shannon-ai-pentester
shannon-ai-pentester — an installable skill for AI agents.
By reason-machines · 1,655 installs
npx skills add reason-machines/trending-skills --skill shannon-ai-pentester
Source repository · Upstream listing
Shannon AI Pentester
Skill by [ara.so](https://ara.so) — Daily 2026 Skills collection.
Shannon is an autonomous, white box AI pentester for web applications and APIs. It reads your source code to identify attack vectors, then executes real exploits (SQLi, XSS, SSRF, auth bypass, authorization flaws) against a live running application — only reporting vulnerabilities with a working proof of concept.
How It Works
1. Reconnaissance — Nmap, Subfinder, WhatWeb, and Schemathesis scan the target
2. Code Analysis — Shannon reads your repository to map attack surfaces
3. Parallel Exploitation — Concurrent agents attempt live exploits across all vulnerability categories
4. Report Generation — Only confirmed, reproducible findings with copy paste PoCs are included
Installation & Prerequisites
Docker (required — Shannon runs entirely in containers)
An Anthropic API key, Claude Code OAuth token, AWS Bedrock credentials, or Google Vertex AI credentials
Quick Start
Shannon builds containers, starts the workflow in the background, and returns a workflow ID.
Key CLI Commands
Configuration
Environment Variables
.env File Example
Usage Examples
Basic Web App Pentest
Testing Against OWASP Juice Shop (Demo)
Authenticated Testing with 2FA
AWS Bedrock Provider
Google Vertex AI Provider
Workspace and Resume Pattern
Workspaces allow you to pause and resume long running pentests:
Output and Reports
Reports are written to the workspace directory (default: ./workspaces/<workflow id / ):
The report includes:
Vulnerability title and CVSS style severity
Affected endpoint and parameter
Root cause with source code reference
Step by step reproduction instructions
Copy paste curl/HTTP PoC
Vulnerability Coverage
Shannon currently tests for:
Category Examples
Injection SQL injection, command injection, LDAP injection
XSS Reflected, stored, DOM based
SSRF Internal network access, cloud metadata endpoints
Broken Authentication Weak tokens, session fixation, auth bypass
Broken Authorization IDOR, privilege escalation, missing access controls
CI/CD Integration Pattern
Troubleshooting
Docker not found or permission denied
Shannon containers fail to build
Pentest stalls / no progress
Target app not reachable from Shannon containers
Rate limit errors from Anthropic
Resume after crash
Important Disclaimers
Only test applications you own or have explicit written permission to test.
Shannon Lite is AGPL 3.0 licensed — any modifications must be open sourced under the same license.
Shannon is a white box tool : it expects access to your application's source code.
It is not a black box scanner. Running it against third party targets without authorization is illegal.
Key Links
GitHub : https://github.com/KeygraphHQ/shannon
Keygraph Platform (Pro) : https://keygraph.io
Sample Report (Juice Shop) : sample reports/shannon report juice shop.md in the repo
Shannon Pro Architecture : SHANNON PRO.md in the repo
Announcements : https://github.com/KeygraphHQ/shannon/discussions/categories/announcements
Discord : https://discord.gg/9ZqQPuhJB7