# Shannon Pentest Phases Deliverables: A Complete Guide to the Five-Stage Security Assessment Workflow

> Explore Shannon's pentest phases deliverables. Discover structured markdown reports and JSON queues for recon, analysis, exploitation, and reporting. Understand each stage's output.

- Repository: [KeygraphHQ/shannon](https://github.com/keygraphhq/shannon)
- Tags: how-to-guide
- Published: 2026-02-16

---

**Shannon generates structured markdown reports and JSON exploitation queues for each pentest phase, mapping deliverable types like `CODE_ANALYSIS`, `RECON`, and `XSS_ANALYSIS` to specific output files that create an auditable chain from initial code review to final executive reporting.**

Shannon is an open-source automated penetration testing framework that orchestrates security assessments through a deterministic five-phase pipeline. Each phase consumes the deliverables of the previous stage and produces standardized outputs—both human-readable markdown reports and machine-readable JSON queues—that feed sequentially into vulnerability analysis, exploitation, and final reporting.

## Phase 1: Pre-Reconnaissance and Code Analysis

The **pre-recon** phase performs static analysis of the target codebase to establish a foundational understanding of the application architecture before dynamic testing begins.

**Primary Deliverable:** `CODE_ANALYSIS`  
**Output File:** [`code_analysis_deliverable.md`](https://github.com/KeygraphHQ/shannon/blob/main/code_analysis_deliverable.md)

According to the implementation in [[`src/phases/pre-recon.ts`](https://github.com/KeygraphHQ/shannon/blob/main/src/phases/pre-recon.ts)](https://github.com/KeygraphHQ/shannon/blob/main/src/phases/pre-recon.ts), this phase analyzes repository structure, identifies entry points, maps technology stacks, and documents high-risk code patterns. The deliverable is saved via the `save_deliverable` MCP tool with the type string `CODE_ANALYSIS`, creating a markdown report that feeds directly into the reconnaissance phase.

## Phase 2: Reconnaissance

The **recon** phase consumes the code analysis deliverable to perform dynamic application mapping and threat modeling.

**Primary Deliverable:** `RECON`  
**Output File:** [`recon_deliverable.md`](https://github.com/KeygraphHQ/shannon/blob/main/recon_deliverable.md)

As implemented in [[`src/phases/recon.ts`](https://github.com/KeygraphHQ/shannon/blob/main/src/phases/recon.ts)](https://github.com/KeygraphHQ/shannon/blob/main/src/phases/recon.ts), this phase parses the pre-recon data to generate an endpoint inventory, catalog input vectors (parameters, headers, cookies), and produce a threat model. The `RECON` deliverable type creates a comprehensive markdown report that serves as the input source for all subsequent vulnerability analysis sub-phases.

## Phase 3: Vulnerability Analysis

The **vulnerability-analysis** phase is subdivided into specialized security domains, each producing dual deliverables: a markdown analysis report and a JSON exploitation queue.

### Injection Analysis

**Deliverable Type:** `INJECTION_ANALYSIS`  
**Output Files:** [`injection_analysis_deliverable.md`](https://github.com/KeygraphHQ/shannon/blob/main/injection_analysis_deliverable.md), [`injection_exploitation_queue.json`](https://github.com/KeygraphHQ/shannon/blob/main/injection_exploitation_queue.json)

The [[`src/phases/injection.ts`](https://github.com/KeygraphHQ/shannon/blob/main/src/phases/injection.ts)](https://github.com/KeygraphHQ/shannon/blob/main/src/phases/injection.ts) module analyzes the recon deliverable for SQL injection and command injection vectors. It outputs a markdown vulnerability report and a structured JSON queue containing confirmed injection points ready for exploitation testing.

### Cross-Site Scripting (XSS) Analysis

**Deliverable Type:** `XSS_ANALYSIS`  
**Output Files:** [`xss_analysis_deliverable.md`](https://github.com/KeygraphHQ/shannon/blob/main/xss_analysis_deliverable.md), [`xss_exploitation_queue.json`](https://github.com/KeygraphHQ/shannon/blob/main/xss_exploitation_queue.json)

Implemented in [[`src/phases/xss.ts`](https://github.com/KeygraphHQ/shannon/blob/main/src/phases/xss.ts)](https://github.com/KeygraphHQ/shannon/blob/main/src/phases/xss.ts), this phase identifies reflected, stored, and DOM-based XSS vulnerabilities. The deliverable includes a detailed analysis markdown file and a JSON exploitation queue mapping vulnerable endpoints to payload strategies.

