* feat(worker): migrate agent runtime from Claude Agent SDK to pi harness
* feat: remove Google Vertex AI provider support
* fix(worker): route Bedrock and custom-base-URL providers from env
* feat(prompts): instruct agents to call submit_exploitation_queue and submit_auth_result
* fix(worker): count sub-agent cost and surface compaction failures
* refactor(worker): rename claude-executor to pi-executor
* feat(worker): pi-event-driven output formatting
* fix(worker): gate adaptive thinking to Opus models, drop CLAUDE_THINKING_LEVEL
* fix(worker): restore minLength/minItems on vuln-collector schemas
* feat(worker): give task sub-agent write+bash, align tool descriptions
* feat(worker): add glob custom tool and route code_path globs to it
* refactor(prompts): use pi tool names (task, todo_write, read, bash, glob)
* refactor(prompts): drop stale MCP terminology for collector tools
* refactor(prompts): drop collector server names from deliverable instructions
* fix(worker): restore minLength/minItems on pre-recon and exploit collector schemas
* feat(worker): load playwright-cli skill via pi resource loader
* refactor(cli): remove CLAUDE_CODE_MAX_OUTPUT_TOKENS config
* build: drop @anthropic-ai/claude-code from worker image
* docs: remove vertex references from llms context
* docs(worker): update stale sdk comments
* refactor(worker): unify provider precedence between preflight and executor
* feat(worker): enforce bounded bash timeouts via pi extension
* ci: bump the beta release line to 2.0.0 (#356)
* fix(cli): pin npx command hints to beta tag
* fix: render agent deliverables before the success commit so resume preserves them (#377)
* feat(cli): restructure run folder and improve terminal UX (#383)
* feat: surface report at run root and nest run internals under .shannon
* feat: use plain-language wording in user-facing terminal messages
* feat(cli): guide users to watch scan progress and surface report path on start
* docs: sync run-folder layout and CLI wording across docs and comments
* feat(cli): add version command reporting package version or git SHA
* feat(cli): detect TTY for interactive prompts, color, and progress output
* docs: document --yes flag, version command, and tty module
* fix(cli): FORCE_COLOR precedence and plain uninstall --yes output
* fix(cli): respect empty NO_COLOR
* fix(cli): let NO_COLOR take precedence over FORCE_COLOR
* docs: mark claude-code-router integration as removed
* refactor(worker): converge shared core with shannon-oss (#388)
* fix(worker): port keygraph shared-core correctness fixes
* refactor(worker): adopt collectors/ and ai/pi/ layout; add task budget cap and cancellation
* refactor(worker): drop inconsistent Collector "Server" suffix
* refactor(worker): drop unused providerConfig/apiKey seams, resolve credentials from env only
* refactor(worker): port oss code_path pattern expansion + external_directory allow
* fix(worker): preserve dotfile paths in code_path avoid patterns (.env no longer stripped to env)
* feat(worker): render Unprocessed Vulnerabilities section in exploit deliverable (align with oss)
* feat(worker): request set_blind_spots for all vuln classes (align auth/ssrf with production prompts)
* refactor(worker): adopt unified permissionSystem* naming and helper layout
* refactor(worker): inline blind_spots into vuln deliverable section array
* chore(worker): drop unused zod dependency (tree is typebox-native)
* fix(worker): normalize base32 TOTP secret to accept padding and whitespace
* refactor(worker): adopt shared toolResult helper and flatSchema naming in collectors
* refactor(worker): use undefined over null in queue-schema builders
* docs(worker): converge renderer/collector doc comments to current pi terminology
* refactor(worker): adopt schema.ts cleanInput/stringEnum helpers in collectors
* feat(worker): converge exploit-collector/renderer with vendored; capture and render overview for blocked findings
* refactor(worker): converge session-tools/pipeline/exploitation-checker with vendored
* refactor(worker): converge task-tool usage reporting with vendored onUsage callback
* refactor(worker): converge structured output onto a submitTool executor channel
* docs(worker): expand exploit-renderer docstring to match shannon-oss
* docs(worker): adopt richer vuln-renderer docstring from shannon-oss
* docs(worker): neutralize billing-detection wording for shannon-oss parity
* fix(worker): verify checkpoint hash in the deliverables clone being reset
* fix(worker): fail fast on malformed exploitation queue JSON
