KeygraphHQ/shannonPublic

Shannon is an AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities before they reach production.

AI summary: A high-performance, open-source knowledge graph engine optimized for fast querying and AI integration.

Stars
46.5K
+43 today
Forks
5.4K
Watchers
221
Open issues
16
Open PRs
16
Contributors
~8
Commits
274
Branches
8

TypeScriptAGPL-3.0Created Sep 27, 2025Last push todayLatest release v2.3.0+177 stars this week+259 this month

Star history

since Sep 28, 2025
020K40KSep 2025Jan 2026Apr 2026Aug 2026
46.5K stars as of Aug 7, 2026, tracked back to Sep 28, 2025. Historical curve reconstructed from public GitHub event archives, calibrated to the current total.

Contribution activity

commits per day, last 52 weeks
AugSepOctNovDecJanFebMarAprMayJunJulAugMonWedFri2025-08-10: 0 commits2025-08-11: 0 commits2025-08-12: 0 commits2025-08-13: 0 commits2025-08-14: 0 commits2025-08-15: 0 commits2025-08-16: 0 commits2025-08-17: 0 commits2025-08-18: 0 commits2025-08-19: 0 commits2025-08-20: 0 commits2025-08-21: 0 commits2025-08-22: 0 commits2025-08-23: 0 commits2025-08-24: 0 commits2025-08-25: 0 commits2025-08-26: 0 commits2025-08-27: 0 commits2025-08-28: 0 commits2025-08-29: 0 commits2025-08-30: 0 commits2025-08-31: 0 commits2025-09-01: 0 commits2025-09-02: 0 commits2025-09-03: 0 commits2025-09-04: 0 commits2025-09-05: 0 commits2025-09-06: 0 commits2025-09-07: 0 commits2025-09-08: 0 commits2025-09-09: 0 commits2025-09-10: 0 commits2025-09-11: 0 commits2025-09-12: 0 commits2025-09-13: 0 commits2025-09-14: 0 commits2025-09-15: 0 commits2025-09-16: 0 commits2025-09-17: 0 commits2025-09-18: 0 commits2025-09-19: 0 commits2025-09-20: 0 commits2025-09-21: 0 commits2025-09-22: 0 commits2025-09-23: 0 commits2025-09-24: 0 commits2025-09-25: 0 commits2025-09-26: 0 commits2025-09-27: 0 commits2025-09-28: 0 commits2025-09-29: 0 commits2025-09-30: 0 commits2025-10-01: 0 commits2025-10-02: 0 commits2025-10-03: 1 commit2025-10-04: 0 commits2025-10-05: 0 commits2025-10-06: 4 commits2025-10-07: 7 commits2025-10-08: 1 commit2025-10-09: 1 commit2025-10-10: 0 commits2025-10-11: 0 commits2025-10-12: 0 commits2025-10-13: 0 commits2025-10-14: 0 commits2025-10-15: 0 commits2025-10-16: 0 commits2025-10-17: 2 commits2025-10-18: 0 commits2025-10-19: 0 commits2025-10-20: 0 commits2025-10-21: 1 commit2025-10-22: 8 commits2025-10-23: 8 commits2025-10-24: 0 commits2025-10-25: 0 commits2025-10-26: 0 commits2025-10-27: 3 commits2025-10-28: 1 commit2025-10-29: 0 commits2025-10-30: 2 commits2025-10-31: 1 commit2025-11-01: 0 commits2025-11-02: 0 commits2025-11-03: 11 commits2025-11-04: 2 commits2025-11-05: 0 commits2025-11-06: 0 commits2025-11-07: 0 commits2025-11-08: 0 commits2025-11-09: 0 commits2025-11-10: 0 commits2025-11-11: 0 commits2025-11-12: 0 commits2025-11-13: 7 commits2025-11-14: 0 commits2025-11-15: 0 commits2025-11-16: 0 commits2025-11-17: 0 commits2025-11-18: 0 commits2025-11-19: 1 commit2025-11-20: 3 commits2025-11-21: 0 commits2025-11-22: 1 commit2025-11-23: 0 commits2025-11-24: 1 commit2025-11-25: 0 commits2025-11-26: 1 commit2025-11-27: 0 commits2025-11-28: 0 commits2025-11-29: 0 commits2025-11-30: 0 commits2025-12-01: 1 commit2025-12-02: 1 commit2025-12-03: 0 commits2025-12-04: 0 commits2025-12-05: 0 commits2025-12-06: 0 commits2025-12-07: 0 commits2025-12-08: 0 commits2025-12-09: 1 commit2025-12-10: 1 commit2025-12-11: 0 commits2025-12-12: 0 commits2025-12-13: 0 commits2025-12-14: 0 commits2025-12-15: 3 commits2025-12-16: 3 commits2025-12-17: 0 commits2025-12-18: 0 commits2025-12-19: 0 commits2025-12-20: 1 commit2025-12-21: 0 commits2025-12-22: 0 commits2025-12-23: 0 commits2025-12-24: 0 commits2025-12-25: 0 commits2025-12-26: 0 commits2025-12-27: 0 commits2025-12-28: 0 commits2025-12-29: 0 commits2025-12-30: 0 commits2025-12-31: 0 commits2026-01-01: 0 commits2026-01-02: 0 commits2026-01-03: 0 commits2026-01-04: 0 commits2026-01-05: 1 commit2026-01-06: 0 commits2026-01-07: 0 commits2026-01-08: 2 commits2026-01-09: 0 commits2026-01-10: 0 commits2026-01-11: 0 commits2026-01-12: 1 commit2026-01-13: 0 commits2026-01-14: 0 commits2026-01-15: 6 commits2026-01-16: 2 commits2026-01-17: 0 commits2026-01-18: 0 commits2026-01-19: 0 commits2026-01-20: 