### Server-Side Request Forgery (SSRF) Analysis

**Deliverable Type:** `SSRF_ANALYSIS`  
**Output Files:** [`ssrf_analysis_deliverable.md`](https://github.com/KeygraphHQ/shannon/blob/main/ssrf_analysis_deliverable.md), [`ssrf_exploitation_queue.json`](https://github.com/KeygraphHQ/shannon/blob/main/ssrf_exploitation_queue.json)

The [[`src/phases/ssrf.ts`](https://github.com/KeygraphHQ/shannon/blob/main/src/phases/ssrf.ts)](https://github.com/KeygraphHQ/shannon/blob/main/src/phases/ssrf.ts) module detects SSRF vulnerabilities in URL parameters and request headers. It produces a markdown analysis and a JSON queue for internal network probing and cloud metadata extraction attempts.

### Authentication Analysis

**Deliverable Type:** `AUTH_ANALYSIS`  
**Output Files:** [`auth_analysis_deliverable.md`](https://github.com/KeygraphHQ/shannon/blob/main/auth_analysis_deliverable.md), [`auth_exploitation_queue.json`](https://github.com/KeygraphHQ/shannon/blob/main/auth_exploitation_queue.json)

As defined in [[`src/phases/auth.ts`](https://github.com/KeygraphHQ/shannon/blob/main/src/phases/auth.ts)](https://github.com/KeygraphHQ/shannon/blob/main/src/phases/auth.ts), this phase evaluates session management, credential handling, and multi-factor authentication implementations. The deliverable includes vulnerability findings and a JSON queue for authentication bypass testing.

### Authorization Analysis

**Deliverable Type:** `AUTHZ_ANALYSIS`  
**Output Files:** [`authz_analysis_deliverable.md`](https://github.com/KeygraphHQ/shannon/blob/main/authz_analysis_deliverable.md), [`authz_exploitation_queue.json`](https://github.com/KeygraphHQ/shannon/blob/main/authz_exploitation_queue.json)

The [[`src/phases/authz.ts`](https://github.com/KeygraphHQ/shannon/blob/main/src/phases/authz.ts)](https://github.com/KeygraphHQ/shannon/blob/main/src/phases/authz.ts) module analyzes role-based access control (RBAC) and horizontal/vertical privilege escalation vectors. It outputs an authorization architecture report and a JSON exploitation queue for privilege escalation testing.

## Phase 4: Exploitation

The **exploitation** phase consumes the JSON exploitation queues generated during vulnerability analysis to perform automated or semi-automated proof-of-concept validation.

**Input:** `*_exploitation_queue.json` files (injection, XSS, SSRF, auth, authz)  
**Output:** `*_evidence.md` files containing confirmed vulnerability evidence, payload details, and risk ratings.

According to the utility modules in [[`src/utils/output-formatter.ts`](https://github.com/KeygraphHQ/shannon/blob/main/src/utils/output-formatter.ts)](https://github.com/KeygraphHQ/shannon/blob/main/src/utils/output-formatter.ts), exploitation agents read the structured JSON queues, execute targeted attacks against the identified vectors, and generate markdown evidence files that document successful exploits with screenshots, request/response pairs, and reproduction steps.

## Phase 5: Reporting

The **reporting** phase consolidates all previous deliverables into a comprehensive security assessment report suitable for executive stakeholders and technical remediation teams.

**Primary Deliverable:** `COMPREHENSIVE_SECURITY_ASSESSMENT`  
**Output File:** [`comprehensive_security_assessment_report.md`](https://github.com/KeygraphHQ/shannon/blob/main/comprehensive_security_assessment_report.md)

As implemented in [[`src/phases/reporting.ts`](https://github.com/KeygraphHQ/shannon/blob/main/src/phases/reporting.ts)](https://github.com/KeygraphHQ/shannon/blob/main/src/phases/reporting.ts), this phase aggregates the code analysis, reconnaissance data, vulnerability findings, exploitation evidence, and risk ratings into a polished markdown report. The deliverable includes executive summaries, technical vulnerability details, CVSS scores, and prioritized remediation guidance. Sample outputs are available in [[`sample-reports/shannon-report-juice-shop.md`](https://github.com/KeygraphHQ/shannon/blob/main/sample-reports/shannon-report-juice-shop.md)](https://github.com/KeygraphHQ/shannon/blob/main/sample-reports/shannon-report-juice-shop.md).