* fix(worker): honor retryable flag when classifying exploitation-queue check failures
* fix(worker): fail fast on corrupted session.json in run-scope validation
* feat(worker): propagate Temporal cancellation signal into agent and auth pi sessions
* fix(worker): mark exploit agent complete when exploitation is skipped so resume skips it
* prompts: drop scan description from executive report prompt
* refactor(worker): add createGenericSubmitTool for raw JSON-schema submit tools
* refactor(worker): gate playwright-cli skill to browser agents via skillsOverride (adopt shannon-oss mechanism)
* docs(worker): correct formatLogTime comment to UTC to match toISOString
* refactor(worker): converge queue-schemas with shannon-oss (guarded count, decl order)
* refactor(worker): converge task-tool with shannon-oss (byte-identical; modelRegistry optional)
* fix(worker): use replaceLiteral for all prompt value insertions to prevent $-mangling
* fix(worker): classify agent execution failures by error type instead of hardcoding validation
* fix(worker): cap auth-failure detail at 250 chars to match shannon-oss
* style(worker): apply biome formatting
* refactor(worker): remove per-session task delegation cap from task tool
* style(cli): collapse usage hint now that the beta tag is gone
* chore: mark the pi harness migration as a breaking change
BREAKING CHANGE: Google Vertex AI is no longer a supported provider. The
CLAUDE_CODE_USE_VERTEX, ANTHROPIC_VERTEX_PROJECT, CLOUD_ML_REGION, and
GOOGLE_APPLICATION_CREDENTIALS environment variables, along with the
use_vertex, vertex_project, and cloud_ml_region config.toml keys, are
removed. Vertex users must switch to Anthropic, AWS Bedrock, or a custom
Anthropic-compatible base URL.
The CLAUDE_CODE_MAX_OUTPUT_TOKENS environment variable and the
max_output_tokens config.toml key are also removed.
* feat: surface report at run root and nest run internals under .shannon
* feat: use plain-language wording in user-facing terminal messages
* feat(cli): guide users to watch scan progress and surface report path on start
* docs: sync run-folder layout and CLI wording across docs and comments
* feat(cli): add version command reporting package version or git SHA
* feat(cli): detect TTY for interactive prompts, color, and progress output
* docs: document --yes flag, version command, and tty module
* fix(cli): FORCE_COLOR precedence and plain uninstall --yes output
* fix(cli): respect empty NO_COLOR
* fix(cli): let NO_COLOR take precedence over FORCE_COLOR
* docs: mark claude-code-router integration as removed
* feat: add ReportOutputProvider for consumer-extended report artifacts
* fix: thread deliverablesSubdir through report assembly
* fix: produce structured report JSON on resume path
* fix: fail loud on structured report output provider errors
* feat: extend checkpoint provider and container DI for consumer-specific backends
* fix: pre-create .shannon overlay mount points on all platforms
* chore: drop claude-code-router mode
* fix: drop 'resets' keyword from spending-cap text patterns
* feat: extract pipeline core for library consumption
* fix: chmod workspace directory for container write access
* fix: resolve playwright output dir relative to deliverables parent
* feat: add multi-provider LLM support via ProviderConfig
* fix: resolve model overrides via options.model, remove unused model env passthrough
* fix: use ANTHROPIC_AUTH_TOKEN for custom base URL and router auth
* fix: skip env-based credential validation when providerConfig is present
* fix: support large UID/GID values for AD/LDAP users in container
* feat: mount user repo as read-only with deliverables bind-mount overlay
* feat: add playground and .playwright-cli overlay mounts
* feat: add filesystem context to pipeline-testing prompts
* fix: use explicit REPO_PATH in filesystem prompt for clarity
* fix: update filesystem prompts with playground notes and absolute screenshot paths
* feat: namespace writable overlays under .shannon/ to avoid polluting host repo
* refactor: rename playground to scratchpad
* fix: redirect playwright-cli output to writable .shannon/ overlay
* fix: pre-create .shannon/ overlay mount points for Linux compatibility
* fix: exclude nested node_modules and dist from Docker build context
* fix: enforce LF line endings for shell scripts on Windows
* feat: integrate npx CLI, CI/CD, and ephemeral worker architecture
Bring in changes from shannon-npx: npx-distributable CLI package (cli/),
semantic-release CI/CD workflows, ephemeral per-scan worker containers,
TOML config support, setup wizard, and workspace management.