4 commits2026-01-21: 0 commits2026-01-22: 1 commit2026-01-23: 0 commits2026-01-24: 0 commits2026-01-25: 0 commits2026-01-26: 0 commits2026-01-27: 1 commit2026-01-28: 0 commits2026-01-29: 0 commits2026-01-30: 0 commits2026-01-31: 0 commits2026-02-01: 0 commits2026-02-02: 0 commits2026-02-03: 0 commits2026-02-04: 0 commits2026-02-05: 0 commits2026-02-06: 0 commits2026-02-07: 2 commits2026-02-08: 0 commits2026-02-09: 1 commit2026-02-10: 2 commits2026-02-11: 8 commits2026-02-12: 1 commit2026-02-13: 4 commits2026-02-14: 3 commits2026-02-15: 0 commits2026-02-16: 14 commits2026-02-17: 2 commits2026-02-18: 0 commits2026-02-19: 2 commits2026-02-20: 2 commits2026-02-21: 1 commit2026-02-22: 0 commits2026-02-23: 0 commits2026-02-24: 3 commits2026-02-25: 0 commits2026-02-26: 0 commits2026-02-27: 0 commits2026-02-28: 0 commits2026-03-01: 0 commits2026-03-02: 0 commits2026-03-03: 3 commits2026-03-04: 12 commits2026-03-05: 3 commits2026-03-06: 6 commits2026-03-07: 1 commit2026-03-08: 0 commits2026-03-09: 1 commit2026-03-10: 0 commits2026-03-11: 0 commits2026-03-12: 0 commits2026-03-13: 0 commits2026-03-14: 0 commits2026-03-15: 0 commits2026-03-16: 0 commits2026-03-17: 0 commits2026-03-18: 2 commits2026-03-19: 2 commits2026-03-20: 0 commits2026-03-21: 0 commits2026-03-22: 0 commits2026-03-23: 0 commits2026-03-24: 0 commits2026-03-25: 0 commits2026-03-26: 0 commits2026-03-27: 1 commit2026-03-28: 0 commits2026-03-29: 0 commits2026-03-30: 0 commits2026-03-31: 0 commits2026-04-01: 1 commit2026-04-02: 2 commits2026-04-03: 1 commit2026-04-04: 0 commits2026-04-05: 0 commits2026-04-06: 1 commit2026-04-07: 0 commits2026-04-08: 0 commits2026-04-09: 0 commits2026-04-10: 1 commit2026-04-11: 0 commits2026-04-12: 0 commits2026-04-13: 0 commits2026-04-14: 0 commits2026-04-15: 0 commits2026-04-16: 4 commits2026-04-17: 0 commits2026-04-18: 0 commits2026-04-19: 0 commits2026-04-20: 2 commits2026-04-21: 1 commit2026-04-22: 0 commits2026-04-23: 1 commit2026-04-24: 0 commits2026-04-25: 0 commits2026-04-26: 0 commits2026-04-27: 0 commits2026-04-28: 2 commits2026-04-29: 0 commits2026-04-30: 0 commits2026-05-01: 1 commit2026-05-02: 0 commits2026-05-03: 0 commits2026-05-04: 1 commit2026-05-05: 0 commits2026-05-06: 2 commits2026-05-07: 0 commits2026-05-08: 0 commits2026-05-09: 0 commits2026-05-10: 0 commits2026-05-11: 0 commits2026-05-12: 0 commits2026-05-13: 0 commits2026-05-14: 0 commits2026-05-15: 0 commits2026-05-16: 0 commits2026-05-17: 0 commits2026-05-18: 0 commits2026-05-19: 0 commits2026-05-20: 1 commit2026-05-21: 2 commits2026-05-22: 0 commits2026-05-23: 0 commits2026-05-24: 0 commits2026-05-25: 0 commits2026-05-26: 0 commits2026-05-27: 1 commit2026-05-28: 2 commits2026-05-29: 0 commits2026-05-30: 0 commits2026-05-31: 0 commits2026-06-01: 0 commits2026-06-02: 0 commits2026-06-03: 1 commit2026-06-04: 0 commits2026-06-05: 1 commit2026-06-06: 0 commits2026-06-07: 0 commits2026-06-08: 0 commits2026-06-09: 0 commits2026-06-10: 0 commits2026-06-11: 0 commits2026-06-12: 2 commits2026-06-13: 0 commits2026-06-14: 0 commits2026-06-15: 0 commits2026-06-16: 0 commits2026-06-17: 1 commit2026-06-18: 0 commits2026-06-19: 4 commits2026-06-20: 0 commits2026-06-21: 0 commits2026-06-22: 0 commits2026-06-23: 3 commits2026-06-24: 0 commits2026-06-25: 0 commits2026-06-26: 0 commits2026-06-27: 0 commits2026-06-28: 0 commits2026-06-29: 0 commits2026-06-30: 0 commits2026-07-01: 0 commits2026-07-02: 0 commits2026-07-03: 0 commits2026-07-04: 1 commit2026-07-05: 0 commits2026-07-06: 0 commits2026-07-07: 0 commits2026-07-08: 0 commits2026-07-09: 0 commits2026-07-10: 0 commits2026-07-11: 0 commits2026-07-12: 0 commits2026-07-13: 0 commits2026-07-14: 0 commits2026-07-15: 0 commits2026-07-16: 2 commits2026-07-17: 0 commits2026-07-18: 0 commits2026-07-19: 0 commits2026-07-20: 1 commit2026-07-21: 0 commits2026-07-22: 0 commits2026-07-23: 0 commits2026-07-24: 0 commits2026-07-25: 1 commit2026-07-26: 0 commits2026-07-27: 0 commits2026-07-28: 1 commit2026-07-29: 0 commits2026-07-30: 4 commits2026-07-31: 0 commits2026-08-01: 0 commits2026-08-02: 0 commits2026-08-03: 0 commits2026-08-04: 1 commit2026-08-05: 0 commits2026-08-06: 0 commits2026-08-07: 2 commits2026-08-08: 0 commits
223 commits in the last yearLessMore

