri 15:00 — 0 commitsFri 16:00 — 0 commitsFri 17:00 — 5 commitsFri 18:00 — 0 commitsFri 19:00 — 1 commitsFri 20:00 — 2 commitsFri 21:00 — 2 commitsFri 22:00 — 2 commitsFri 23:00 — 2 commitsSat 0:00 — 1 commitsSat 1:00 — 1 commitsSat 2:00 — 3 commitsSat 3:00 — 0 commitsSat 4:00 — 0 commitsSat 5:00 — 0 commitsSat 6:00 — 0 commitsSat 7:00 — 0 commitsSat 8:00 — 0 commitsSat 9:00 — 0 commitsSat 10:00 — 2 commitsSat 11:00 — 1 commitsSat 12:00 — 0 commitsSat 13:00 — 0 commitsSat 14:00 — 0 commitsSat 15:00 — 0 commitsSat 16:00 — 0 commitsSat 17:00 — 0 commitsSat 18:00 — 0 commitsSat 19:00 — 0 commitsSat 20:00 — 1 commitsSat 21:00 — 1 commitsSat 22:00 — 0 commitsSat 23:00 — 1 commits
Commit volume by weekday and hour (UTC). Larger dots mean more commits.
DateListRankStars gained
Mar 5, 2026daily#7+337
Mar 4, 2026daily#3+529
Mar 3, 2026daily#7+324
Feb 15, 2026daily#21+168
Feb 14, 2026daily#17+164
Feb 13, 2026daily#18+134
Feb 12, 2026daily#21+156
Feb 11, 2026daily#15+252
Feb 10, 2026daily#2+756
Feb 9, 2026daily#1+1,224
Feb 8, 2026daily#1+1,270
Feb 7, 2026daily#1+1,230
Feb 6, 2026daily#2+693
  • freeCodeCamp/freeCodeCamp

    freeCodeCamp.org's open-source codebase and curriculum. Learn math, programming, and computer science for free.

    456.7K stars · TypeScript

  • openclaw/openclaw

    The AI that really does things. Any OS. Any Platform. The lobster way. 🦞

    391.3K stars · TypeScript

  • trimstray/the-book-of-secret-knowledge

    A collection of inspiring lists, manuals, cheatsheets, blogs, hacks, one-liners, cli/web tools and more.

    247.8K stars

  • anomalyco/opencode

    The open source coding agent.

    211.7K stars · TypeScript

  • n8n-io/n8n

    Fair-code workflow automation platform with native AI capabilities. Combine visual building with custom code, self-host or cloud, 400+ integrations.

    206.7K stars · TypeScript

  • microsoft/vscode

    Visual Studio Code

    193.5K stars · TypeScript