Files
shannon/apps/cli/README.md
T
george-keygraphandClaude Opus 5.5 5d961820b3 docs: name the editions Shannon, Pro, Enterprise and Community Program
Drop "Shannon Open Source" and "the Keygraph platform" as product names.
The open-source project is Shannon (Shannon OSS where a contrast helps),
and the commercial editions are Keygraph Pro and Keygraph Enterprise, plus
the Community Program. The one retired-names line now maps Shannon Lite to
Shannon and Shannon Pro to Keygraph Pro. Also covers the npm README, the
coverage and safety docs, llms.txt and the regenerated llms-full.txt.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-07 10:32:40 -07:00

3.4 KiB

Shannon, AI Pentester for Web Apps and APIs, by Keygraph

Shannon is an autonomous, AI pentester for web applications and APIs.

It analyzes your source code, identifies attack paths, and executes real exploits to prove vulnerabilities before they reach production.

This package is Shannon: the full open-source agent, run locally from your command line.


Join Discord      Visit Keygraph.io


Quick Start

Prerequisites

  • Docker: required for the worker container.
  • Node.js 18+: required for the recommended npx workflow.
  • AI provider credentials: Shannon runs on Anthropic, OpenAI, xAI, AWS Bedrock, and any other provider in the harness catalogue — each of which you can point at a proxy or LLM gateway through a custom base URL. You bring your own key, and Keygraph never proxies your model traffic. Shannon is provider-agnostic.
  • Cyber safeguards cleared with your provider: Anthropic and OpenAI apply real-time safeguards to cyber-security workloads, which can interrupt a scan mid-run. Complete their guidance for legitimate security testers before your first run.

Run Shannon

Warning: Shannon actively executes exploits. Run it only against applications and environments you own or have explicit written authorization to test. Do not run Shannon against production systems.

# Configure credentials with the interactive wizard.
npx @keygraph/shannon setup

# Run a pentest against a source-available target.
npx @keygraph/shannon start -u https://your-app.com -r /path/to/your-repo

Shannon pulls the worker image from Docker Hub, starts the required local infrastructure, mounts the target repository read-only inside an ephemeral worker container, and writes results to a local workspace.

Editions

Shannon is this package: the open-source pentester you run yourself, on demand, and complete in that lane. Keygraph Pro and Keygraph Enterprise are the commercial editions. They run an enhanced build of Shannon continuously and close the full AppSec lifecycle around it: code analysis, finding management, automated remediation, verification, and enterprise deployment. The Community Program offers Pro at no cost to organizations that qualify. See keygraph.io/pricing.

Documentation

Full README, guides, and usage documentation: github.com/KeygraphHQ/shannon

License

Shannon is licensed under the GNU Affero General Public License v3.0.

Commercial and enterprise licensing is available for organizations that need different license terms, commercial support, private redistribution, managed-service use, or broader deployment options, including Keygraph Pro and Enterprise.

For commercial licensing, contact shannon@keygraph.io.

Built by Keygraph