* feat(cli): support any Pi provider via generic SHANNON_AI_API_KEY
* docs(cli): point users to pi.dev/models for provider and model ids
* docs: document generic provider path and pi.dev catalogue
* feat(worker): record token, cache, and turn usage per agent
* feat: replace model tiers with a single SHANNON_AI_MODEL across five providers
* feat(cli): rebuild the setup wizard for provider and model selection
* docs: document single-model selection and supported providers
* feat(worker): use chat completions for OpenAI behind a custom base URL
* feat: add SHANNON_AI_OPENAI_FORMAT to pick the wire API for OpenAI gateways
* refactor(cli): drop endpoint path hints from the gateway format picker
* feat(worker): enable pi in-session provider retry with retry-after backoff
* refactor(worker): hand provider error classification to pi and drop the Anthropic ladders
* refactor: remove the subscription retry preset and pipeline config section
* fix(worker): validate Bedrock credentials with the same live probe as other providers
* feat(worker): render the report from structured findings instead of agent-written markdown
* fix(worker): dispose the credential probe session on every path
* fix(worker): refuse to replace the assembled report with an empty one
* refactor(worker): catch post-processing throws across the whole finalization block
* revert(worker): drop the report zero-findings guard
* docs(worker): correct the retry split and Bedrock credential claims
* docs: regenerate llms-full.txt from current sources
* feat(cli): build and run the npx flow from a clone
* refactor(cli): flatten the setup summary output
* feat(cli): reject runs with more than one provider configured
* fix(worker): say a rejected bash call never ran
* chore(cli): drop grok-4.3 and gpt-5.6-luna from the setup suggestions
* feat(worker): capture structured finding locations for SARIF output
* fix(worker): enumerate queue confidence so the report inherits it verbatim
* feat(worker): give the reporting phase a mode-specific output schema
* feat(worker): emit a SARIF 2.1.0 log for exploitative runs
* fix(worker): correct SARIF locations and defer fingerprinting to the upload action
* fix(worker): drop the confidence suffix from the analysis-mode summary list
* feat(worker): give exploit findings a dedicated code location field
* feat(worker): carry structured code locations from the vuln queue to the report
* fix(worker): join code locations from the vuln queue instead of re-asking agents
* fix(worker): spell out the finding_id to category mapping in the tool schema
* feat: drop Google/Gemini as a supported AI provider
* fix(worker): stop asking the report agent for code locations
* docs: correct the provider list and drop the removed rate-limit settings
* docs: add provider cyber safeguards and suggested models per provider
* docs: document the SARIF output and the report rating thresholds
* feat(worker): migrate agent runtime from Claude Agent SDK to pi harness
* feat: remove Google Vertex AI provider support
* fix(worker): route Bedrock and custom-base-URL providers from env
* feat(prompts): instruct agents to call submit_exploitation_queue and submit_auth_result
* fix(worker): count sub-agent cost and surface compaction failures
* refactor(worker): rename claude-executor to pi-executor
* feat(worker): pi-event-driven output formatting
* fix(worker): gate adaptive thinking to Opus models, drop CLAUDE_THINKING_LEVEL
* fix(worker): restore minLength/minItems on vuln-collector schemas
* feat(worker): give task sub-agent write+bash, align tool descriptions
* feat(worker): add glob custom tool and route code_path globs to it
* refactor(prompts): use pi tool names (task, todo_write, read, bash, glob)
* refactor(prompts): drop stale MCP terminology for collector tools
* refactor(prompts): drop collector server names from deliverable instructions
* fix(worker): restore minLength/minItems on pre-recon and exploit collector schemas
* feat(worker): load playwright-cli skill via pi resource loader
* refactor(cli): remove CLAUDE_CODE_MAX_OUTPUT_TOKENS config
* build: drop @anthropic-ai/claude-code from worker image
* docs: remove vertex references from llms context
* docs(worker): update stale sdk comments
* refactor(worker): unify provider precedence between preflight and executor
* feat(worker): enforce bounded bash timeouts via pi extension
* ci: bump the beta release line to 2.0.0 (#356)
* fix(cli): pin npx command hints to beta tag
* fix: render agent deliverables before the success commit so resume preserves them (#377)
* feat(cli): restructure run folder and improve terminal UX (#383)
* feat: surface report at run root and nest run internals under .shannon
* feat: use plain-language wording in user-facing terminal messages
* feat(cli): guide users to watch scan progress and surface report path on start
* docs: sync run-folder layout and CLI wording across docs and comments
* feat(cli): add version command reporting package version or git SHA
* feat(cli): detect TTY for interactive prompts, color, and progress output
* docs: document --yes flag, version command, and tty module
* fix(cli): FORCE_COLOR precedence and plain uninstall --yes output
* fix(cli): respect empty NO_COLOR
* fix(cli): let NO_COLOR take precedence over FORCE_COLOR
* docs: mark claude-code-router integration as removed
* refactor(worker): converge shared core with shannon-oss (#388)
* fix(worker): port keygraph shared-core correctness fixes
* refactor(worker): adopt collectors/ and ai/pi/ layout; add task budget cap and cancellation
* refactor(worker): drop inconsistent Collector "Server" suffix
