# Run autonomous white-box pentests against web apps and APIs with Shannon

> Analyze a web app's source code, execute real exploit attempts against the running target, and return proof-backed findings before release.

- Skill: `agentskillexchange/run-autonomous-white-box-pentests-against-web-apps-and-apis-` (Agent Skill)
- Install (CLI): `npx skillmds@latest add agentskillexchange/run-autonomous-white-box-pentests-against-web-apps-and-apis-`
- Raw SKILL.md: https://api.skillmd.com/api/skills/agentskillexchange/run-autonomous-white-box-pentests-against-web-apps-and-apis-/raw
- Safety review: pending (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Security
- Author: agentskillexchange (https://skillmd.com/u/agentskillexchange)
- Updated: 2026-09-08
- Page: https://skillmd.com/skills/agentskillexchange/run-autonomous-white-box-pentests-against-web-apps-and-apis-

---


# Run autonomous white-box pentests against web apps and APIs with Shannon

Analyze a web app's source code, execute real exploit attempts against the running target, and return proof-backed findings before release.

## Prerequisites

Node.js 18+, Docker, target web app URL, local source repository, model/API credentials supported by Shannon

## Installation

Requirements and caveats from upstream:
- **Data Flow Analysis (SAST)**: Identifies sources (user input, API requests) and sinks (SQL queries, command execution), then traces paths between them. At each node, an LLM evaluates whether the specific sanitization...
- | **Analysis Engine** | Code review prompting | CPG-based data flow with LLM reasoning at every node |
- [Prerequisites](#prerequisites)

Basic usage or getting-started notes:
- Shannon closes that gap by providing on-demand, automated penetration testing that can run against every build or release.
- **Parallel Processing**: Vulnerability analysis and exploitation phases run concurrently across all attack categories.
- [Setup & Usage Instructions](#setup--usage-instructions)

- Source: https://github.com/KeygraphHQ/shannon
- Extracted from upstream docs: https://raw.githubusercontent.com/KeygraphHQ/shannon/HEAD/README.md

## Documentation

- https://keygraph.io/

## Source

- [Agent Skill Exchange](https://agentskillexchange.com/skills/run-autonomous-white-box-pentests-against-web-apps-and-apis-with-shannon/)

