KeygraphHQ/shannon

Shannon is an AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove...

View on GitHub ↗Jump to charts ↓Open shareable report

Summary Information

Updated 52 minutes ago
Added to GitGenius on February 9th, 2026
Created on September 27th, 2025
Open Issues & Pull Requests: 30 (+0)
Number of forks: 5,430
Total Stargazers: 47,146 (+4)
Total Subscribers: 223 (+0)

Repository Insights (GitGenius)

Median issue/PR response: 9.8 hours
Mean response time: 5.5 days
90th percentile: 21.2 days
Tracked items: 127

How this project is maintained

Around half of the issues opened in the past year never receive a reply. Only 14% of issues opened in the past year have been closed. Three people close 84% of everything that gets resolved.

Charts & Analytics

Fetching additional details & charts...

Issue Activity (beta)

Open issues: 16
New in 7 days: 0
Closed in 7 days: 0
Avg open age: 1 days
Stale 30+ days: 13
Stale 90+ days: 2

Recent activity

Opened in 7 days: 0
Closed in 7 days: 0
Comments in 7 days: 0
Events in 7 days: 0

Top labels

No label distribution available yet.

Most active issues this week

No issue events were indexed in the last 7 days.

Detailed Description

Shannon is an AI pentester for web applications and APIs that analyzes source code, identifies attack vectors, and executes real exploits to prove vulnerabilities before they reach production.

Shannon addresses the security gap created by infrequent penetration testing cycles. It combines source-code analysis with live exploitation through browser automation and command-line tools to identify potential attack paths and execute working proofs-of-concept. The tool only reports vulnerabilities where exploitation succeeds, ensuring findings are actionable rather than theoretical.

Shannon Open Source is the standalone version you run locally from the command line, distinct from the commercial Keygraph platform that uses the same underlying agent. The tool suits teams shipping code frequently who need on-demand security testing integrated into their development workflow rather than relying on annual penetration tests. It works against running web applications and their APIs, making it applicable to both traditional web apps and API-first architectures.

The maintainers respond to new issues and pull requests within a day, indicating active engagement with the user base.