LaunchedEditorial Listing

Shannon

Keygraph · Shannon: Open-Source White-Box AI Pentester for Web Apps and APIs

Open Shannon

Shannon is Keygraph's open-source (AGPL-3.0) AI pentester for web applications and APIs that combines source-code analysis with testing of the running app, and follows a "no exploit, no report" rule so only proven issues reach the report. It suits engineering teams that can run it against a staging environment they are authorized to test, locally or in GitHub Actions and GitLab CI.

PricingFreemium
Setupmedium
Runs onSelf-hosted
Open sourceYes
DocsYes
CategorySecurity
Penetration TestingApplication SecurityWhite-Box TestingOpen SourceCI/CDSARIFBYOK

Best for

Engineering teams with access to both the source code and a staging copy of their web app or API who want open-source, evidence-backed security testing in CI

Not ideal for

Teams that can only test production, anyone without written authorization for the target, and organizations that need dependency scanning, secrets scanning, or business-logic testing without Keygraph's paid platform

Who it's for

Developers and AppSec engineers testing web applications and APIs they own, with source-code access and a staging environment

Capabilities

  • White-box testing that combines source-code analysis with checks against a running staging app
  • "No exploit, no report": only findings Shannon can demonstrate appear in the final report
  • Agentic security code analysis (v3.0) that maps architecture, trust boundaries, interfaces, and data flows
  • Finding reconciliation that merges and deduplicates candidates across pipelines
  • Authenticated testing with credentials, login flows, TOTP, and rules of engagement
  • Resumable workspaces and a CLI with live scan status
  • PDF, Markdown, JSON, and SARIF 2.1.0 reports
  • Official GitHub Action and GitLab CI/CD component with severity-based pipeline gating and SARIF upload to GitHub code scanning
  • Bring-your-own model: Anthropic, OpenAI, xAI, AWS Bedrock, Pi harness providers, gateways, and local OpenAI-compatible servers

Limitations

  • Not a passive scanner: it can create users and change data, so Keygraph says to run it only on sandboxed or staging environments with explicit written authorization
  • Needs both source code and a running instance of the app; it is not a black-box external scanner in the open-source edition
  • Coverage in the open-source edition centers on injection, XSS, SSRF, and broken authentication and authorization; dependency, secrets, configuration, and business-logic findings are out of scope
  • Requires Docker, Node.js 18+, and your own model provider key, and a full run takes roughly 1 to 1.5 hours plus model costs
  • Anthropic and OpenAI cyber safeguards can stop a scan partway unless you complete their security-tester verification
  • Results depend on model quality, and Keygraph says reports still require human review
  • External code contributions are not accepted; the AGPL-3.0 license may require a commercial license for some uses

Use cases

  • Testing a staging deployment of a web app with its source code before release
  • Running Shannon in GitHub Actions on release branches and failing the build on confirmed findings
  • Uploading SARIF results to GitHub code scanning for triage alongside other tools
  • Comparing results across model providers to balance cost and depth
  • Giving a small team without a dedicated pentester a first pass on common web vulnerability classes

Our take

Shannon's strict rule of reporting only what it can demonstrate makes its output easier to act on than most automated scanners, and using source code to guide testing is a sensible fit for teams testing their own apps. The open-source edition is deliberately focused on a set of common web vulnerability classes, so it complements rather than replaces dependency scanning, secrets scanning, and human pentests. Plan for a disposable staging environment, model costs, and multi-hour runs.

Who should use it

Teams that own a web app or API, can stand up a staging copy, and want free, evidence-backed AI security testing locally or in CI.

Who should skip it

Teams that can only test production, anyone without written authorization, and organizations that need broad coverage such as dependency and secrets scanning from one free tool.

Strengths

  • Free and open source, with no seat or usage caps
  • "No exploit, no report" keeps findings evidence-backed
  • Uses source code to focus testing, which suits teams that own the app
  • Official GitHub Actions and GitLab integrations with SARIF output
  • Flexible model choice, including local models

Weaknesses

  • Mutates application state, so it needs a disposable staging environment
  • Narrower vulnerability coverage in the open-source edition
  • Long runs and model costs per scan
  • Model providers' cyber safeguards can interrupt scans

Shannon pricing

Shannon Open Source

Free

  • AGPL-3.0
  • Runs locally or in CI
  • No seat or usage caps
  • Bring your own model

Community Program

Free while you qualify

  • Full Pro plan for U.S. 501(c)(3) nonprofits and pre-Series A startups with 20 or fewer active developers
  • Cloud-hosted only

Pro

$50/developer

Billed monthly

  • Cloud-hosted Keygraph platform
  • All modules included
  • Unlimited repos and scans
  • SSO, RBAC, audit logs, and Jira sync

Enterprise

Custom

  • Self-hosted or air-gapped deployment
  • Dedicated engineer
  • Custom SLA and DPA

Note: Open-source users pay their own model costs. Pro seats count active developers over a trailing 90-day window. Commercial licensing of Shannon is available from Keygraph.

