* feat(worker): migrate agent runtime from Claude Agent SDK to pi harness
* feat: remove Google Vertex AI provider support
* fix(worker): route Bedrock and custom-base-URL providers from env
* feat(prompts): instruct agents to call submit_exploitation_queue and submit_auth_result
* fix(worker): count sub-agent cost and surface compaction failures
* refactor(worker): rename claude-executor to pi-executor
* feat(worker): pi-event-driven output formatting
* fix(worker): gate adaptive thinking to Opus models, drop CLAUDE_THINKING_LEVEL
* fix(worker): restore minLength/minItems on vuln-collector schemas
* feat(worker): give task sub-agent write+bash, align tool descriptions
* feat(worker): add glob custom tool and route code_path globs to it
* refactor(prompts): use pi tool names (task, todo_write, read, bash, glob)
* refactor(prompts): drop stale MCP terminology for collector tools
* refactor(prompts): drop collector server names from deliverable instructions
* fix(worker): restore minLength/minItems on pre-recon and exploit collector schemas
* feat(worker): load playwright-cli skill via pi resource loader
* refactor(cli): remove CLAUDE_CODE_MAX_OUTPUT_TOKENS config
* build: drop @anthropic-ai/claude-code from worker image
* docs: remove vertex references from llms context
* docs(worker): update stale sdk comments
* refactor(worker): unify provider precedence between preflight and executor
* feat(worker): enforce bounded bash timeouts via pi extension
* ci: bump the beta release line to 2.0.0 (#356)
* fix(cli): pin npx command hints to beta tag
* fix: render agent deliverables before the success commit so resume preserves them (#377)
* feat(cli): restructure run folder and improve terminal UX (#383)
* feat: surface report at run root and nest run internals under .shannon
* feat: use plain-language wording in user-facing terminal messages
* feat(cli): guide users to watch scan progress and surface report path on start
* docs: sync run-folder layout and CLI wording across docs and comments
* feat(cli): add version command reporting package version or git SHA
* feat(cli): detect TTY for interactive prompts, color, and progress output
* docs: document --yes flag, version command, and tty module
* fix(cli): FORCE_COLOR precedence and plain uninstall --yes output
* fix(cli): respect empty NO_COLOR
* fix(cli): let NO_COLOR take precedence over FORCE_COLOR
* docs: mark claude-code-router integration as removed
* refactor(worker): converge shared core with shannon-oss (#388)
* fix(worker): port keygraph shared-core correctness fixes
* refactor(worker): adopt collectors/ and ai/pi/ layout; add task budget cap and cancellation
* refactor(worker): drop inconsistent Collector "Server" suffix
* refactor(worker): drop unused providerConfig/apiKey seams, resolve credentials from env only
* refactor(worker): port oss code_path pattern expansion + external_directory allow
* fix(worker): preserve dotfile paths in code_path avoid patterns (.env no longer stripped to env)
* feat(worker): render Unprocessed Vulnerabilities section in exploit deliverable (align with oss)
* feat(worker): request set_blind_spots for all vuln classes (align auth/ssrf with production prompts)
* refactor(worker): adopt unified permissionSystem* naming and helper layout
* refactor(worker): inline blind_spots into vuln deliverable section array
* chore(worker): drop unused zod dependency (tree is typebox-native)
* fix(worker): normalize base32 TOTP secret to accept padding and whitespace
* refactor(worker): adopt shared toolResult helper and flatSchema naming in collectors
* refactor(worker): use undefined over null in queue-schema builders
* docs(worker): converge renderer/collector doc comments to current pi terminology
* refactor(worker): adopt schema.ts cleanInput/stringEnum helpers in collectors
* feat(worker): converge exploit-collector/renderer with vendored; capture and render overview for blocked findings
* refactor(worker): converge session-tools/pipeline/exploitation-checker with vendored
* refactor(worker): converge task-tool usage reporting with vendored onUsage callback
* refactor(worker): converge structured output onto a submitTool executor channel
