| name | shannon-ai-pentester |
| description | Autonomous white-box AI pentester for web applications and APIs using source code analysis and live exploit execution |
| triggers | ["run a pentest on my web app","scan my application for security vulnerabilities","set up Shannon AI pentester","automate security testing with Shannon","find vulnerabilities in my API","run Shannon against my repo","configure Shannon pentesting tool","generate a security audit report for my app"] |
Shannon AI Pentester
Skill by ara.so — Daily 2026 Skills collection.
Shannon is an autonomous, white-box AI pentester for web applications and APIs. It reads your source code to identify attack vectors, then executes real exploits (SQLi, XSS, SSRF, auth bypass, authorization flaws) against a live running application — only reporting vulnerabilities with a working proof-of-concept.
How It Works
- Reconnaissance — Nmap, Subfinder, WhatWeb, and Schemathesis scan the target
- Code Analysis — Shannon reads your repository to map attack surfaces
- Parallel Exploitation — Concurrent agents attempt live exploits across all vulnerability categories
- Report Generation — Only confirmed, reproducible findings with copy-paste PoCs are included
Installation & Prerequisites
- Docker (required — Shannon runs entirely in containers)
- An Anthropic API key, Claude Code OAuth token, AWS Bedrock credentials, or Google Vertex AI credentials
git clone https://github.com/KeygraphHQ/shannon.git
cd shannon
Quick Start
export ANTHROPIC_API_KEY="sk-ant-..."
export CLAUDE_CODE_MAX_OUTPUT_TOKENS=64000
cat > .env << 'EOF'
ANTHROPIC_API_KEY=sk-ant-...
CLAUDE_CODE_MAX_OUTPUT_TOKENS=64000
EOF
./shannon start URL=https://your-app.example.com REPO=/path/to/your/repo
Shannon builds containers, starts the workflow in the background, and returns a workflow ID.
Key CLI Commands
./shannon start URL=https://target.example.com REPO=/path/to/repo
./shannon start URL=https://target.example.com REPO=/path/to/repo WORKSPACE=my-audit-2024
./shannon logs <workflow-id>
./shannon status <workflow-id>
./shannon resume WORKSPACE=my-audit-2024
./shannon stop <workflow-id>
./shannon report <workflow-id>
Configuration
Environment Variables
ANTHROPIC_API_KEY=sk-ant-...
CLAUDE_CODE_OAUTH_TOKEN=...
CLAUDE_CODE_MAX_OUTPUT_TOKENS=64000
AWS_ACCESS_KEY_ID=...
AWS_SECRET_ACCESS_KEY=...
AWS_DEFAULT_REGION=us-east-1
SHANNON_AI_PROVIDER=bedrock
SHANNON_BEDROCK_MODEL=anthropic.claude-3-7-sonnet-20250219-v1:0
GOOGLE_APPLICATION_CREDENTIALS=/path/to/service-account.json
SHANNON_AI_PROVIDER=vertex
SHANNON_VERTEX_PROJECT=your-gcp-project
SHANNON_VERTEX_REGION=us-east5
.env File Example
ANTHROPIC_API_KEY=sk-ant-...
