# shannon | KeygraphHQ | Knowledge Base | Instagit

Fully autonomous AI hacker to find actual exploits in your web apps. Shannon has achieved a 96.15% success rate on the hint-free, source-aware XBOW Benchmark.

GitHub Stars: 22.4k

Repository: https://github.com/keygraphhq/shannon

---

## Articles

### [How Shannon Validates YAML Configuration Files Using JSON Schema and AJV](/keygraphhq/shannon/shannon-validate-yaml-config-json-schema-ajv)

Learn how Shannon validates YAML files using JSON Schema and AJV. Discover its defense-in-depth approach combining parsing, schema validation, and custom security checks for safe configuration distribution.

- Tags: how-to-guide
- Published: 2026-02-16

### [How Shannon Enforces Agent Prerequisites for Deterministic Execution Order in session-manager](/keygraphhq/shannon/shannon-session-manager-agent-prerequisites-execution-order)

Learn how Shannon enforces agent prerequisites for deterministic execution order. Discover static dependency maps, topological sorting, and runtime validation in Temporal workflows.

- Tags: internals
- Published: 2026-02-16

### [Shannon's Security Validation Rules for Configuration Files: A Deep Dive into Dangerous Pattern Blocking](/keygraphhq/shannon/shannon-security-validation-config-files-dangerous-patterns)

Discover Shannon's security validation rules for configuration files. Learn how this five-layer defense strategy blocks dangerous patterns in YAML files to prevent code injection and path traversal.

- Tags: deep-dive
- Published: 2026-02-16

### [How to Set Up Focus and Avoid Rules to Scope Shannon Pentesting to Specific API Endpoints](/keygraphhq/shannon/shannon-configure-focus-avoid-rules-api-endpoints)

Scope Shannon pentesting to specific API endpoints by defining focus and avoid arrays in the YAML configuration. Filter URLs efficiently for targeted security testing.

- Tags: how-to-guide
- Published: 2026-02-16

### [How to Debug Worker Logs and Query Workflow Execution Status in Shannon](/keygraphhq/shannon/shannon-debug-worker-logs-query-workflow-status)

Debug Shannon worker logs with ./shannon logs ID and query workflow execution status using ./shannon query ID. Empower your debugging with Temporal progress queries.

- Tags: how-to-guide
- Published: 2026-02-16

### [Estimated Runtime and Cost for a Full Pentest Cycle with Shannon: Technical Benchmarks and Optimization](/keygraphhq/shannon/shannon-pentest-runtime-cost-estimate)

Discover Shannon's estimated pentest runtime and cost. Get a full, 1-1.5 hour security analysis for around $50 USD using Claude 4.5 Sonnet and orchestrated LLM agents.

- Tags: benchmarks
- Published: 2026-02-16

### [Legal and Ethical Requirements for Using Shannon on Target Applications: A Complete Guide](/keygraphhq/shannon/shannon-legal-ethical-requirements-target-applications)

Understand legal and ethical requirements for using Shannon, the AI pentesting framework. Get explicit written authorization before running Shannon to avoid CFAA violations and data modification.

- Tags: best-practices
- Published: 2026-02-16

### [How Shannon Handles Graceful Failure of Agents in Parallel Execution Groups](/keygraphhq/shannon/shannon-graceful-failure-parallel-agents)

Learn how Shannon ensures successful pentests with graceful failure handling for agents in parallel execution groups using Promise.allSettled and structured error classification.

- Tags: internals
- Published: 2026-02-16

### [How Shannon's Prompt Manager Handles Variable Substitution for Context: A Technical Deep Dive](/keygraphhq/shannon/shannon-prompt-manager-variable-substitution)

Explore how Shannon's prompt manager handles variable substitution for context. Learn about its pure-function pipeline for template loading, include directives, and interpolation.

- Tags: deep-dive
- Published: 2026-02-16

### [Shannon Lite vs Shannon Pro: Complete Feature and Architecture Comparison](/keygraphhq/shannon/shannon-lite-vs-pro-features)

Compare Shannon Lite AGPL with Shannon Pro commercial. Discover key differences in features and architecture including source-sink analysis, data-flow analysis, CVSS scoring, CI CD integration, and RBAC.

- Tags: comparison
- Published: 2026-02-16

### [How Shannon Handles Authentication Flows for Form-Based Login, SSO, and API Authentication](/keygraphhq/shannon/shannon-handle-authentication-flows-form-sso-api)

Explore how Shannon simplifies authentication flows for form-based login, SSO, and API authentication using declarative YAML and modular prompt templates for automated Playwright commands.

- Tags: deep-dive
- Published: 2026-02-16

### [External Security Tools Integrated into Shannon: Nmap, Subfinder, WhatWeb, and Schemathesis](/keygraphhq/shannon/shannon-integrated-external-security-tools)

Shannon's Pre-Recon phase integrates Nmap, Subfinder, WhatWeb, and Schemathesis concurrently for network discovery, subdomain enumeration, technology fingerprinting, and API schema testing.