* docs(worker): expand exploit-renderer docstring to match shannon-oss
* docs(worker): adopt richer vuln-renderer docstring from shannon-oss
* docs(worker): neutralize billing-detection wording for shannon-oss parity
* fix(worker): verify checkpoint hash in the deliverables clone being reset
* fix(worker): fail fast on malformed exploitation queue JSON
* fix(worker): honor retryable flag when classifying exploitation-queue check failures
* fix(worker): fail fast on corrupted session.json in run-scope validation
* feat(worker): propagate Temporal cancellation signal into agent and auth pi sessions
* fix(worker): mark exploit agent complete when exploitation is skipped so resume skips it
* prompts: drop scan description from executive report prompt
* refactor(worker): add createGenericSubmitTool for raw JSON-schema submit tools
* refactor(worker): gate playwright-cli skill to browser agents via skillsOverride (adopt shannon-oss mechanism)
* docs(worker): correct formatLogTime comment to UTC to match toISOString
* refactor(worker): converge queue-schemas with shannon-oss (guarded count, decl order)
* refactor(worker): converge task-tool with shannon-oss (byte-identical; modelRegistry optional)
* fix(worker): use replaceLiteral for all prompt value insertions to prevent $-mangling
* fix(worker): classify agent execution failures by error type instead of hardcoding validation
* fix(worker): cap auth-failure detail at 250 chars to match shannon-oss
* style(worker): apply biome formatting
* refactor(worker): remove per-session task delegation cap from task tool
* style(cli): collapse usage hint now that the beta tag is gone
* chore: mark the pi harness migration as a breaking change
BREAKING CHANGE: Google Vertex AI is no longer a supported provider. The
CLAUDE_CODE_USE_VERTEX, ANTHROPIC_VERTEX_PROJECT, CLOUD_ML_REGION, and
GOOGLE_APPLICATION_CREDENTIALS environment variables, along with the
use_vertex, vertex_project, and cloud_ml_region config.toml keys, are
removed. Vertex users must switch to Anthropic, AWS Bedrock, or a custom
Anthropic-compatible base URL.
The CLAUDE_CODE_MAX_OUTPUT_TOKENS environment variable and the
max_output_tokens config.toml key are also removed.
* feat: surface report at run root and nest run internals under .shannon
* feat: use plain-language wording in user-facing terminal messages
* feat(cli): guide users to watch scan progress and surface report path on start
* docs: sync run-folder layout and CLI wording across docs and comments
* feat(cli): add version command reporting package version or git SHA
* feat(cli): detect TTY for interactive prompts, color, and progress output
* docs: document --yes flag, version command, and tty module
* fix(cli): FORCE_COLOR precedence and plain uninstall --yes output
* fix(cli): respect empty NO_COLOR
* fix(cli): let NO_COLOR take precedence over FORCE_COLOR
* docs: mark claude-code-router integration as removed
Apply the same convention from the README pass across the rest of the
repo content so the company and the product are never conflated:
company -> "Keygraph", commercial product -> "the Keygraph platform".
- docs/keygraph-platform.md: retitle "# Keygraph" -> "# Keygraph Platform"
and refer to the product as "the Keygraph platform" throughout (the
page is the platform overview, not a company page).
- docs/coverage-roadmap.md, docs/safety.md: product references updated;
the "Keygraph is not responsible for misuse" line stays as the company.
- llms.txt / llms-full.txt: kept in sync with the README and docs they
mirror, so the combined-context files don't reintroduce the conflation.
No filenames changed.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Replace the README with the marketing-reviewed version and bring the
project onto one consistent naming scheme:
- "Shannon Lite" -> "Shannon" (the open-source CLI is just Shannon)
- "Shannon Pro" -> "Keygraph" (the commercial platform)
- Rename docs/shannon-pro.md -> docs/keygraph-platform.md and fix the
internal link, matching the README's link target.
- Regenerate llms.txt and llms-full.txt from the updated README and docs.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>