
Shannon Ai Pentester
- 1.6k installs
- 66 repo stars
- Updated July 9, 2026
- aradotso/trending-skills
Shannon is a Docker-based autonomous white-box AI pentester that confirms web and API vulnerabilities with live proof-of-concepts.
About
Shannon is an autonomous white-box pentester for web apps and APIs. It reconnoiters targets with Nmap, Subfinder, WhatWeb, and Schemathesis, reads repository code to map attack surfaces, then runs parallel exploit agents for SQLi, XSS, SSRF, auth bypass, and authorization flaws. Only confirmed reproducible findings with copy-paste proof-of-concepts reach the final report. Setup requires Docker and Anthropic, Claude Code OAuth, Bedrock, or Vertex credentials. CLI covers start with URL and REPO paths, logs, status, resume via WORKSPACE, stop, and report. Configuration supports rate limits, concurrency, and model selection. Use when teams need automated security testing tied to real source context rather than black-box scans alone.
- Combines recon tools, repository code analysis, and parallel live exploit agents.
- Reports only confirmed vulnerabilities with reproducible proof-of-concept steps.
- Runs fully in Docker with ./shannon start URL=... REPO=... workflow IDs.
- Supports resume, status, logs, stop, and final report commands.
- Targets web applications and APIs with SQLi, XSS, SSRF, and auth flaw coverage.
Shannon Ai Pentester by the numbers
- 1,621 all-time installs (skills.sh)
- +16 installs in the week ending Jul 28, 2026 (Skillselion tracking)
- Ranked #316 of 2,209 Security skills by installs in the Skillselion catalog
- Security screen: HIGH risk (skills.sh audit)
- Data as of Jul 28, 2026 (Skillselion catalog sync)
shannon-ai-pentester capabilities & compatibility
- Capabilities
- reconnaissance · code analysis · exploit agents · poc reports
- Use cases
- security audit · testing
What shannon-ai-pentester says it does
Shannon is an autonomous, white-box AI pentester for web applications and APIs. It reads your source code to identify attack vectors, then executes real exploits
npx skills add https://github.com/aradotso/trending-skills --skill shannon-ai-pentesterAdd your badge
Show developers this skill is listed on Skillselion. Paste this into your README.
| Installs | 1.6k |
|---|---|
| repo stars | ★ 66 |
| Security audit | 1 / 3 scanners passed |
| Last updated | July 9, 2026 |
| Repository | aradotso/trending-skills ↗ |
How do I automate security testing that uses my source code and verifies real exploits against a running app?
Run Shannon, an autonomous white-box AI pentester that maps attack surfaces from source code and confirms exploits with live PoCs against a running app.
Who is it for?
Teams pentesting web apps and APIs with repository context and live target URLs.
Skip if: Black-box-only scans without code access or non-Docker environments.
When should I use this skill?
User asks to run a pentest, scan an API, or configure Shannon against a repo.
What you get
A Shannon workflow report listing only confirmed, reproducible findings with PoC steps.
- Security audit report
- Confirmed vulnerability findings with proof
Files
Shannon AI Pentester
Skill by ara.so — Daily 2026 Skills collection.
Shannon is an autonomous, white-box AI pentester for web applications and APIs. It reads your source code to identify attack vectors, then executes real exploits (SQLi, XSS, SSRF, auth bypass, authorization flaws) against a live running application — only reporting vulnerabilities with a working proof-of-concept.
How It Works
1. Reconnaissance — Nmap, Subfinder, WhatWeb, and Schemathesis scan the target 2. Code Analysis — Shannon reads your repository to map attack surfaces 3. Parallel Exploitation — Concurrent agents attempt live exploits across all vulnerability categories 4. Report Generation — Only confirmed, reproducible findings with copy-paste PoCs are included
Installation & Prerequisites
- Docker (required — Shannon runs entirely in containers)
- An Anthropic API key, Claude Code OAuth token, AWS Bedrock credentials, or Google Vertex AI credentials
git clone https://github.com/KeygraphHQ/shannon.git
cd shannonQuick Start
# Option A: Export credentials
export ANTHROPIC_API_KEY="sk-ant-..."
export CLAUDE_CODE_MAX_OUTPUT_TOKENS=64000
# Option B: .env file
cat > .env << 'EOF'
ANTHROPIC_API_KEY=sk-ant-...
CLAUDE_CODE_MAX_OUTPUT_TOKENS=64000
EOF
# Run a pentest
./shannon start URL=https://your-app.example.com REPO=/path/to/your/repoShannon builds containers, starts the workflow in the background, and returns a workflow ID.