Signals and awards

derived from tracked data
  • Widely adopted

    46,488 stars

  • Actively maintained

    Pushed within 48 hours

  • Continuous integration

    Automated checks passing

  • Repeat trending

    13 trending appearances

What shannon does

Shannon is a highly optimized knowledge graph engine built from the ground up to handle massive, complex graph datasets with extremely low latency. It leverages advanced indexing structures and a custom query execution engine to dramatically accelerate multi-hop queries and graph traversals. The system is specifically designed to integrate seamlessly with modern AI workflows, providing native support for vector embeddings and graph-augmented Retrieval-Augmented Generation (RAG). By combining traditional graph database capabilities with vector search, Shannon enables applications to reason over structured relational data and unstructured semantic data simultaneously.

This engine is targeted at data engineers, backend developers, and AI practitioners who require a fast, scalable graph database.

  • Hybrid Query Engine: Executes complex graph traversals and high-dimensional vector similarity searches within the same unified query.
  • Ultra-Low Latency Traversals: Utilizes memory-optimized data structures to ensure multi-hop relationship queries return in milliseconds.
  • Native AI Integration: Provides built-in connectors for popular LLM frameworks to facilitate Graph-RAG architectures natively.
  • Scalable Storage Architecture: Designed to scale horizontally, handling billions of nodes and edges across distributed clusters efficiently.
  • Flexible Schema Management: Allows for dynamic schema evolution without requiring significant downtime or complex migrations.

Where teams use it

Graph-Augmented RAG (GraphRAG)

For AI applications requiring deep context and factual grounding, combining vector search with structured entity relationship traversals.

Complex Fraud Detection

For financial institutions needing to rapidly trace complex, multi-layered transaction networks in real-time to identify anomalous patterns.

Enterprise Knowledge Discovery

For organizations building internal search tools that must connect disparate data silos into a unified, queryable relationship graph.

Recommendation Systems

For e-commerce platforms generating real-time product recommendations based on complex user interactions and item relationships.

Getting started: docker run -p 8080:8080 keygraphhq/shannon:latest

README

main branch
Shannon - AI Pentester by Keygraph

Shannon - AI Pentester by Keygraph

KeygraphHQ%2Fshannon | Trendshift

Shannon is an autonomous, AI pentester for web applications and APIs.
It analyzes your source code, identifies attack paths, and executes real exploits to prove vulnerabilities before they reach production.

This repository is Shannon Open Source: the full agent, run locally from your command line.


Join Discord Visit Keygraph.io


Tip

AI agents and LLMs: start with llms.txt for a concise map of this repository, or use llms-full.txt for the README and docs combined into one file.

Table of Contents

What is Shannon?

Shannon is an autonomous AI pentester developed by Keygraph. It performs security testing of web applications and their underlying APIs by combining source-code analysis with live exploitation.

Shannon analyzes your web application's source code to identify potential attack vectors, then uses browser automation and command-line tools to execute real exploits against the running application and its APIs. Only vulnerabilities with a working proof-of-concept are included in the final report.

Shannon is the agent. This repository is Shannon Open Source, the standalone pentester you run yourself. The same Shannon also powers the Keygraph platform, Keygraph's commercial pentesting product. See Editions for how the two compare.

Why Shannon Exists

Thanks to tools like Claude Code and Cursor, your team ships code non-stop. But your penetration test? That happens once a year. This creates a massive security gap. For the other 364 days, you could be unknowingly shipping vulnerabilities to production.

Shannon closes that gap by providing on-demand, automated penetration testing that can run against every build or release.

Shannon in Action

Shannon running an autonomous pentest

Sample penetration test reports from intentionally vulnerable applications, produced by Shannon Open Source:

Target Summary Report
OWASP Juice Shop 20+ vulnerabilities, including authentication bypass, SQL injection, IDOR, and SSRF. View report
c{api}tal API Approximately 15 critical and high-severity API findings, including command injection, auth bypass, and mass assignment. View report
OWASP crAPI 15+ critical and high-severity findings across JWT, injection, SSRF, and API authorization paths. View report

Quick Start

Prerequisites

  • Docker: required for the worker container.
  • Node.js 18+: required for the recommended npx workflow.
  • AI provider credentials: Anthropic, OpenAI, xAI, or AWS Bedrock - or any other provider. Claude models are recommended. For suggested model IDs per provider, plus gateways and custom base URLs, see AI providers.
  • Cyber safeguards cleared with your provider: Anthropic and OpenAI apply real-time safeguards to cyber-security workloads, which can interrupt a scan mid-run. Complete their guidance for legitimate security testers before your first run - see AI providers.