* refactor(worker): drop unused providerConfig/apiKey seams, resolve credentials from env only
* refactor(worker): port oss code_path pattern expansion + external_directory allow
* fix(worker): preserve dotfile paths in code_path avoid patterns (.env no longer stripped to env)
* feat(worker): render Unprocessed Vulnerabilities section in exploit deliverable (align with oss)
* feat(worker): request set_blind_spots for all vuln classes (align auth/ssrf with production prompts)
* refactor(worker): adopt unified permissionSystem* naming and helper layout
* refactor(worker): inline blind_spots into vuln deliverable section array
* chore(worker): drop unused zod dependency (tree is typebox-native)
* fix(worker): normalize base32 TOTP secret to accept padding and whitespace
* refactor(worker): adopt shared toolResult helper and flatSchema naming in collectors
* refactor(worker): use undefined over null in queue-schema builders
* docs(worker): converge renderer/collector doc comments to current pi terminology
* refactor(worker): adopt schema.ts cleanInput/stringEnum helpers in collectors
* feat(worker): converge exploit-collector/renderer with vendored; capture and render overview for blocked findings
* refactor(worker): converge session-tools/pipeline/exploitation-checker with vendored
* refactor(worker): converge task-tool usage reporting with vendored onUsage callback
* refactor(worker): converge structured output onto a submitTool executor channel
* docs(worker): expand exploit-renderer docstring to match shannon-oss
* docs(worker): adopt richer vuln-renderer docstring from shannon-oss
* docs(worker): neutralize billing-detection wording for shannon-oss parity
* fix(worker): verify checkpoint hash in the deliverables clone being reset
* fix(worker): fail fast on malformed exploitation queue JSON
* fix(worker): honor retryable flag when classifying exploitation-queue check failures
* fix(worker): fail fast on corrupted session.json in run-scope validation
* feat(worker): propagate Temporal cancellation signal into agent and auth pi sessions
* fix(worker): mark exploit agent complete when exploitation is skipped so resume skips it
* prompts: drop scan description from executive report prompt
* refactor(worker): add createGenericSubmitTool for raw JSON-schema submit tools
* refactor(worker): gate playwright-cli skill to browser agents via skillsOverride (adopt shannon-oss mechanism)
* docs(worker): correct formatLogTime comment to UTC to match toISOString
* refactor(worker): converge queue-schemas with shannon-oss (guarded count, decl order)
* refactor(worker): converge task-tool with shannon-oss (byte-identical; modelRegistry optional)
* fix(worker): use replaceLiteral for all prompt value insertions to prevent $-mangling
* fix(worker): classify agent execution failures by error type instead of hardcoding validation
* fix(worker): cap auth-failure detail at 250 chars to match shannon-oss
* style(worker): apply biome formatting
* refactor(worker): remove per-session task delegation cap from task tool
* style(cli): collapse usage hint now that the beta tag is gone
* chore: mark the pi harness migration as a breaking change
BREAKING CHANGE: Google Vertex AI is no longer a supported provider. The
CLAUDE_CODE_USE_VERTEX, ANTHROPIC_VERTEX_PROJECT, CLOUD_ML_REGION, and
GOOGLE_APPLICATION_CREDENTIALS environment variables, along with the
use_vertex, vertex_project, and cloud_ml_region config.toml keys, are
removed. Vertex users must switch to Anthropic, AWS Bedrock, or a custom
Anthropic-compatible base URL.
The CLAUDE_CODE_MAX_OUTPUT_TOKENS environment variable and the
max_output_tokens config.toml key are also removed.
* feat: surface report at run root and nest run internals under .shannon
* feat: use plain-language wording in user-facing terminal messages
* feat(cli): guide users to watch scan progress and surface report path on start
* docs: sync run-folder layout and CLI wording across docs and comments
* feat(cli): add version command reporting package version or git SHA
* feat(cli): detect TTY for interactive prompts, color, and progress output
* docs: document --yes flag, version command, and tty module
* fix(cli): FORCE_COLOR precedence and plain uninstall --yes output
* fix(cli): respect empty NO_COLOR
* fix(cli): let NO_COLOR take precedence over FORCE_COLOR
* docs: mark claude-code-router integration as removed
Apply the same convention from the README pass across the rest of the
repo content so the company and the product are never conflated:
company -> "Keygraph", commercial product -> "the Keygraph platform".
- docs/keygraph-platform.md: retitle "# Keygraph" -> "# Keygraph Platform"
and refer to the product as "the Keygraph platform" throughout (the
page is the platform overview, not a company page).
- docs/coverage-roadmap.md, docs/safety.md: product references updated;
the "Keygraph is not responsible for misuse" line stays as the company.
- llms.txt / llms-full.txt: kept in sync with the README and docs they
mirror, so the combined-context files don't reintroduce the conflation.
No filenames changed.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Replace the README with the marketing-reviewed version and bring the
project onto one consistent naming scheme:
- "Shannon Lite" -> "Shannon" (the open-source CLI is just Shannon)
- "Shannon Pro" -> "Keygraph" (the commercial platform)
- Rename docs/shannon-pro.md -> docs/keygraph-platform.md and fix the
internal link, matching the README's link target.
- Regenerate llms.txt and llms-full.txt from the updated README and docs.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>