Shannon Lite vs Shannon Pro: Complete Feature and Architecture Comparison
Shannon Lite is a free, AGPL‑licensed CLI tool that performs context‑window limited source‑sink analysis, while Shannon Pro is a commercial platform offering cross‑codebase data‑flow analysis, CVSS scoring, CI/CD integration, and enterprise RBAC.
The KeygraphHQ/shannon repository hosts both editions of this AI‑powered security scanner. While Shannon Lite provides foundational vulnerability detection for individual developers, Shannon Pro extends the architecture with multi‑agent orchestration and enterprise controls. Understanding the differences between Shannon Lite and Shannon Pro helps teams choose the right deployment model for their security workflows.
Core Feature Comparison
Scanning Engine and Analysis Depth
Shannon Lite implements a simple source‑sink analysis constrained to the LLM context window. It runs a single Claude Agent that examines code within token budget limits, making it suitable for focused scans of individual modules.
Shannon Pro deploys an LLM‑powered data‑flow analysis engine inspired by LLM‑Driven Data‑Flow Analysis research. According to the source code in src/session-manager.ts, Pro coordinates a fleet of specialized Claude Agents that contribute to a graph‑based data‑flow engine. This tracks input → sink relationships across the entire codebase, enabling detection of multi‑module vulnerability chains that exceed context window limitations.
Enterprise Features and Compliance
Shannon Pro adds enterprise controls absent from the open‑source edition:
- CVSS Scoring: Automatic CVSS v3.1 calculation for each finding
- Remediation Guidance: Line‑by‑line code fixes generated by the LLM, versus basic descriptions in Lite
- RBAC and SSO: Multi‑user support with role‑based access control and SAML/SSO integration
- Audit Logging: Immutable checkpoints and compliance reports (OWASP, PCI‑DSS, SOC 2) stored in
audit-logs/*viasrc/audit/ - Support: Dedicated support with SLA versus community‑driven Discord and GitHub issues
Architecture Comparison: AGPL vs Commercial
Analysis Engine Implementation
The architectural divergence begins in the agent orchestration layer. In src/session-manager.ts, Shannon Lite initializes a single agent queue with linear execution. Shannon Pro extends this to manage parallel groups of agents that simultaneously query a global data‑flow graph.
Shannon Lite’s analysis is limited by the context window of the underlying LLM. Shannon Pro’s graph‑based engine in src/session-manager.ts aggregates input‑output relationships across files, enabling detection of vulnerabilities that span multiple modules.
Workflow Orchestration
Both editions use Temporal workflows defined in src/temporal/workflows.ts, but with different concurrency models:
Shannon Lite runs four linear phases: Reconnaissance → Vulnerability Analysis → Exploitation → Reporting. Each phase completes before the next begins.
Shannon Pro enlarges the parallel groups within the same Temporal backbone. The Vulnerability Analysis stage runs five simultaneous agents that each query the global data‑flow graph, dramatically increasing coverage while maintaining the workflow structure.
Scalability and Deployment Options
Shannon Lite is designed for single‑container deployment via docker-compose.docker.yml, running on a single Docker container with no built‑in authentication beyond LLM API keys.
Shannon Pro supports cloud‑scale deployment as a stateless service behind a load balancer, with horizontal scaling of Temporal workers. Deployment options include:
- Cloud‑hosted SaaS: Fully managed by Keygraph
- Self‑hosted: Docker or Kubernetes with enterprise configuration via
configs/example-config.yaml
The self‑hosted Pro configuration in configs/example-config.yaml exposes settings for SSO, audit storage (S3 or local), and compliance reporting that are absent from the Lite edition.
Practical Usage Examples
Running Shannon Lite Locally
Shannon Lite requires only Docker and an Anthropic API key:
# Clone the repository
git clone https://github.com/KeygraphHQ/shannon.git
cd shannon
# Provide an Anthropic API key
export ANTHROPIC_API_KEY="your-key"
# Run a pentest against a local app
./shannon start URL=http://host.docker.internal:3000 REPO=sample-app
This executes the single‑agent scan defined in src/session-manager.ts with context‑window limited analysis.
Integrating Shannon Pro into CI/CD
Shannon Pro provides native GitHub Actions support and API access for automated pipelines:
name: Security Scan
on: [push, pull_request]
jobs:
shannon-pro:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
- name: Run Shannon Pro
env:
SHANNON_API_KEY: ${{ secrets.SHANNON_API_KEY }}
run: |
curl -X POST https://api.keygraph.io/shannon/run \
-H "Authorization: Bearer $SHANNON_API_KEY" \
-d '{"repo":"${{ github.repository }}","ref":"${{ github.sha }}"}'
This triggers the multi‑agent workflow in src/temporal/workflows.ts with parallel vulnerability analysis.