Technical specs

Available models

Claude Sonnet 4.6 (default)Claude OpusOpenAI GPT modelsxAI GrokAWS BedrockPi harness providersLocal models via Ollama, vLLM, or LM Studio

Where Shannon excels

Release-gate testing in CI

The GitHub Action and GitLab component can fail a pipeline only on confirmed findings, which avoids blocking releases on unproven alerts.

Evidence-backed findings for developers

Because unproven candidates are dropped, developers receive a shorter list of issues with supporting evidence.

Cost-aware model selection

Bring-your-own models let teams run cheaper models for routine scans and stronger ones for deeper reviews.

Shannon vs. competitors

Shannon vs. Strix

Strix accepts more target types, including URLs without code and API specs, and has its own cloud platform with PR reviews and autofix; Shannon is a white-box tester that requires source code plus a running app and applies a strict proven-findings-only rule.

Shannon vs. CodeMender

CodeMender is a managed Google Cloud agent focused on finding and patching vulnerabilities in source code; Shannon tests a running web app and reports demonstrated issues, and it is free and self-hosted.

Frequently asked questions

What is Shannon?

Shannon is an open-source AI pentester from Keygraph for web applications and APIs. It analyzes your source code, tests the running app, and includes only vulnerabilities it can demonstrate in its report.

Is Shannon free?

Yes. Shannon Open Source is free under AGPL-3.0 with no seat or usage caps; you pay your model provider. Keygraph's hosted platform starts at $50 per developer per month (Pro), with a free Community Program for qualifying nonprofits and early-stage startups, and custom Enterprise pricing.

Which models does Shannon support?

Anthropic, OpenAI, xAI, and AWS Bedrock are built in, and other providers work through the Pi harness catalogue, custom base URLs, or gateways such as LiteLLM. Local models can run through Ollama, vLLM, or LM Studio. If no model is set, Shannon defaults to Claude Sonnet 4.6.

Can I run Shannon on production?

Keygraph says not to. Shannon can create users and change data, so it should run only against sandboxed or staging environments with disposable data and explicit written authorization.

Does Shannon work in CI?

Yes. Keygraph publishes an official GitHub Action and a GitLab CI/CD component that keep reports as artifacts, can fail the pipeline on confirmed findings above a severity threshold, and can upload SARIF to GitHub code scanning.

Integrations & fit

GitHub ActionsGitLab CI/CDGitHub code scanning (SARIF)DockerAnthropicOpenAIxAIAWS BedrockOpenRouterOllamavLLMLM Studio
Good fit forSolo / individual, Startup / small team, Enterprise
Pricing modelFreemium· Free tier available
See pricing on Shannon →

Alternatives to consider

About Shannon

Shannon is a white-box security tester: you give it both a repository and the URL of a running copy of the app, and it uses the code to decide where the app is likely to be vulnerable before testing those paths against the live instance. Version 3.0 (September 2026) added an agentic security code-analysis stage that maps architecture, trust boundaries, and data flows, then merges and deduplicates candidates before validation. Anything Shannon cannot demonstrate is dropped, which keeps reports short. It runs with `npx @keygraph/shannon`, pulls a worker container from Docker Hub, and mounts the repository read-only. Models are bring-your-own: Anthropic, OpenAI, xAI, and AWS Bedrock are built in, other providers work through the Pi harness catalogue or a gateway, and local models run through OpenAI-compatible servers. Reports come out as PDF, Markdown, JSON, and SARIF, and official GitHub Actions and GitLab components can fail a pipeline on confirmed findings. The open-source edition focuses on injection, XSS, SSRF, and broken authentication and authorization; dependency scanning, secrets scanning, business-logic testing, and verified fix PRs are part of Keygraph's paid platform. The tradeoffs are real: it changes application state, so Keygraph says to use only sandboxed or staging environments with written authorization; a full run takes roughly one to 1.5 hours plus model costs; model providers' cyber safeguards can stop a scan unless you have cleared them; and reports still need human review.

Updates from Shannon

New FeatureShannon v3.3 refreshes its model catalogue at scan start

v3.3.0 fetches the latest model catalogue over the network at the start of each scan, following v3.2.0 (custom model configs and clearer startup errors) and v3.1.0 (per-provider custom base URLs).

LaunchShannon 3.0 adds agentic security code analysis and CI integrations

Shannon 3.0 introduced a multi-stage security code-analysis pipeline, a rebuilt CLI, resumable workspaces, official GitHub Actions and GitLab CI/CD integrations, PDF and Markdown reports, native SARIF 2.1.0, and cross-pipeline deduplication.

Are you the founder? Claim this listing →