CLAUDE_CODE_MAX_OUTPUT_TOKENS=64000
TARGET_USERNAME=admin@example.com
TARGET_PASSWORD=supersecret
TARGET_TOTP_SECRET=BASE32TOTPSECRET
Usage Examples
Basic Web App Pentest
./shannon start \
URL=http://localhost:3000 \
REPO=$(pwd)/../my-express-app
Testing Against OWASP Juice Shop (Demo)
docker run -d -p 3000:3000 bkimminich/juice-shop
./shannon start \
URL=http://localhost:3000 \
REPO=/path/to/juice-shop
Authenticated Testing with 2FA
export TARGET_USERNAME="admin@yourapp.com"
export TARGET_PASSWORD="$ADMIN_PASSWORD"
export TARGET_TOTP_SECRET="$TOTP_BASE32_SECRET"
./shannon start URL=https://staging.yourapp.com REPO=/path/to/repo
AWS Bedrock Provider
export AWS_ACCESS_KEY_ID="$AWS_ACCESS_KEY_ID"
export AWS_SECRET_ACCESS_KEY="$AWS_SECRET_ACCESS_KEY"
export AWS_DEFAULT_REGION=us-east-1
export SHANNON_AI_PROVIDER=bedrock
export SHANNON_BEDROCK_MODEL=anthropic.claude-3-7-sonnet-20250219-v1:0
./shannon start URL=https://target.example.com REPO=/path/to/repo
Google Vertex AI Provider
export GOOGLE_APPLICATION_CREDENTIALS=/path/to/service-account.json
export SHANNON_AI_PROVIDER=vertex
export SHANNON_VERTEX_PROJECT=my-gcp-project
export SHANNON_VERTEX_REGION=us-east5
./shannon start URL=https://target.example.com REPO=/path/to/repo
Workspace and Resume Pattern
Workspaces allow you to pause and resume long-running pentests:
./shannon start \
URL=https://target.example.com \
REPO=/path/to/repo \
WORKSPACE=sprint-42-audit
./shannon resume WORKSPACE=sprint-42-audit
./shannon report WORKSPACE=sprint-42-audit
Output and Reports
Reports are written to the workspace directory (default: ./workspaces/<workflow-id>/):
workspaces/
└── my-audit-2024/
├── report.md # Final pentest report with PoC exploits
├── findings.json # Machine-readable findings
└── logs/ # Per-agent execution logs
The report includes:
- Vulnerability title and CVSS-style severity
- Affected endpoint and parameter
- Root cause with source code reference
- Step-by-step reproduction instructions
- Copy-paste curl/HTTP PoC
Vulnerability Coverage
Shannon currently tests for:
| Category | Examples |
|---|
| Injection | SQL injection, command injection, LDAP injection |
| XSS | Reflected, stored, DOM-based |
| SSRF | Internal network access, cloud metadata endpoints |
| Broken Authentication | Weak tokens, session fixation, auth bypass |
| Broken Authorization | IDOR, privilege escalation, missing access controls |
CI/CD Integration Pattern
name: Shannon Pentest
on:
push:
branches: [staging]
jobs:
pentest:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
with:
path: app
- name: Clone Shannon
run: git clone https://github.com/KeygraphHQ/shannon.git
- name: Start Application
run: |
cd app
docker compose up -d
# Wait for app to be healthy
sleep 30
- name: Run Shannon
working-directory: shannon
env:
ANTHROPIC_API_KEY: ${{ secrets.ANTHROPIC_API_KEY }}
CLAUDE_CODE_MAX_OUTPUT_TOKENS: 64000
run: |
./shannon start \
URL=http://localhost:3000 \
REPO=${{ github.workspace }}/app \
WORKSPACE=ci-${{ github.sha }}
# Wait for completion and get report
./shannon wait ci-${{ github.sha }}
./shannon report ci-${{ github.sha }} > pentest-report.md
Troubleshooting
Docker not found or permission denied
docker info
sudo usermod -aG docker $USER
newgrp docker
Shannon containers fail to build
docker compose -f shannon/docker-compose.yml build --no-cache
Pentest stalls / no progress
./shannon logs <workflow-id>
Target app not reachable from Shannon containers
./shannon start \
URL=http://host.docker.internal:3000 \
REPO=/path/to/repo
docker network create pentest-net
docker run --network pentest-net ...
Rate limit errors from Anthropic
export SHANNON_AI_PROVIDER=bedrock
export AWS_DEFAULT_REGION=us-east-1
Resume after crash
./shannon start URL=... REPO=... WORKSPACE=named-session
./shannon resume WORKSPACE=named-session
Important Disclaimers
- Only test applications you own or have explicit written permission to test.
- Shannon Lite is AGPL-3.0 licensed — any modifications must be open-sourced under the same license.
- Shannon is a white-box tool: it expects access to your application's source code.
- It is not a black-box scanner. Running it against third-party targets without authorization is illegal.
Key Links