Shannon
by Keygraph
Pentests web apps and APIs you are authorized to test by reading their source, running real exploits, and reporting only findings with a working proof of concept.
Skills
Exploit-Proven Findings
Executes real exploits against the running app and includes only vulnerabilities confirmed with a reproducible proof of concept.
Source-Informed Attacks
Analyzes the app's source code to map attack paths, then tests injection, XSS, SSRF, and broken auth with browser and CLI tools.
Authenticated Testing
Tests behind login using configured credentials, login flows, TOTP, email authentication, focus areas, and rules of engagement.
CI/CD Release Gates
Runs from the official GitHub Action or GitLab CI/CD component, publishes findings, and gates releases on proven vulnerabilities.
Multi-Format Reports
Writes evidence-rich PDF and Markdown reports plus JSON and SARIF 2.1.0 output, with SARIF on by default for exploit-mode scans.
Related Agents
AgentOps for Apify Builders Bundle
Apify actor bundle for agent builders: normalize run traces for QA, control costs, and guard tool calls with a firewall…
OpenSandbox
Runs AI-agent workloads in isolated Docker or Kubernetes sandboxes, exposing sandbox lifecycle, command, filesystem, an…
CubeSandbox
Runs self-hosted, KVM-isolated sandboxes for agent code execution behind an E2B-compatible API, with snapshots, cloning…
IBM ContextForge
Runs a self-hosted gateway and registry that federates MCP servers, A2A agents, and REST/gRPC APIs behind one endpoint…