## Running Shannon: Practical Examples

### CLI Execution

Run a complete five-phase assessment using the Shannon CLI:

```bash

# Execute full pipeline against a local target

shannon run \
  --target http://localhost:8080 \
  --config ./configs/example-config.yaml \
  --output ./audit-logs

```

### Configuration File

Define your assessment scope using a YAML configuration validated against [[`configs/config-schema.json`](https://github.com/KeygraphHQ/shannon/blob/main/configs/config-schema.json)](https://github.com/KeygraphHQ/shannon/blob/main/configs/config-schema.json):

```yaml
target: http://localhost:8080
phases:
  - pre-recon
  - recon
  - injection
  - xss
  - ssrf
  - auth
  - authz
  - reporting
output_dir: ./deliverables
git_integration: true

```

### Programmatic Integration

Invoke Shannon programmatically from a TypeScript application:

```typescript
import { Shannon } from './src/cli/ui';

const shannon = new Shannon({
  target: 'http://localhost:8080',
  configPath: './configs/example-config.yaml',
  outputDir: './audit-logs',
  enableGitLog: true
});

// Execute all phases sequentially
await shannon.execute();

```

### Customizing Prompt Templates

Override default prompt templates by replacing files in the prompt library:

```bash

# Replace the reconnaissance prompt with custom logic

cp my-custom-recon-prompt.txt src/prompts/recon.txt

# Run assessment with custom prompt

shannon run --target http://example.com

```

## Key Files Reference

| File | Description |
|------|-------------|
| [[`src/cli/ui.ts`](https://github.com/KeygraphHQ/shannon/blob/main/src/cli/ui.ts)](https://github.com/KeygraphHQ/shannon/blob/main/src/cli/ui.ts) | Entry point implementing the `shannon run` command-line interface. |
| [[`src/phases/pre-recon.ts`](https://github.com/KeygraphHQ/shannon/blob/main/src/phases/pre-recon.ts)](https://github.com/KeygraphHQ/shannon/blob/main/src/phases/pre-recon.ts) | Generates the `CODE_ANALYSIS` deliverable through static codebase examination. |
| [[`src/phases/recon.ts`](https://github.com/KeygraphHQ/shannon/blob/main/src/phases/recon.ts)](https://github.com/KeygraphHQ/shannon/blob/main/src/phases/recon.ts) | Produces the `RECON` deliverable containing endpoint inventory and threat models. |
| [[`src/phases/injection.ts`](https://github.com/KeygraphHQ/shannon/blob/main/src/phases/injection.ts)](https://github.com/KeygraphHQ/shannon/blob/main/src/phases/injection.ts) | Creates `INJECTION_ANALYSIS` deliverables and SQLi/command-injection exploitation queues. |
| [[`src/phases/xss.ts`](https://github.com/KeygraphHQ/shannon/blob/main/src/phases/xss.ts)](https://github.com/KeygraphHQ/shannon/blob/main/src/phases/xss.ts) | Generates `XSS_ANALYSIS` deliverables and cross-site scripting exploitation queues. |
| [[`src/phases/ssrf.ts`](https://github.com/KeygraphHQ/shannon/blob/main/src/phases/ssrf.ts)](https://github.com/KeygraphHQ/shannon/blob/main/src/phases/ssrf.ts) | Produces `SSRF_ANALYSIS` deliverables and server-side request forgery exploitation queues. |
| [[`src/phases/auth.ts`](https://github.com/KeygraphHQ/shannon/blob/main/src/phases/auth.ts)](https://github.com/KeygraphHQ/shannon/blob/main/src/phases/auth.ts) | Creates `AUTH_ANALYSIS` deliverables and authentication bypass exploitation queues. |
| [[`src/phases/authz.ts`](https://github.com/KeygraphHQ/shannon/blob/main/src/phases/authz.ts)](https://github.com/KeygraphHQ/shannon/blob/main/src/phases/authz.ts) | Generates `AUTHZ_ANALYSIS` deliverables and authorization privilege escalation queues. |
| [[`src/phases/reporting.ts`](https://github.com/KeygraphHQ/shannon/blob/main/src/phases/reporting.ts)](https://github.com/KeygraphHQ/shannon/blob/main/src/phases/reporting.ts) | Consolidates all deliverables into the final comprehensive security assessment report. |
| [[`src/utils/file-io.ts`](https://github.com/KeygraphHQ/shannon/blob/main/src/utils/file-io.ts)](https://github.com/KeygraphHQ/shannon/blob/main/src/utils/file-io.ts) | Handles reading and writing of markdown and JSON deliverable files. |
| [[`src/utils/output-formatter.ts`](https://github.com/KeygraphHQ/shannon/blob/main/src/utils/output-formatter.ts)](https://github.com/KeygraphHQ/shannon/blob/main/src/utils/output-formatter.ts) | Formats LLM responses into structured deliverable documents. |
| [[`src/utils/git-manager.ts`](https://github.com/KeygraphHQ/shannon/blob/main/src/utils/git-manager.ts)](https://github.com/KeygraphHQ/shannon/blob/main/src/utils/git-manager.ts) | Manages git-backed audit logging for all generated deliverables. |
| [`src/prompts/*.txt`](https://github.com/KeygraphHQ/shannon/tree/main/src/prompts) | LLM prompt templates that define the analysis criteria for each phase. |
| [[`sample-reports/shannon-report-juice-shop.md`](https://github.com/KeygraphHQ/shannon/blob/main/sample-reports/shannon-report-juice-shop.md)](https://github.com/KeygraphHQ/shannon/blob/main/sample-reports/shannon-report-juice-shop.md) | Example of a completed comprehensive security assessment report. |
| [[`configs/config-schema.json`](https://github.com/KeygraphHQ/shannon/blob/main/configs/config-schema.json)](https://github.com/KeygraphHQ/shannon/blob/main/configs/config-schema.json) | JSON schema validating the YAML configuration file structure. |