Run Shannon

Warning

Shannon actively executes exploits. Run it only against applications and environments you own or have explicit written authorization to test. Do not run Shannon against production systems.

# Configure credentials with the interactive wizard.
npx @keygraph/shannon setup

# Run a pentest against a source-available target.
npx @keygraph/shannon start -u https://your-app.com -r /path/to/your-repo

Shannon pulls the worker image from Docker Hub, starts the required local infrastructure, mounts the target repository read-only inside an ephemeral worker container, and writes results to a local workspace.

For source builds, authenticated scans, provider-specific setup, and platform notes, see Documentation.

Tip

Prefer to run on your Claude Code subscription instead of API credits? The shannon-v1 branch is the last release built on the Claude Agent SDK, so it accepts a Claude Code OAuth token. Generate one with claude setup-token, then run npx @keygraph/shannon@1.9.0 setup and pick OAuth Token. Pentests then cost nothing beyond your existing subscription.

Key Capabilities

  • Proof-by-exploitation reports: Shannon reports validated findings with reproducible proof-of-concept steps instead of speculative warnings.
  • White-box attack planning: Shannon uses source-code analysis to guide dynamic testing and focus on realistic attack paths.
  • Autonomous execution: Shannon launches reconnaissance, vulnerability analysis, exploitation, and report generation from a single command.
  • Authenticated testing: configuration files can describe login flows, test credentials, TOTP, email-based login flows, focus areas, and rules of engagement.
  • OWASP-focused coverage: Shannon targets exploitable Injection, XSS, SSRF, Broken Authentication, and Broken Authorization issues.
  • Resumable workspaces: Shannon can resume interrupted runs without re-running completed agents.

Editions

Shannon ships in two ways: Shannon Open Source, the pentester you run yourself, and the Keygraph platform, the commercial pentesting product that runs Shannon continuously and closes the full AppSec lifecycle around it.

Shannon Open Source (this repository) is the standalone pentester: a CLI agent for white-box, proof-by-exploitation testing of web applications and APIs you own or are authorized to test. It reads your source, plans attacks, executes real exploits, and reports only what it can prove. It runs on demand and is complete in that lane. You point it at a target, it pentests, it reports.

The Keygraph platform is the enterprise-ready, continuous pentesting product powered by Shannon. In the Keygraph platform, an enhanced build of Shannon runs continuously in a hardened, orchestrated environment fed by Keygraph's full code-analysis stack. Around that engine, the platform closes the entire vulnerability lifecycle, from analysis to a verified fix:

  • Analyze: Code Property Graph SAST, SCA with reachability, secrets, IaC, and container scanning. First-class detection in their own right, and context that sharpens Shannon's attacks.
  • Prove: autonomous black-box and source-aware white-box pentests turn candidate findings into proven, exploited vulnerabilities rather than speculative alerts.
  • Manage: one canonical record per vulnerability per repository, deduplicated across every source, with ownership, status, SLA tracking, dashboards, and bidirectional Jira sync.
  • Remediate and verify: patches written automatically and re-tested against the patched code before delivery, landing in your existing review workflow rather than auto-applied.
  • Deploy: self-hosted and air-gapped environments, strict bring-your-own-key model access, and customer-controlled LLM gateway patterns, so source, results, and model traffic stay inside your perimeter.

Shannon is the proof engine at the center of the Keygraph platform. Shannon Open Source gives you that engine to run yourself. The Keygraph platform surrounds Shannon with continuous analysis, finding management, remediation, verification, and enterprise deployment.

AppSec lifecycle stage Shannon Open Source Keygraph platform
Analyze Basic LLM pass-through of source to plan attacks Actual code-base parsing, plus Code Property Graph, SAST, SCA with reachability, secrets, IaC, and containers
Pentest and prove White-box only, proof by exploitation Enhanced white-box, plus black-box and grey-box modes, run continuously
Manage findings Local Markdown report Canonical findings system: deduplication across sources, ownership, SLA, dashboards, Jira sync, and professional pentest-grade PDF reports
Remediate and verify Fix manually from the report, then re-run the full scan to verify Automated remediation: opens a PR with the fix, verified by point re-test without re-running the full scan
Deploy and operate Local CLI and Docker worker Self-hosted, air-gapped, BYOK, continuous, enterprise integrations
License and support AGPL-3.0, community Commercial, supported

Learn more on the Keygraph website, read the Keygraph platform technical overview, start a free trial or book a demo, or contact shannon@keygraph.io.