Key CLI Commands
# Start a pentest
./shannon start URL=https://target.example.com REPO=/path/to/repo
# Start with explicit workspace name (for resuming)
./shannon start URL=https://target.example.com REPO=/path/to/repo WORKSPACE=my-audit-2024
# Monitor live progress (tail logs)
./shannon logs <workflow-id>
# Check status of a running pentest
./shannon status <workflow-id>
# Resume an interrupted pentest
./shannon resume WORKSPACE=my-audit-2024
# Stop a running pentest
./shannon stop <workflow-id>
# View the final report
./shannon report <workflow-id>Configuration
Environment Variables
# Required (choose one auth method)
ANTHROPIC_API_KEY=sk-ant-... # Anthropic direct
CLAUDE_CODE_OAUTH_TOKEN=... # Claude Code OAuth
# Recommended
CLAUDE_CODE_MAX_OUTPUT_TOKENS=64000 # Increase output window for large reports
# AWS Bedrock (alternative to Anthropic direct)
AWS_ACCESS_KEY_ID=...
AWS_SECRET_ACCESS_KEY=...
AWS_DEFAULT_REGION=us-east-1
SHANNON_AI_PROVIDER=bedrock
SHANNON_BEDROCK_MODEL=anthropic.claude-3-7-sonnet-20250219-v1:0
# Google Vertex AI (alternative to Anthropic direct)
GOOGLE_APPLICATION_CREDENTIALS=/path/to/service-account.json
SHANNON_AI_PROVIDER=vertex
SHANNON_VERTEX_PROJECT=your-gcp-project
SHANNON_VERTEX_REGION=us-east5.env File Example
# .env (place in the shannon project root)
ANTHROPIC_API_KEY=sk-ant-...
CLAUDE_CODE_MAX_OUTPUT_TOKENS=64000
# Optional: target credentials for authenticated testing
TARGET_USERNAME=admin@example.com
TARGET_PASSWORD=supersecret
TARGET_TOTP_SECRET=BASE32TOTPSECRET # Shannon handles 2FA automaticallyUsage Examples
Basic Web App Pentest
# Point Shannon at a running local app with its source code
./shannon start \
URL=http://localhost:3000 \
REPO=$(pwd)/../my-express-appTesting Against OWASP Juice Shop (Demo)
# Pull and run Juice Shop
docker run -d -p 3000:3000 bkimminich/juice-shop
# Run Shannon against it
./shannon start \
URL=http://localhost:3000 \
REPO=/path/to/juice-shopAuthenticated Testing with 2FA
export TARGET_USERNAME="admin@yourapp.com"
export TARGET_PASSWORD="$ADMIN_PASSWORD"
export TARGET_TOTP_SECRET="$TOTP_BASE32_SECRET"
./shannon start URL=https://staging.yourapp.com REPO=/path/to/repoAWS Bedrock Provider
export AWS_ACCESS_KEY_ID="$AWS_ACCESS_KEY_ID"
export AWS_SECRET_ACCESS_KEY="$AWS_SECRET_ACCESS_KEY"
export AWS_DEFAULT_REGION=us-east-1
export SHANNON_AI_PROVIDER=bedrock
export SHANNON_BEDROCK_MODEL=anthropic.claude-3-7-sonnet-20250219-v1:0
./shannon start URL=https://target.example.com REPO=/path/to/repoGoogle Vertex AI Provider
export GOOGLE_APPLICATION_CREDENTIALS=/path/to/service-account.json
export SHANNON_AI_PROVIDER=vertex
export SHANNON_VERTEX_PROJECT=my-gcp-project
export SHANNON_VERTEX_REGION=us-east5
./shannon start URL=https://target.example.com REPO=/path/to/repoWorkspace and Resume Pattern
Workspaces allow you to pause and resume long-running pentests:
# Start with a named workspace
./shannon start \
URL=https://target.example.com \
REPO=/path/to/repo \
WORKSPACE=sprint-42-audit
# Later, resume from where it stopped
./shannon resume WORKSPACE=sprint-42-audit
# Workspaces persist results so you can re-run reports
./shannon report WORKSPACE=sprint-42-auditOutput and Reports
Reports are written to the workspace directory (default: ./workspaces/<workflow-id>/):
workspaces/
└── my-audit-2024/
├── report.md # Final pentest report with PoC exploits
├── findings.json # Machine-readable findings
└── logs/ # Per-agent execution logsThe report includes:
- Vulnerability title and CVSS-style severity
- Affected endpoint and parameter
- Root cause with source code reference
- Step-by-step reproduction instructions
- Copy-paste curl/HTTP PoC
Vulnerability Coverage
Shannon currently tests for:
| Category | Examples |
|---|---|
| Injection | SQL injection, command injection, LDAP injection |
| XSS | Reflected, stored, DOM-based |