Accessing Pro Features via API
Fetch detailed findings with CVSS scores using the Shannon Pro REST API:
import requests, os
api_key = os.getenv("SHANNON_API_KEY")
headers = {"Authorization": f"Bearer {api_key}"}
resp = requests.get("https://api.keygraph.io/shannon/findings", headers=headers)
for finding in resp.json()["findings"]:
print(f"{finding['id']}: {finding['title']} (CVSS {finding['cvss']})")
The API exposes the graph‑based analysis results stored in the Pro audit system.
Configuring Enterprise Audit Logs
For self‑hosted Shannon Pro deployments, enable compliance logging via configs/example-config.yaml:
audit:
enabled: true
storage: s3 # or local
s3:
bucket: shannon-audits
auth:
sso:
enabled: true
provider: saml
metadata_url: https://sso.example.com/metadata.xml
This activates the enterprise controls implemented in src/audit/ and src/queue-validation.ts.
Key Files and Implementation Details
Understanding the codebase structure clarifies the technical boundaries between editions:
src/session-manager.ts: Defines the agent queue and orchestration logic. Lite uses a single agent; Pro implements parallel groups and graph‑based data‑flow tracking.src/temporal/workflows.ts: Contains the workflow definitions. Lite runs linear phases; Pro extends this with concurrent agent execution during vulnerability analysis.src/tool-checker.ts: Validates external security tools. Pro exposes this as a plugin API for custom scanners.src/queue-validation.ts: Enforces enterprise standards for deliverables, including RBAC and compliance checks available only in Pro.configs/example-config.yaml: Demonstrates configuration options. Pro‑specific fields include SSO, audit storage backends, and compliance reporting.docker-compose.docker.yml: Supports single‑container deployment suitable for Lite; Pro can use this for self‑hosting but typically deploys to cloud‑scale infrastructure.
Summary
- Shannon Lite is an open‑source, AGPL‑3.0 licensed CLI tool providing context‑window limited source‑sink analysis via a single Claude Agent, suitable for individual developers and small projects.
- Shannon Pro is a commercial platform adding cross‑codebase data‑flow analysis through a multi‑agent graph engine, automatic CVSS scoring, detailed remediation guidance, and native CI/CD integration.
- Architecture: Lite runs linear Temporal workflows in a single Docker container; Pro scales horizontally with parallel agent groups, cloud deployment options, and enterprise RBAC/SSO controls.
- Key differentiators: Pro exposes plugin APIs in
src/tool-checker.tsandsrc/queue-validation.ts, supports audit logging viasrc/audit/, and offers both SaaS and self‑hosted deployment with SAML configuration inconfigs/example-config.yaml.
Frequently Asked Questions
What is the main technical difference between Shannon Lite and Shannon Pro?
The primary technical distinction lies in the analysis engine architecture. Shannon Lite uses a single Claude Agent performing context‑window constrained source‑sink analysis, while Shannon Pro implements a graph‑based data‑flow engine coordinated by src/session-manager.ts that tracks input → sink relationships across the entire codebase using multiple parallel agents.
Can I upgrade from Shannon Lite to Shannon Pro without changing my workflow?
Yes, the upgrade path is designed for compatibility. Both editions share the same Temporal workflow backbone defined in src/temporal/workflows.ts, so existing Lite CLI commands work in Pro. However, Pro unlocks parallel execution stages and requires API keys for the commercial service or enterprise configuration in configs/example-config.yaml for self‑hosted deployments.
Is Shannon Pro available as a self‑hosted option or only SaaS?
Shannon Pro supports both deployment models. You can use the cloud‑hosted SaaS version managed by Keygraph, or self‑host Pro using Docker or Kubernetes with the configuration templates in configs/example-config.yaml. The self‑hosted option requires setting up enterprise features like SSO and audit storage backends manually.
Does Shannon Lite include any commercial features or API access?
No, Shannon Lite is strictly a stand‑alone CLI tool with no built‑in API access or CI/CD integrations. It runs as a single Docker container without authentication mechanisms beyond LLM API keys. Commercial features such as the REST API, webhook connectors, and RBAC controls are exclusive to Shannon Pro.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →