diff --git a/.env.example b/.env.example index 6e20880f..3c960e9b 100644 --- a/.env.example +++ b/.env.example @@ -13,7 +13,7 @@ SHANNON_AI_MODEL=anthropic:claude-sonnet-4-6 # --- xAI --------------------------------------------------------------------- # SHANNON_AI_API_KEY=your-api-key-here -# SHANNON_AI_MODEL=xai:grok-4.5 +# SHANNON_AI_MODEL=xai:grok-4.7 # --- AWS Bedrock ------------------------------------------------------------- # Bearer token only; model must be enabled in your region. @@ -48,9 +48,9 @@ SHANNON_AI_MODEL=anthropic:claude-sonnet-4-6 # See the guide below to use an OpenAI subscription # https://github.com/KeygraphHQ/shannon/blob/main/docs/ai-providers.md#openai-codex-chatgpt-pluspro-subscription # SHANNON_USE_PI_AUTH=1 -# SHANNON_AI_MODEL=openai-codex:gpt-5.5 +# SHANNON_AI_MODEL=openai-codex:gpt-6-sol # Or the guide below to use an xAI subscription # https://github.com/KeygraphHQ/shannon/blob/main/docs/ai-providers.md#xai-grok-subscription # SHANNON_USE_PI_AUTH=1 -# SHANNON_AI_MODEL=xai:grok-4.6 +# SHANNON_AI_MODEL=xai:grok-4.7 diff --git a/apps/cli/src/commands/setup.ts b/apps/cli/src/commands/setup.ts index 3208c184..c280b21f 100644 --- a/apps/cli/src/commands/setup.ts +++ b/apps/cli/src/commands/setup.ts @@ -36,17 +36,24 @@ const GATEWAY_DIALECTS: readonly { /** Suggested models per curated provider, best-first. Free-text entry accepts any model in the provider's catalogue. */ const MODEL_SUGGESTIONS: Readonly> = { - anthropic: ['claude-sonnet-4-6', 'claude-opus-4-8', 'claude-opus-4-7', 'claude-haiku-4-5-20251001'], - openai: ['gpt-5.6-sol', 'gpt-5.5', 'gpt-5.4'], - xai: ['grok-4.5'], + anthropic: [ + 'claude-sonnet-5', + 'claude-opus-5', + 'claude-sonnet-4-6', + 'claude-opus-4-8', + 'claude-opus-4-7', + 'claude-haiku-4-5-20251001', + ], + openai: ['gpt-6-sol', 'gpt-5.6-sol', 'gpt-5.5', 'gpt-5.4'], + xai: ['grok-4.7'], 'amazon-bedrock': ['us.anthropic.claude-sonnet-4-6', 'us.anthropic.claude-opus-4-8', 'us.anthropic.claude-opus-4-7'], }; /** Placeholder shown in the free-text model ID prompt, per curated provider. */ const MODEL_ID_PLACEHOLDER: Readonly> = { anthropic: 'claude-sonnet-4-6', - openai: 'gpt-5.6-sol', - xai: 'grok-4.5', + openai: 'gpt-6-sol', + xai: 'grok-4.7', 'amazon-bedrock': 'us.anthropic.claude-opus-4-8', }; diff --git a/docs/ai-providers.md b/docs/ai-providers.md index e8f6e08a..4cb7fbb6 100644 --- a/docs/ai-providers.md +++ b/docs/ai-providers.md @@ -59,9 +59,9 @@ These are the models `npx @keygraph/shannon setup` offers, best-first. They are | Provider | Suggested model IDs | | --- | --- | -| `anthropic` | `claude-sonnet-4-6`, `claude-opus-4-8`, `claude-opus-4-7`, `claude-haiku-4-5-20251001` | -| `openai` | `gpt-5.6-sol`, `gpt-5.5`, `gpt-5.4` | -| `xai` | `grok-4.6`, `grok-4.5` | +| `anthropic` | `claude-sonnet-5`, `claude-opus-5`, `claude-sonnet-4-6`, `claude-opus-4-8`, `claude-opus-4-7`, `claude-haiku-4-5-20251001` | +| `openai` | `gpt-6-sol`, `gpt-5.6-sol`, `gpt-5.5`, `gpt-5.4` | +| `xai` | `grok-4.7` | | `amazon-bedrock` | `us.anthropic.claude-sonnet-4-6`, `us.anthropic.claude-opus-4-8`, `us.anthropic.claude-opus-4-7` | Bedrock IDs are region-prefixed and must be enabled in your account, so the ID that works for you may differ from the one listed here. @@ -81,14 +81,14 @@ OpenAI: ```bash export SHANNON_AI_API_KEY=sk-... -export SHANNON_AI_MODEL=openai:gpt-5.6-sol +export SHANNON_AI_MODEL=openai:gpt-6-sol ``` xAI: ```bash export SHANNON_AI_API_KEY=xai-... -export SHANNON_AI_MODEL=xai:grok-4.5 +export SHANNON_AI_MODEL=xai:grok-4.7 ``` Source-build mode reads the same variables from a `.env` file. @@ -130,7 +130,7 @@ OpenAI Responses LLM gateway: ```bash export SHANNON_AI_API_KEY=sk-... -export SHANNON_AI_MODEL=openai:gpt-5.6-sol +export SHANNON_AI_MODEL=openai:gpt-6-sol export SHANNON_AI_BASE_URL=https://llm-gateway.example.com/v1 ``` @@ -282,12 +282,12 @@ An xAI subscription can run Shannon. Shannon reuses a login created by Pi. ```bash export SHANNON_USE_PI_AUTH=1 - export SHANNON_AI_MODEL=xai:grok-4.6 + export SHANNON_AI_MODEL=xai:grok-4.7 ``` 4. In npx mode, run `npx @keygraph/shannon start ...` from the same shell. In source-build mode, add the two variables to `.env` and run `./shannon start ...