| SSRF | Internal network access, cloud metadata endpoints |
| Broken Authentication | Weak tokens, session fixation, auth bypass |
| Broken Authorization | IDOR, privilege escalation, missing access controls |
CI/CD Integration Pattern
# .github/workflows/pentest.yml
name: Shannon Pentest
on:
push:
branches: [staging]
jobs:
pentest:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
with:
path: app
- name: Clone Shannon
run: git clone https://github.com/KeygraphHQ/shannon.git
- name: Start Application
run: |
cd app
docker compose up -d
# Wait for app to be healthy
sleep 30
- name: Run Shannon
working-directory: shannon
env:
ANTHROPIC_API_KEY: ${{ secrets.ANTHROPIC_API_KEY }}
CLAUDE_CODE_MAX_OUTPUT_TOKENS: 64000
run: |
./shannon start \
URL=http://localhost:3000 \
REPO=${{ github.workspace }}/app \
WORKSPACE=ci-${{ github.sha }}
# Wait for completion and get report
./shannon wait ci-${{ github.sha }}
./shannon report ci-${{ github.sha }} > pentest-report.md
- name: Upload Report
uses: actions/upload-artifact@v4
with:
name: pentest-report
path: shannon/pentest-report.mdTroubleshooting
Docker not found or permission denied
# Ensure Docker daemon is running
docker info
# Add your user to the docker group (Linux)
sudo usermod -aG docker $USER
newgrp dockerShannon containers fail to build
# Force a clean rebuild
docker compose -f shannon/docker-compose.yml build --no-cachePentest stalls / no progress
# Check live logs for the blocking agent
./shannon logs <workflow-id>
# Common causes:
# - Target app is not reachable from inside the Shannon container
# - ANTHROPIC_API_KEY is missing or rate-limited
# - CLAUDE_CODE_MAX_OUTPUT_TOKENS not set (model hits default limit)Target app not reachable from Shannon containers
# Use host.docker.internal instead of localhost
./shannon start \
URL=http://host.docker.internal:3000 \
REPO=/path/to/repo
# Or put both on the same Docker network
docker network create pentest-net
docker run --network pentest-net ... # your app
# Then set SHANNON_DOCKER_NETWORK=pentest-net in .envRate limit errors from Anthropic
# Use AWS Bedrock or Vertex AI to avoid shared rate limits
export SHANNON_AI_PROVIDER=bedrock
export AWS_DEFAULT_REGION=us-east-1Resume after crash
# Always use WORKSPACE= when starting to enable resumability
./shannon start URL=... REPO=... WORKSPACE=named-session
# Resume
./shannon resume WORKSPACE=named-sessionImportant Disclaimers
- Only test applications you own or have explicit written permission to test.
- Shannon Lite is AGPL-3.0 licensed — any modifications must be open-sourced under the same license.
- Shannon is a white-box tool: it expects access to your application's source code.
- It is not a black-box scanner. Running it against third-party targets without authorization is illegal.
Key Links
- GitHub: https://github.com/KeygraphHQ/shannon
- Keygraph Platform (Pro): https://keygraph.io
- Sample Report (Juice Shop):
sample-reports/shannon-report-juice-shop.mdin the repo - Shannon Pro Architecture:
SHANNON-PRO.mdin the repo - Announcements: https://github.com/KeygraphHQ/shannon/discussions/categories/announcements
- Discord: https://discord.gg/9ZqQPuhJB7
Related skills
FAQ
What is shannon-ai-pentester?
Run Shannon, an autonomous white-box AI pentester that maps attack surfaces from source code and confirms exploits with live PoCs against a running app.
What is shannon-ai-pentester?
Run Shannon, an autonomous white-box AI pentester that maps attack surfaces from source code and confirms exploits with live PoCs against a running app.
What is shannon-ai-pentester?
Run Shannon, an autonomous white-box AI pentester that maps attack surfaces from source code and confirms exploits with live PoCs against a running app.
Is Shannon Ai Pentester safe to install?
skills.sh reports 1 of 3 security scanners passed. Review the Security Audits panel on this page before installing in production.