Architecture

Shannon uses a multi-agent workflow that combines source-code analysis with live exploitation:

        ┌──────────────────────┐
        │   Pre-Reconnaissance │
        │   (source code scan) │
        └──────────┬───────────┘
                   │
                   ▼
        ┌──────────────────────┐
        │   Reconnaissance     │
        │  (attack surface     │
        │   mapping)           │
        └──────────┬───────────┘
                   │
                   ▼
        ┌──────────┴───────────┐
        │          │           │
        ▼          ▼           ▼
  ┌───────────┐ ┌───────────┐ ┌───────────┐
  │ Vuln      │ │ Vuln      │ │   ...     │
  │(Injection)│ │  (XSS)    │ │           │
  └─────┬─────┘ └─────┬─────┘ └─────┬─────┘
        │              │             │
        ▼              ▼             ▼
  ┌───────────┐ ┌───────────┐ ┌───────────┐
  │ Exploit   │ │ Exploit   │ │   ...     │
  │(Injection)│ │  (XSS)    │ │           │
  └─────┬─────┘ └─────┬─────┘ └─────┬─────┘
        │              │             │
        └──────┬───────┴─────────────┘
               │
               ▼
        ┌──────────────────────┐
        │      Reporting       │
        └──────────────────────┘

At a high level:

  • Pre-reconnaissance identifies frameworks, entry points, data flows, and likely attack surfaces from the repository.
  • Reconnaissance explores the live application and correlates runtime behavior with code-level context.
  • Vulnerability analysis runs specialized agents for Injection, XSS, SSRF, Authentication, and Authorization.
  • Exploitation attempts real proof-of-concept attacks and discards hypotheses that cannot be proven.
  • Reporting compiles validated findings, evidence, and remediation guidance into a final Markdown report.

Each scan runs in an ephemeral Docker container with an isolated workspace and per-invocation orchestration.

Documentation

Use these guides for operational detail:

Guide Use it for
Source build and CLI commands Cloning, building, common commands, output paths, and local development.
Configuration Authenticated testing, login flows, rules of engagement, and report filters.
AI providers Selecting the model, the supported providers (Anthropic, OpenAI, xAI, AWS Bedrock, and any other Pi-supported provider), and custom gateways.
Platforms and networking Windows/WSL2, Linux, macOS, Docker networking, local apps, and custom hostnames.
Workspaces and resuming Naming workspaces, resuming interrupted scans, and workspace storage.
Safety and limitations Authorized-use requirements, non-production guidance, mutative effects, cost, and model caveats.
Coverage and roadmap Current vulnerability coverage and planned work.
Keygraph platform The continuous, agentic pentesting platform: code analysis, black-box and white-box testing, finding management, remediation, verification, and enterprise deployment.

Safety, Scope, and Limitations

Shannon is not a passive scanner. Its exploitation agents can create users, submit forms, mutate application state, trigger outbound requests, and otherwise affect the target system. Use sandboxed, staging, or local development environments with disposable data.

You are responsible for using Shannon legally and ethically. Do not point Shannon at systems, repositories, or applications you do not own or do not have explicit authorization to test.

Important limitations:

  • Shannon Open Source focuses on actively exploitable issues such as Injection, XSS, SSRF, Broken Authentication, and Broken Authorization. Broader static-analysis coverage, including vulnerable dependencies and insecure configurations, is delivered through the Keygraph platform.
  • Findings still require human review. LLM-generated reports can contain weakly supported or incorrect details.
  • Shannon is officially supported with Claude models. Smaller, alternative, or proxied non-Claude models may be incomplete or unstable.
  • A full run can take roughly 1 to 1.5 hours and may incur LLM API costs depending on model pricing and application complexity.
  • Do not scan untrusted or adversarial codebases. AI-powered tools that read source code can be exposed to prompt injection.

Read the full Safety and limitations guide before running Shannon in a new environment.

License

Shannon Open Source is licensed under the GNU Affero General Public License v3.0.

Commercial and enterprise licensing is available for organizations that need different license terms, commercial support, private redistribution, managed-service use, or broader deployment options, including the Keygraph platform.

For commercial licensing, contact shannon@keygraph.io.

About Keygraph

Keygraph is the company behind Shannon. It also builds the Keygraph platform, the commercial agentic pentesting product that closes the full AppSec lifecycle and runs an enhanced build of Shannon as its pentesting engine.

Community and Support

Community office hours are available for hands-on help with bugs, deployments, and configuration questions.

  • US/EU: Thursday, 10:00 AM PT
  • Asia: Thursday, 2:00 PM IST
  • Book a slot

Join Discord to ask questions, share feedback, and connect with other Shannon users.

At this time, Keygraph is not accepting external code contributions. Issues are welcome for bug reports and feature requests:

Stay connected:

Built by Keygraph

View on GitHub

Recent activity

commits and pull requests

Releases and announcements

15 total
  1. v2.3.0v2.3.0Aug 6, 2026

    # [2.3.0](https://github.com/KeygraphHQ/shannon/compare/v2.2.0...v2.3.0) (2026-08-06) ### Features * **cli:** support any Pi provider via generic SHANNON_AI_API_KEY ([#415](https://github.com/KeygraphHQ/shannon/issues/415)) ([a1675f8](https://github.com/KeygraphHQ/shannon/commit/a1675f839055baafa5ceace1f5bba0d3205a1422))

  2. v2.2.0v2.2.0Aug 4, 2026

    # [2.2.0](https://github.com/KeygraphHQ/shannon/compare/v2.1.0...v2.2.0) (2026-08-04) ### Features * **worker:** record severity in analysis mode and fix prompt substitutions ([#413](https://github.com/KeygraphHQ/shannon/issues/413)) ([86effd5](https://github.com/KeygraphHQ/shannon/commit/86effd524054a152048d4c2aabb26f90cd79ee1e))

  3. v2.1.0v2.1.0Jul 30, 2026

    # [2.1.0](https://github.com/KeygraphHQ/shannon/compare/v2.0.0...v2.1.0) (2026-07-30) ### Features * multi-provider model support, SARIF output, and exploit-mode fixes ([#402](https://github.com/KeygraphHQ/shannon/issues/402)) ([1ce250d](https://github.com/KeygraphHQ/shannon/commit/1ce250d6a510a1560be58cc13e9684636a3bb025))