Preserves all shannon-only changes: security hardening (localhost-bound
ports, MCP env allowlist, path traversal guard), updated benchmarks
(XBEN 19/31/35/44), README assets, and prompt injection disclaimer.
Applies security hardening to cli/infra/compose.yml as well.
* refactor: migrate to Turborepo + pnpm + Biome monorepo
Restructure into apps/worker, apps/cli, packages/mcp-server with
Turborepo task orchestration, pnpm workspaces, Biome linting/formatting,
and tsdown CLI bundling.
Key changes:
- src/ -> apps/worker/src/, cli/ -> apps/cli/, mcp-server/ -> packages/mcp-server/
- prompts/ and configs/ moved into apps/worker/
- npm replaced with pnpm, package-lock.json replaced with pnpm-lock.yaml
- Dockerfile updated for pnpm-based builds
- CLI logs command rewritten with chokidar for cross-platform reliability
- Router health checking added for auto-detected router mode
- Centralized path resolution via apps/worker/src/paths.ts
* fix: resolve all biome warnings and formatting issues
- Remove unnecessary non-null assertions where values are guaranteed
- Replace array index access with .at() for safer element retrieval
- Use local variables to avoid repeated process.env lookups
- Replace any types with unknown in functional utilities
- Use nullish coalescing for TOTP hash byte access
- Auto-format security patches to match biome config
* fix: pin pnpm to 10.12.1 in Dockerfile for catalog support
* fix: handle Esc cancellation in Bedrock setup flow
Replace p.group() with individual prompts and per-field cancel checks,
matching the pattern used by all other provider setup flows.
* feat: add optional model customization to Anthropic setup
* fix: resolve Docker bind mount permission errors on Linux
Use entrypoint-based UID remapping instead of --user flag so the
container's pentest user matches the host UID/GID, keeping bind-mounted
volumes writable. Git config moved to --system level to survive remapping.
* fix: show resumed workflow ID in splash screen URL
When resuming a workflow, the Temporal Web UI link pointed to the old
(terminated) workflow ID. Now extracts "New Workflow ID" from the resume
header in workflow.log, falling back to the original ID for fresh scans.
* style: fix biome formatting in docker.ts
* fix: align TypeScript config types with JSON Schema
- SuccessCondition.type: use schema values (url_contains,
element_present, url_equals_exactly, text_contains) instead of
stale values (url, cookie, element, redirect)
- Authentication.login_flow: mark optional to match schema which
does not require it
* feat: mark GitHub release as latest during rollback
* fix: use native ARM64 runners for Docker multi-platform builds
Replace QEMU emulation with parallel native builds using a matrix
strategy (ubuntu-latest for amd64, ubuntu-24.04-arm for arm64).
Each platform pushes by digest, then a merge job creates the
multi-arch manifest list before signing with cosign.
* fix: resolve SessionMutex race condition with 3+ concurrent waiters
* fix: skip POSIX permission check on Windows
writeFileSync mode option is ignored on Windows, so config.toml
gets 0o666 and the guard rejects it.
* fix: resolve unsubstituted placeholders in report prompt
Remove unused {{GITHUB_URL}} placeholder and wire up {{AUTH_CONTEXT}}
with structured auth context (login type, username, URL, MFA status).