## Summary

- **Shannon pentest phases deliverables** follow a strict pipeline: `CODE_ANALYSIS` → `RECON` → vulnerability-specific analyses (`INJECTION_ANALYSIS`, `XSS_ANALYSIS`, etc.) → exploitation evidence → comprehensive final report.
- Each vulnerability analysis phase produces dual deliverables: a human-readable markdown analysis (`*_analysis_deliverable.md`) and a machine-readable JSON exploitation queue (`*_exploitation_queue.json`).
- The `save_deliverable` MCP tool persists all outputs using standardized `deliverable_type` strings, ensuring consistent formatting across the assessment lifecycle.
- Final reporting consolidates all phase outputs into a single [`comprehensive_security_assessment_report.md`](https://github.com/KeygraphHQ/shannon/blob/main/comprehensive_security_assessment_report.md) suitable for executive stakeholders and remediation teams.

## Frequently Asked Questions

### What file formats does Shannon generate for each pentest phase?

Shannon generates **markdown** files for human-readable reports and **JSON** files for machine-readable exploitation queues. Each vulnerability analysis phase produces both formats: for example, [`xss_analysis_deliverable.md`](https://github.com/KeygraphHQ/shannon/blob/main/xss_analysis_deliverable.md) contains the detailed findings, while [`xss_exploitation_queue.json`](https://github.com/KeygraphHQ/shannon/blob/main/xss_exploitation_queue.json) provides structured data for the exploitation phase to execute proof-of-concept attacks.

### How does Shannon ensure deliverables are preserved across pipeline stages?

Shannon uses the `save_deliverable` MCP tool with standardized `deliverable_type` strings (such as `CODE_ANALYSIS`, `RECON`, and `AUTHZ_ANALYSIS`) to persist outputs. The [[`src/utils/git-manager.ts`](https://github.com/KeygraphHQ/shannon/blob/main/src/utils/git-manager.ts)](https://github.com/KeygraphHQ/shannon/blob/main/src/utils/git-manager.ts) module optionally commits each deliverable to a git-backed audit log, creating an immutable chain of evidence from initial code analysis through final reporting.

### Can I customize the deliverables generated during the vulnerability analysis phases?

Yes. You can override the LLM prompt templates in [`src/prompts/*.txt`](https://github.com/KeygraphHQ/shannon/tree/main/src/prompts) to modify how Shannon analyzes vulnerabilities and structures its deliverables. Additionally, the [[`configs/config-schema.json`](https://github.com/KeygraphHQ/shannon/blob/main/configs/config-schema.json)](https://github.com/KeygraphHQ/shannon/blob/main/configs/config-schema.json) allows you to define which phases execute, effectively controlling which deliverable types are generated during an assessment.