  4. v2.0.0v2.0.0Jul 16, 2026

    # [2.0.0](https://github.com/KeygraphHQ/shannon/compare/v1.9.0...v2.0.0) (2026-07-16) ### Features * **worker:** migrate agent runtime from Claude Agent SDK to pi harness ([#389](https://github.com/KeygraphHQ/shannon/issues/389)) ([5ff40f8](https://github.com/KeygraphHQ/shannon/commit/5ff40f8c6f694a5b50753b5e46ba061f88d0c6d6)), closes [#356](https://github.com/KeygraphHQ/shannon/issues/356) [#377](https://github.com/KeygraphHQ/shannon/issues/377) [#383](https://github.com/KeygraphHQ/shannon/issues/383) [#388](https://github.com/KeygraphHQ/shannon/issues/388) ### BREAKING CHANGES * **worker:** Google Vertex AI is no longer a supported provider. The CLAUDE_CODE_USE_VERTEX, ANTHROPIC_VERTEX_PROJECT, CLOUD_ML_REGION, and GOOGLE_APPLICATION_CREDENTIALS environment variables, along with the use_vertex, vertex_project, and cloud_ml_region config.toml keys, are removed. Vertex users must switch to Anthropic, AWS Bedrock, or a custom Anthropic-compatible base URL. The CLAUDE_CODE_MAX_OUTPUT_TOKENS environment variable and the max_output_tokens config.toml key are also removed.

  5. v1.9.0v1.9.0Jul 4, 2026

    # [1.9.0](https://github.com/KeygraphHQ/shannon/compare/v1.8.1...v1.9.0) (2026-07-04) ### Features * **cli:** restructure run folder and improve terminal UX ([#384](https://github.com/KeygraphHQ/shannon/issues/384)) ([00e5645](https://github.com/KeygraphHQ/shannon/commit/00e56455dfb0f2626b63e7e9231980cfb48e2fe2))

Code frequency

additions and deletions
+1.2M-1.2MWeek of 2025-09-28: +16,062 linesWeek of 2025-09-28: -0 linesWeek of 2025-10-05: +116 linesWeek of 2025-10-05: -178 linesWeek of 2025-10-12: +166 linesWeek of 2025-10-12: -4 linesWeek of 2025-10-19: +4,631 linesWeek of 2025-10-19: -3,315 linesWeek of 2025-10-26: +147 linesWeek of 2025-10-26: -151 linesWeek of 2025-11-02: +1,187,243 linesWeek of 2025-11-02: -89 linesWeek of 2025-11-09: +3,123 linesWeek of 2025-11-09: -94 linesWeek of 2025-11-16: +20 linesWeek of 2025-11-16: -22 linesWeek of 2025-11-23: +914 linesWeek of 2025-11-23: -2,397 linesWeek of 2025-11-30: +7 linesWeek of 2025-11-30: -3 linesWeek of 2025-12-07: +36 linesWeek of 2025-12-07: -8 linesWeek of 2025-12-14: +49 linesWeek of 2025-12-14: -12 linesWeek of 2025-12-21: +0 linesWeek of 2025-12-21: -0 linesWeek of 2025-12-28: +0 linesWeek of 2025-12-28: -0 linesWeek of 2026-01-04: +8,410 linesWeek of 2026-01-04: -7,177 linesWeek of 2026-01-11: +7,508 linesWeek of 2026-01-11: -5,129 linesWeek of 2026-01-18: +64 linesWeek of 2026-01-18: -113 linesWeek of 2026-01-25: +0 linesWeek of 2026-01-25: -1 linesWeek of 2026-02-01: +3 linesWeek of 2026-02-01: -1 linesWeek of 2026-02-08: +2,188 linesWeek of 2026-02-08: -707 linesWeek of 2026-02-15: +5,315 linesWeek of 2026-02-15: -4,961 linesWeek of 2026-02-22: +150 linesWeek of 2026-02-22: -14 linesWeek of 2026-03-01: +780 linesWeek of 2026-03-01: -348 linesWeek of 2026-03-08: +16,055 linesWeek of 2026-03-08: -21,259 linesWeek of 2026-03-15: +343 linesWeek of 2026-03-15: -11 linesWeek of 2026-03-22: +20,383 linesWeek of 2026-03-22: -1,201,689 linesWeek of 2026-03-29: +617 linesWeek of 2026-03-29: -498 linesWeek of 2026-04-05: +623 linesWeek of 2026-04-05: -113 linesWeek of 2026-04-12: +4 linesWeek of 2026-04-12: -4 linesWeek of 2026-04-19: +329 linesWeek of 2026-04-19: -440 linesWeek of 2026-04-26: +2,092 linesWeek of 2026-04-26: -384 linesWeek of 2026-05-03: +155 linesWeek of 2026-05-03: -126 linesWeek of 2026-05-10: +0 linesWeek of 2026-05-10: -0 linesWeek of 2026-05-17: +771 linesWeek of 2026-05-17: -150 linesWeek of 2026-05-24: +247 linesWeek of 2026-05-24: -12 linesWeek of 2026-05-31: +6,046 linesWeek of 2026-05-31: -2,396 linesWeek of 2026-06-07: +249 linesWeek of 2026-06-07: -122 linesWeek of 2026-06-14: +361 linesWeek of 2026-06-14: -365 linesWeek of 2026-06-21: +94 linesWeek of 2026-06-21: -147 linesWeek of 2026-06-28: +445 linesWeek of 2026-06-28: -172 linesWeek of 2026-07-05: +0 linesWeek of 2026-07-05: -0 linesWeek of 2026-07-12: +6,248 linesWeek of 2026-07-12: -4,996 linesWeek of 2026-07-19: +4 linesWeek of 2026-07-19: -1 linesWeek of 2026-07-26: +0 linesWeek of 2026-07-26: -0 linesSep 28, 2025Jul 26, 2026
+1.3M lines added, -1.3M removed over the last year.

