shannon-ai-pentester

shannon-ai-pentester — an installable skill for AI agents.

By reason-machines · 1,655 installs

npx skills add reason-machines/trending-skills --skill shannon-ai-pentester

Source repository · Upstream listing

Shannon AI Pentester Skill by [ara.so](https://ara.so) — Daily 2026 Skills collection. Shannon is an autonomous, white box AI pentester for web applications and APIs. It reads your source code to identify attack vectors, then executes real exploits (SQLi, XSS, SSRF, auth bypass, authorization flaws) against a live running application — only reporting vulnerabilities with a working proof of concept. How It Works 1. Reconnaissance — Nmap, Subfinder, WhatWeb, and Schemathesis scan the target 2. Code Analysis — Shannon reads your repository to map attack surfaces 3. Parallel Exploitation — Concurrent agents attempt live exploits across all vulnerability categories 4. Report Generation — Only confirmed, reproducible findings with copy paste PoCs are included Installation & Prerequisites Docker (required — Shannon runs entirely in containers) An Anthropic API key, Claude Code OAuth token, AWS Bedrock credentials, or Google Vertex AI credentials Quick Start Shannon builds containers, starts the workflow in the background, and returns a workflow ID. Key CLI Commands Configuration Environment Variables .env File Example Usage Examples Basic Web App Pentest Testing Against OWASP Juice Shop (Demo) Authenticated Testing with 2FA AWS Bedrock Provider Google Vertex AI Provider Workspace and Resume Pattern Workspaces allow you to pause and resume long running pentests: Output and Reports Reports are written to the workspace directory (default: ./workspaces/<workflow id / ): The report includes: Vulnerability title and CVSS style severity Affected endpoint and parameter Root cause with source code reference Step by step reproduction instructions Copy paste curl/HTTP PoC Vulnerability Coverage Shannon currently tests for: Category Examples Injection SQL injection, command injection, LDAP injection XSS Reflected, stored, DOM based SSRF Internal network access, cloud metadata endpoints Broken Authentication Weak tokens, session fixation, auth bypass Broken Authorization IDOR, privilege escalation, missing access controls CI/CD Integration Pattern Troubleshooting Docker not found or permission denied Shannon containers fail to build Pentest stalls / no progress Target app not reachable from Shannon containers Rate limit errors from Anthropic Resume after crash Important Disclaimers Only test applications you own or have explicit written permission to test. Shannon Lite is AGPL 3.0 licensed — any modifications must be open sourced under the same license. Shannon is a white box tool : it expects access to your application's source code. It is not a black box scanner. Running it against third party targets without authorization is illegal. Key Links GitHub : https://github.com/KeygraphHQ/shannon Keygraph Platform (Pro) : https://keygraph.io Sample Report (Juice Shop) : sample reports/shannon report juice shop.md in the repo Shannon Pro Architecture : SHANNON PRO.md in the repo Announcements : https://github.com/KeygraphHQ/shannon/discussions/categories/announcements Discord : https://discord.gg/9ZqQPuhJB7