Keygraph · Shannon: Open-Source White-Box AI Pentester for Web Apps and APIs
Shannon is Keygraph's open-source (AGPL-3.0) AI pentester for web applications and APIs that combines source-code analysis with testing of the running app, and follows a "no exploit, no report" rule so only proven issues reach the report. It suits engineering teams that can run it against a staging environment they are authorized to test, locally or in GitHub Actions and GitLab CI.
Best for
Engineering teams with access to both the source code and a staging copy of their web app or API who want open-source, evidence-backed security testing in CI
Not ideal for
Teams that can only test production, anyone without written authorization for the target, and organizations that need dependency scanning, secrets scanning, or business-logic testing without Keygraph's paid platform
Who it's for
Developers and AppSec engineers testing web applications and APIs they own, with source-code access and a staging environment
Shannon's strict rule of reporting only what it can demonstrate makes its output easier to act on than most automated scanners, and using source code to guide testing is a sensible fit for teams testing their own apps. The open-source edition is deliberately focused on a set of common web vulnerability classes, so it complements rather than replaces dependency scanning, secrets scanning, and human pentests. Plan for a disposable staging environment, model costs, and multi-hour runs.
Who should use it
Teams that own a web app or API, can stand up a staging copy, and want free, evidence-backed AI security testing locally or in CI.
Who should skip it
Teams that can only test production, anyone without written authorization, and organizations that need broad coverage such as dependency and secrets scanning from one free tool.
Shannon Open Source
Free
Community Program
Free while you qualify
Pro
$50/developer
Billed monthly
Enterprise
Custom
Note: Open-source users pay their own model costs. Pro seats count active developers over a trailing 90-day window. Commercial licensing of Shannon is available from Keygraph.
Available models
Release-gate testing in CI
The GitHub Action and GitLab component can fail a pipeline only on confirmed findings, which avoids blocking releases on unproven alerts.
Evidence-backed findings for developers
Because unproven candidates are dropped, developers receive a shorter list of issues with supporting evidence.
Cost-aware model selection
Bring-your-own models let teams run cheaper models for routine scans and stronger ones for deeper reviews.
Shannon vs. Strix
Strix accepts more target types, including URLs without code and API specs, and has its own cloud platform with PR reviews and autofix; Shannon is a white-box tester that requires source code plus a running app and applies a strict proven-findings-only rule.
Shannon vs. CodeMender
CodeMender is a managed Google Cloud agent focused on finding and patching vulnerabilities in source code; Shannon tests a running web app and reports demonstrated issues, and it is free and self-hosted.
What is Shannon?
Shannon is an open-source AI pentester from Keygraph for web applications and APIs. It analyzes your source code, tests the running app, and includes only vulnerabilities it can demonstrate in its report.
Is Shannon free?
Yes. Shannon Open Source is free under AGPL-3.0 with no seat or usage caps; you pay your model provider. Keygraph's hosted platform starts at $50 per developer per month (Pro), with a free Community Program for qualifying nonprofits and early-stage startups, and custom Enterprise pricing.
Which models does Shannon support?
Anthropic, OpenAI, xAI, and AWS Bedrock are built in, and other providers work through the Pi harness catalogue, custom base URLs, or gateways such as LiteLLM. Local models can run through Ollama, vLLM, or LM Studio. If no model is set, Shannon defaults to Claude Sonnet 4.6.
Can I run Shannon on production?
Keygraph says not to. Shannon can create users and change data, so it should run only against sandboxed or staging environments with disposable data and explicit written authorization.
Does Shannon work in CI?
Yes. Keygraph publishes an official GitHub Action and a GitLab CI/CD component that keep reports as artifacts, can fail the pipeline on confirmed findings above a severity threshold, and can upload SARIF to GitHub code scanning.

Strix (OmniSecure, Inc.)
Engineering and AppSec teams that want open-source, AI-driven pentesting of their own apps and APIs in the CLI or CI, with an option to move to a managed platform
Freemium
Security and platform teams already on Google Cloud who want an agent that verifies vulnerabilities and proposes tested patches, and who can join a preview program
PaidShannon is a white-box security tester: you give it both a repository and the URL of a running copy of the app, and it uses the code to decide where the app is likely to be vulnerable before testing those paths against the live instance. Version 3.0 (September 2026) added an agentic security code-analysis stage that maps architecture, trust boundaries, and data flows, then merges and deduplicates candidates before validation. Anything Shannon cannot demonstrate is dropped, which keeps reports short. It runs with `npx @keygraph/shannon`, pulls a worker container from Docker Hub, and mounts the repository read-only. Models are bring-your-own: Anthropic, OpenAI, xAI, and AWS Bedrock are built in, other providers work through the Pi harness catalogue or a gateway, and local models run through OpenAI-compatible servers. Reports come out as PDF, Markdown, JSON, and SARIF, and official GitHub Actions and GitLab components can fail a pipeline on confirmed findings. The open-source edition focuses on injection, XSS, SSRF, and broken authentication and authorization; dependency scanning, secrets scanning, business-logic testing, and verified fix PRs are part of Keygraph's paid platform. The tradeoffs are real: it changes application state, so Keygraph says to use only sandboxed or staging environments with written authorization; a full run takes roughly one to 1.5 hours plus model costs; model providers' cyber safeguards can stop a scan unless you have cleared them; and reports still need human review.
v3.3.0 fetches the latest model catalogue over the network at the start of each scan, following v3.2.0 (custom model configs and clearer startup errors) and v3.1.0 (per-provider custom base URLs).
Shannon 3.0 introduced a multi-stage security code-analysis pipeline, a rebuilt CLI, resumable workspaces, official GitHub Actions and GitLab CI/CD integrations, PDF and Markdown reports, native SARIF 2.1.0, and cross-pipeline deduplication.
Are you the founder? Claim this listing →