Commits per week

last 52 weeks
250Week of 2025-08-10: 0 commitsWeek of 2025-08-17: 0 commitsWeek of 2025-08-24: 0 commitsWeek of 2025-08-31: 0 commitsWeek of 2025-09-07: 0 commitsWeek of 2025-09-14: 0 commitsWeek of 2025-09-21: 0 commitsWeek of 2025-09-28: 1 commitsWeek of 2025-10-05: 13 commitsWeek of 2025-10-12: 2 commitsWeek of 2025-10-19: 17 commitsWeek of 2025-10-26: 7 commitsWeek of 2025-11-02: 13 commitsWeek of 2025-11-09: 7 commitsWeek of 2025-11-16: 5 commitsWeek of 2025-11-23: 2 commitsWeek of 2025-11-30: 2 commitsWeek of 2025-12-07: 2 commitsWeek of 2025-12-14: 7 commitsWeek of 2025-12-21: 0 commitsWeek of 2025-12-28: 0 commitsWeek of 2026-01-04: 3 commitsWeek of 2026-01-11: 9 commitsWeek of 2026-01-18: 5 commitsWeek of 2026-01-25: 1 commitsWeek of 2026-02-01: 2 commitsWeek of 2026-02-08: 19 commitsWeek of 2026-02-15: 21 commitsWeek of 2026-02-22: 3 commitsWeek of 2026-03-01: 25 commitsWeek of 2026-03-08: 1 commitsWeek of 2026-03-15: 4 commitsWeek of 2026-03-22: 1 commitsWeek of 2026-03-29: 4 commitsWeek of 2026-04-05: 2 commitsWeek of 2026-04-12: 4 commitsWeek of 2026-04-19: 4 commitsWeek of 2026-04-26: 3 commitsWeek of 2026-05-03: 3 commitsWeek of 2026-05-10: 0 commitsWeek of 2026-05-17: 3 commitsWeek of 2026-05-24: 3 commitsWeek of 2026-05-31: 2 commitsWeek of 2026-06-07: 2 commitsWeek of 2026-06-14: 5 commitsWeek of 2026-06-21: 3 commitsWeek of 2026-06-28: 1 commitsWeek of 2026-07-05: 0 commitsWeek of 2026-07-12: 2 commitsWeek of 2026-07-19: 2 commitsWeek of 2026-07-26: 5 commitsWeek of 2026-08-02: 3 commitsAug 10, 2025Aug 2, 2026
223 commits in the last 52 weeks.