`. -Suggested Grok models are `grok-4.6` and `grok-4.5`. +The suggested Grok model is `grok-4.7`. ## Claude Code subscription diff --git a/docs/development.md b/docs/development.md index d3cfb584..d3f0dd4c 100644 --- a/docs/development.md +++ b/docs/development.md @@ -123,7 +123,7 @@ npx @keygraph/shannon start -u https://example.com -r /path/to/repo -w q1-audit npx @keygraph/shannon start -u https://example.com -r /path/to/repo --follow # Validate the configured login only, then stop (no pentest or report). -npx @keygraph/shannon start -u https://example.com -r /path/to/repo -c /path/to/my-config.yaml --validate-auth --follow +npx @keygraph/shannon start -u https://example.com -r /path/to/repo -c /path/to/my-config.yaml --validate-auth # List running and completed scans. npx @keygraph/shannon scans diff --git a/llms-full.txt b/llms-full.txt index 54b0da76..05bc1c33 100644 --- a/llms-full.txt +++ b/llms-full.txt @@ -523,6 +523,9 @@ npx @keygraph/shannon start -u https://example.com -r /path/to/repo -w q1-audit # Stream the log until the scan finishes, then exit on its outcome (useful in CI). npx @keygraph/shannon start -u https://example.com -r /path/to/repo --follow +# Validate the configured login only, then stop (no pentest or report). +npx @keygraph/shannon start -u https://example.com -r /path/to/repo -c /path/to/my-config.yaml --validate-auth + # List running and completed scans. npx @keygraph/shannon scans ``` @@ -535,6 +538,7 @@ Source-build examples: ./shannon start -u https://example.com -r /path/to/repo -o ./my-reports ./shannon start -u https://example.com -r /path/to/repo -w q1-audit ./shannon start -u https://example.com -r /path/to/repo --follow +./shannon start -u https://example.com -r /path/to/repo -c /path/to/my-config.yaml --validate-auth ./shannon scans # Rebuild the worker image. @@ -751,6 +755,17 @@ login_flow: - "Click " ``` +### Validating Authentication Only + +To confirm your login flow works before committing to a full scan, add `--validate-auth` to `start`: + +```bash +npx @keygraph/shannon start -u https://your-app.com -r /path/to/repo -c config.yaml --validate-auth +``` + +The run performs preflight and the single real login, then stops. No pentest, reconciliation, or report +is produced. It requires an `authentication` block in the config. + --- # File: docs/ai-providers.md @@ -816,9 +831,9 @@ These are the models `npx @keygraph/shannon setup` offers, best-first. They are | Provider | Suggested model IDs | | --- | --- | -| `anthropic` | `claude-sonnet-4-6`, `claude-opus-4-8`, `claude-opus-4-7`, `claude-haiku-4-5-20251001` | -| `openai` | `gpt-5.6-sol`, `gpt-5.5`, `gpt-5.4` | -| `xai` | `grok-4.6`, `grok-4.5` | +| `anthropic` | `claude-sonnet-5`, `claude-opus-5`, `claude-sonnet-4-6`, `claude-opus-4-8`, `claude-opus-4-7`, `claude-haiku-4-5-20251001` | +| `openai` | `gpt-6-sol`, `gpt-5.6-sol`, `gpt-5.5`, `gpt-5.4` | +| `xai` | `grok-4.7` | | `amazon-bedrock` | `us.anthropic.claude-sonnet-4-6`, `us.anthropic.claude-opus-4-8`, `us.anthropic.claude-opus-4-7` | Bedrock IDs are region-prefixed and must be enabled in your account, so the ID that works for you may differ from the one listed here. @@ -838,14 +853,14 @@ OpenAI: ```bash export SHANNON_AI_API_KEY=sk-... -export SHANNON_AI_MODEL=openai:gpt-5.6-sol +export SHANNON_AI_MODEL=openai:gpt-6-sol ``` xAI: ```bash export SHANNON_AI_API_KEY=xai-... -export SHANNON_AI_MODEL=xai:grok-4.5 +export SHANNON_AI_MODEL=xai:grok-4.7 ``` Source-build mode reads the same variables from a `.env` file. @@ -887,7 +902,7 @@ OpenAI Responses LLM gateway: ```bash export SHANNON_AI_API_KEY=sk-... -export SHANNON_AI_MODEL=openai:gpt-5.6-sol +export SHANNON_AI_MODEL=openai:gpt-6-sol export SHANNON_AI_BASE_URL=https://llm-gateway.example.com/v1 ``` @@ -1039,12 +1054,12 @@ An xAI subscription can run Shannon. Shannon reuses a login created by Pi. ```bash export SHANNON_USE_PI_AUTH=1 - export SHANNON_AI_MODEL=xai:grok-4.6 + export SHANNON_AI_MODEL=xai:grok-4.7 ``` 4. In npx mode, run `npx @keygraph/shannon start ...` from the same shell. In source-build mode, add the two variables to `.env` and run `./shannon start ...`. -Suggested Grok models are `grok-4.6` and `grok-4.5`. +The suggested Grok model is `grok-4.7`. ## Claude Code subscription