* fix: remove duplicate environment gate from merge-docker job
Move DOCKERHUB_USERNAME from vars to secrets so merge-docker can access
credentials without its own environment scope. This eliminates the
redundant double approval since build-docker already gates on
release-publish.
* fix: replace POSIX sleep binary with cross-platform async sleep
execFileSync('sleep') is unavailable on Windows. Use node:timers/promises
setTimeout instead, making ensureInfra async.
* fix: use session.json for workflow ID on resume instead of parsing workflow.log
On resume, workflow.log already exists with stale headers from the
previous run. The CLI poll found '====' immediately and extracted the
old workflow ID, producing a wrong Temporal Web UI URL.
Read the workflow ID from session.json instead — the worker writes
resume attempts there atomically. For fresh runs, poll until
originalWorkflowId appears. For resumes, poll until a new
resumeAttempts entry is appended.
* feat: add custom base URL support for Anthropic-compatible proxies
Support ANTHROPIC_BASE_URL + ANTHROPIC_AUTH_TOKEN to route SDK requests
through LiteLLM or any Anthropic-compatible proxy. Adds TUI wizard
option, TOML config mapping, credential validation, and preflight
endpoint reachability check via SDK query.
* fix: remove environment gates and add NPM_TOKEN to publish step
* feat: add beta release and rollback workflows with cosign signing
* fix: remove redundant checkout and pnpm steps from beta release workflow
* docs: normalize README commands to mode-neutral shorthand
Add a substitution note after Quick Start sections so all subsequent
examples use bare `shannon` instead of mixing `./shannon` and
`npx @keygraph/shannon`. Mode-specific commands (build, update,
uninstall) get inline annotations. Also fixes a broken command in the
Custom Base URL section.
* fix: remove redundant `update` command
Image is already auto-pulled by `ensureImage()` during `start` when the
pinned version tag is missing locally. Manual `update` was unnecessary.
* docs: add CLI package README stub
* docs: update README setup instructions for dual CLI modes
* docs: update announcement banner to npx availability
* feat: migrate from MCP tools to CLI based tools (#252)
* feat: migrate from MCP tools to CLI tools
* fix: restore browser action emoji formatters for CLI output
Adapt formatBrowserAction for playwright-cli commands, replacing the old
mcp__playwright__browser_* tool name matching removed during migration.
* fix: mount credential file to fixed container path for Vertex AI
GOOGLE_APPLICATION_CREDENTIALS was forwarded as-is to the container,
causing the relative host path to resolve against the repo mount
instead of the credentials mount. Now both local and npx modes mount
the resolved file to /app/credentials/google-sa-key.json and rewrite
the env var to match.
* feat: add git awareness and optional description field to config
* fix: drop redundant --ipc host flag from worker container
* fix: align announcement banner URL with main branch
* feat: add target URL reachability preflight check (#254)
* Moving asset benchmark graph image to this folder
* Move benchmark results to benchmark repo
Windows Defender flags exploit code in the pentest reports as false positives, forcing every Windows user to add a Defender exclusion just to clone Shannon.
* Updated README
* fix: case-insensitive grep for semantic-release version probe
* fix: harden supply chain security (#255)
* fix: patch smol-toml and tsdown vulnerabilities
Update smol-toml 1.6.0→1.6.1 (DoS via recursive comment parsing) and
tsdown 0.21.2→0.21.5 (picomatch ReDoS + method injection).
* fix: pin all unpinned dependency versions in Dockerfile
Pins subfinder v2.13.0, WhatWeb v0.6.3 (switched from git clone to
release tarball), schemathesis 4.13.0, addressable 2.8.9,
claude-code 2.1.84, and playwright-cli 0.1.1 for reproducible builds.
* fix: pin GitHub Actions to commit SHAs for supply chain security
* fix: pin GitHub Actions to commit SHAs in beta and rollback workflows