When work happens

weekday and hour
SunMonTueWedThuFriSat036912151821Sun 0:00 — 0 commitsSun 1:00 — 0 commitsSun 2:00 — 0 commitsSun 3:00 — 0 commitsSun 4:00 — 0 commitsSun 5:00 — 0 commitsSun 6:00 — 0 commitsSun 7:00 — 0 commitsSun 8:00 — 0 commitsSun 9:00 — 0 commitsSun 10:00 — 0 commitsSun 11:00 — 0 commitsSun 12:00 — 0 commitsSun 13:00 — 0 commitsSun 14:00 — 0 commitsSun 15:00 — 0 commitsSun 16:00 — 0 commitsSun 17:00 — 0 commitsSun 18:00 — 0 commitsSun 19:00 — 0 commitsSun 20:00 — 0 commitsSun 21:00 — 0 commitsSun 22:00 — 0 commitsSun 23:00 — 0 commitsMon 0:00 — 0 commitsMon 1:00 — 0 commitsMon 2:00 — 0 commitsMon 3:00 — 0 commitsMon 4:00 — 0 commitsMon 5:00 — 0 commitsMon 6:00 — 0 commitsMon 7:00 — 0 commitsMon 8:00 — 0 commitsMon 9:00 — 2 commitsMon 10:00 — 8 commitsMon 11:00 — 3 commitsMon 12:00 — 4 commitsMon 13:00 — 3 commitsMon 14:00 — 1 commitsMon 15:00 — 0 commitsMon 16:00 — 3 commitsMon 17:00 — 2 commitsMon 18:00 — 8 commitsMon 19:00 — 1 commitsMon 20:00 — 8 commitsMon 21:00 — 1 commitsMon 22:00 — 2 commitsMon 23:00 — 0 commitsTue 0:00 — 2 commitsTue 1:00 — 2 commitsTue 2:00 — 2 commitsTue 3:00 — 1 commitsTue 4:00 — 0 commitsTue 5:00 — 0 commitsTue 6:00 — 0 commitsTue 7:00 — 0 commitsTue 8:00 — 2 commitsTue 9:00 — 5 commitsTue 10:00 — 2 commitsTue 11:00 — 1 commitsTue 12:00 — 4 commitsTue 13:00 — 6 commitsTue 14:00 — 3 commitsTue 15:00 — 0 commitsTue 16:00 — 4 commitsTue 17:00 — 0 commitsTue 18:00 — 0 commitsTue 19:00 — 1 commitsTue 20:00 — 0 commitsTue 21:00 — 2 commitsTue 22:00 — 1 commitsTue 23:00 — 1 commitsWed 0:00 — 5 commitsWed 1:00 — 1 commitsWed 2:00 — 1 commitsWed 3:00 — 1 commitsWed 4:00 — 2 commitsWed 5:00 — 0 commitsWed 6:00 — 0 commitsWed 7:00 — 0 commitsWed 8:00 — 0 commitsWed 9:00 — 0 commitsWed 10:00 — 1 commitsWed 11:00 — 3 commitsWed 12:00 — 2 commitsWed 13:00 — 6 commitsWed 14:00 — 0 commitsWed 15:00 — 0 commitsWed 16:00 — 5 commitsWed 17:00 — 2 commitsWed 18:00 — 10 commitsWed 19:00 — 2 commitsWed 20:00 — 0 commitsWed 21:00 — 0 commitsWed 22:00 — 1 commitsWed 23:00 — 1 commitsThu 0:00 — 3 commitsThu 1:00 — 2 commitsThu 2:00 — 0 commitsThu 3:00 — 1 commitsThu 4:00 — 2 commitsThu 5:00 — 0 commitsThu 6:00 — 0 commitsThu 7:00 — 0 commitsThu 8:00 — 0 commitsThu 9:00 — 0 commitsThu 10:00 — 3 commitsThu 11:00 — 3 commitsThu 12:00 — 4 commitsThu 13:00 — 2 commitsThu 14:00 — 2 commitsThu 15:00 — 4 commitsThu 16:00 — 6 commitsThu 17:00 — 9 commitsThu 18:00 — 1 commitsThu 19:00 — 5 commitsThu 20:00 — 4 commitsThu 21:00 — 0 commitsThu 22:00 — 2 commitsThu 23:00 — 2 commitsFri 0:00 — 3 commitsFri 1:00 — 0 commitsFri 2:00 — 2 commitsFri 3:00 — 0 commitsFri 4:00 — 1 commitsFri 5:00 — 0 commitsFri 6:00 — 0 commitsFri 7:00 — 1 commitsFri 8:00 — 0 commitsFri 9:00 — 0 commitsFri 10:00 — 1 commitsFri 11:00 — 6 commitsFri 12:00 — 0 commitsFri 13:00 — 3 commitsFri 14:00 — 2 commitsFri 15:00 — 0 commitsFri 16:00 — 0 commitsFri 17:00 — 5 commitsFri 18:00 — 0 commitsFri 19:00 — 1 commitsFri 20:00 — 2 commitsFri 21:00 — 0 commitsFri 22:00 — 2 commitsFri 23:00 — 2 commitsSat 0:00 — 1 commitsSat 1:00 — 1 commitsSat 2:00 — 3 commitsSat 3:00 — 0 commitsSat 4:00 — 0 commitsSat 5:00 — 0 commitsSat 6:00 — 0 commitsSat 7:00 — 0 commitsSat 8:00 — 0 commitsSat 9:00 — 0 commitsSat 10:00 — 2 commitsSat 11:00 — 1 commitsSat 12:00 — 0 commitsSat 13:00 — 0 commitsSat 14:00 — 0 commitsSat 15:00 — 0 commitsSat 16:00 — 0 commitsSat 17:00 — 0 commitsSat 18:00 — 0 commitsSat 19:00 — 0 commitsSat 20:00 — 1 commitsSat 21:00 — 1 commitsSat 22:00 — 0 commitsSat 23:00 — 1 commits
Commit volume by weekday and hour (UTC). Larger dots mean more commits.
DateListRankStars gained
Mar 5, 2026daily#7+337
Mar 4, 2026daily#3+529
Mar 3, 2026daily#7+324
Feb 15, 2026daily#21+168
Feb 14, 2026daily#17+164
Feb 13, 2026daily#18+134
Feb 12, 2026daily#21+156
Feb 11, 2026daily#15+252
Feb 10, 2026daily#2+756
Feb 9, 2026daily#1+1,224
Feb 8, 2026daily#1+1,270
Feb 7, 2026daily#1+1,230
Feb 6, 2026daily#2+693
  • freeCodeCamp/freeCodeCamp

    freeCodeCamp.org's open-source codebase and curriculum. Learn math, programming, and computer science for free.

    453.6K stars · TypeScript

  • openclaw/openclaw

    Your own personal AI assistant. Any OS. Any Platform. The lobster way. 🦞

    385.5K stars · TypeScript

  • openclaw/openclaw

    Your own personal AI assistant. Any OS. Any Platform. The lobster way. 🦞

    384.4K stars · TypeScript

  • openclaw/openclaw

    Your own personal AI assistant. Any OS. Any Platform. The lobster way. 🦞

    384.4K stars · TypeScript

  • openclaw/openclaw

    Your own personal AI assistant. Any OS. Any Platform. The lobster way. 🦞

    384.4K stars · TypeScript

  • trimstray/the-book-of-secret-knowledge

    A collection of inspiring lists, manuals, cheatsheets, blogs, hacks, one-liners, cli/web tools and more.

    237.2K stars