Run autonomous white-box pentests against web apps and APIs with Shannon
Analyze a web app's source code, execute real exploit attempts against the running target, and return proof-backed findings before release.
Prerequisites
Node.js 18+, Docker, target web app URL, local source repository, model/API credentials supported by Shannon
Installation
Choose whichever fits your setup:
- Copy this skill folder into your local skills directory.
- Clone the repo and symlink or copy the skill into your agent workspace.
- Add the repo as a git submodule if you manage shared skills centrally.
- Install it through your internal provisioning or packaging workflow.
- Download the folder directly from GitHub and place it in your skills collection.
Install command or upstream instructions:
Run npx @keygraph/shannon setup, then start a scan with npx @keygraph/shannon start -u https://your-app.com -r /path/to/your-repo. Docker is required because the npx workflow pulls and runs the Shannon worker image.