- Tags: how-to-guide
- Published: 2026-02-16

### [Shannon Pentest Phases Deliverables: A Complete Guide to the Five-Stage Security Assessment Workflow](/keygraphhq/shannon/shannon-pentest-phases-deliverables)

Explore Shannon's pentest phases deliverables. Discover structured markdown reports and JSON queues for recon, analysis, exploitation, and reporting. Understand each stage's output.

- Tags: how-to-guide
- Published: 2026-02-16

### [How to Configure Custom Output Directories for Audit Logs and Reports in Shannon](/keygraphhq/shannon/shannon-configure-custom-output-directories-logs-reports)

Configure custom output directories for Shannon audit logs and reports using the OUTPUT flag. Streamline your workflow and manage logged data efficiently.

- Tags: how-to-guide
- Published: 2026-02-16

### [How to Monitor Pentest Progress Using Shannon's Temporal Web UI Query Mechanism](/keygraphhq/shannon/shannon-monitor-pentest-progress-temporal-web-ui)

Monitor pentest progress effectively using Shannon's Temporal Web UI query mechanism. Access real-time workflow state via the Temporal Web UI and CLI for better insights.

- Tags: how-to-guide
- Published: 2026-02-16

### [Shannon Environment Variables for Anthropic Claude and OpenAI Models](/keygraphhq/shannon/shannon-environment-variables-anthropic-claude-openai)

Discover the essential environment variables for Shannon, enabling Anthropic Claude and OpenAI model integration. Simplify your setup for seamless API access.

- Tags: how-to-guide
- Published: 2026-02-16

### [How to Test Applications on Localhost from Docker Containers Using host.docker.internal with Shannon](/keygraphhq/shannon/shannon-test-localhost-docker-host-docker-internal)

Easily test localhost applications from Docker containers using Shannon and host.docker.internal. Connect directly to your host machine for seamless development.

- Tags: tutorial
- Published: 2026-02-16

### [How Shannon's Audit Logging System Tracks Session Metrics and Per-Agent Execution Details](/keygraphhq/shannon/shannon-audit-logging-session-metrics-agent-execution)

Discover how Shannon's audit logging system tracks session metrics and agent execution details using a three-layer architecture for complete pentest workflow telemetry.

- Tags: internals
- Published: 2026-02-16

### [Configuring Retry Logic for Transient vs Permanent Errors in Shannon Temporal Activities](/keygraphhq/shannon/shannon-temporal-activities-retry-logic-errors)

Learn how to configure retry logic for transient vs permanent errors in Shannon Temporal activities. Understand custom policies for non-retryable errors like AuthenticationError.

- Tags: how-to-guide
- Published: 2026-02-16

### [How Shannon's "No Exploit, No Report" Policy Eliminates False Positives in Security Testing](/keygraphhq/shannon/shannon-no-exploit-no-report-policy-false-positives)

Discover how Shannon's No Exploit No Report policy drastically reduces false positives in security testing by demanding reproducible proof of vulnerability for every finding. Enhance your tests now.

- Tags: internals
- Published: 2026-02-16

### [Vuln vs Exploit Agent Pairs in Shannon: Understanding the Difference in Penetration Testing Pipelines](/keygraphhq/shannon/shannon-vuln-vs-exploit-agent-pairs)

Clarify the distinction between vuln and exploit agent pairs in Shannon. Learn how vuln agents find vulnerabilities and exploit agents attempt conditional exploitation.

- Tags: deep-dive
- Published: 2026-02-16

### [How to Configure TOTP/2FA Authentication for Testing Applications in Shannon](/keygraphhq/shannon/configure-totp-2fa-authentication-shannon)

Configure TOTP 2FA for testing applications in Shannon. Easily set up two-factor authentication with base-32 secrets and automated code generation for browser automation.

- Tags: how-to-guide
- Published: 2026-02-16

### [Shannon's Temporal Workflow Crash Recovery: How It Preserves State in the Pentest Pipeline](/keygraphhq/shannon/shannon-temporal-workflow-crash-recovery-state-preservation)

Discover Shannon's Temporal workflow crash recovery. Learn how it automatically persists state at await boundaries to resume pentest pipelines seamlessly after worker crashes, preserving all progress and data.

- Tags: internals
- Published: 2026-02-16

### [Shannon Multi-Agent Architecture: How It Enables Parallel Vulnerability Analysis and Exploitation](/keygraphhq/shannon/shannon-multi-agent-architecture-parallel-analysis-exploitation)

Discover Shannon's multi-agent architecture enabling parallel vulnerability analysis and exploitation. Learn how its temporal-driven pipeline accelerates security testing.

- Tags: architecture
- Published: 2026-02-16

### [Shannon's Parallel Execution Capabilities for Vulnerability Analysis: A Technical Deep Dive](/keygraphhq/shannon/shannon-parallel-execution-vulnerability-analysis)

Explore Shannon's parallel execution for vulnerability analysis. Discover how Temporal pipelines and Promise-based mutexes speed up pentests while ensuring deterministic order.

- Tags: deep-dive
- Published: 2026-02-15

