Files
shannon/apps/cli
ajmallesh 98c66e051d feat(config)!: replace vuln_classes with agentic_sast
Wire Agentic SAST and reconciliation into the main pipeline, persist their durable state, and add the Miscellaneous finding and exploitation lane.

Make scan completion, cancellation, partial outcomes, resume identity, and report recovery use the integrated final workflow contract. Introduce the atomic finalization, ordering, renumbering, compaction, and output services that workflow calls. Keep completed Miscellaneous work and report drafts idempotent across resume, preserve public main's default-on exploit SARIF behavior, and describe stage-fallback candidates without claiming they were exported.

BREAKING CHANGE: `vuln_classes` has been removed. Configs containing it now fail validation, and all five core pentest classes run on every scan.

Workspaces created by Shannon 2.x cannot be resumed. Finish or discard in-flight scans before upgrading, then start a new workspace name.
2026-08-26 19:55:03 -07:00
..

Shannon — AI Pentester for Web Applications and APIs

Shannon — AI Pentester by Keygraph

Shannon is an autonomous, white-box AI pentester for web applications and APIs.
It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities before they reach production.


Announcements Join Discord Visit Keygraph.io Follow Us on Linkedin


Full README and usage guide
https://github.com/KeygraphHQ/shannon#readme