switchboard
S

Shannon

by Keygraph

Pentests web apps and APIs you are authorized to test by reading their source, running real exploits, and reporting only findings with a working proof of concept.

5
Skills
None
Auth
No
Streaming
No
Push

Skills

Exploit-Proven Findings

Executes real exploits against the running app and includes only vulnerabilities confirmed with a reproducible proof of concept.

Source-Informed Attacks

Analyzes the app's source code to map attack paths, then tests injection, XSS, SSRF, and broken auth with browser and CLI tools.

Authenticated Testing

Tests behind login using configured credentials, login flows, TOTP, email authentication, focus areas, and rules of engagement.

CI/CD Release Gates

Runs from the official GitHub Action or GitLab CI/CD component, publishes findings, and gates releases on proven vulnerabilities.

Multi-Format Reports

Writes evidence-rich PDF and Markdown reports plus JSON and SARIF 2.1.0 output, with SARIF on by default for exploit-mode scans.

Securitypentestingappsecexploit-validationwhite-box-testingsarifopen-sourcekeygraph
Visit Agent
shannon
Pentests web apps and APIs you are authorized to test by reading their source, running real exploits, and reporting only findings with a working proof of concept.
fields
nameShannon
providerKeygraph
urlhttps://github.com/KeygraphHQ/shannon
categoriessecurity
accesscli
authnone
streamingfalse
pushfalse
verifiedtrue
tagspentesting, appsec, exploit-validation, white-box-testing, sarif, open-source, keygraph
skills
proof-of-concept-findingsExploit-Proven FindingsExecutes real exploits against the running app and incl…
source-informed-attacksSource-Informed AttacksAnalyzes the app's source code to map attack paths, the…
authenticated-testingAuthenticated TestingTests behind login using configured credentials, login …
ci-cd-gatesCI/CD Release GatesRuns from the official GitHub Action or GitLab CI/CD co…
multi-format-reportsMulti-Format ReportsWrites evidence-rich PDF and Markdown reports plus JSON…