Shannon Pentest Phases Deliverables: A Complete Guide to the Five-Stage Security Assessment Workflow

Shannon generates structured markdown reports and JSON exploitation queues for each pentest phase, mapping deliverable types like CODE_ANALYSIS, RECON, and XSS_ANALYSIS to specific output files that create an auditable chain from initial code review to final executive reporting.

Shannon is an open-source automated penetration testing framework that orchestrates security assessments through a deterministic five-phase pipeline. Each phase consumes the deliverables of the previous stage and produces standardized outputs—both human-readable markdown reports and machine-readable JSON queues—that feed sequentially into vulnerability analysis, exploitation, and final reporting.

Phase 1: Pre-Reconnaissance and Code Analysis

The pre-recon phase performs static analysis of the target codebase to establish a foundational understanding of the application architecture before dynamic testing begins.

Primary Deliverable: CODE_ANALYSIS
Output File: code_analysis_deliverable.md

According to the implementation in [src/phases/pre-recon.ts](https://github.com/KeygraphHQ/shannon/blob/main/src/phases/pre-recon.ts), this phase analyzes repository structure, identifies entry points, maps technology stacks, and documents high-risk code patterns. The deliverable is saved via the save_deliverable MCP tool with the type string CODE_ANALYSIS, creating a markdown report that feeds directly into the reconnaissance phase.

Phase 2: Reconnaissance

The recon phase consumes the code analysis deliverable to perform dynamic application mapping and threat modeling.

Primary Deliverable: RECON
Output File: recon_deliverable.md

As implemented in [src/phases/recon.ts](https://github.com/KeygraphHQ/shannon/blob/main/src/phases/recon.ts), this phase parses the pre-recon data to generate an endpoint inventory, catalog input vectors (parameters, headers, cookies), and produce a threat model. The RECON deliverable type creates a comprehensive markdown report that serves as the input source for all subsequent vulnerability analysis sub-phases.

Phase 3: Vulnerability Analysis

The vulnerability-analysis phase is subdivided into specialized security domains, each producing dual deliverables: a markdown analysis report and a JSON exploitation queue.

Injection Analysis

Deliverable Type: INJECTION_ANALYSIS
Output Files: injection_analysis_deliverable.md, injection_exploitation_queue.json

The [src/phases/injection.ts](https://github.com/KeygraphHQ/shannon/blob/main/src/phases/injection.ts) module analyzes the recon deliverable for SQL injection and command injection vectors. It outputs a markdown vulnerability report and a structured JSON queue containing confirmed injection points ready for exploitation testing.

Cross-Site Scripting (XSS) Analysis

Deliverable Type: XSS_ANALYSIS
Output Files: xss_analysis_deliverable.md, xss_exploitation_queue.json

Implemented in [src/phases/xss.ts](https://github.com/KeygraphHQ/shannon/blob/main/src/phases/xss.ts), this phase identifies reflected, stored, and DOM-based XSS vulnerabilities. The deliverable includes a detailed analysis markdown file and a JSON exploitation queue mapping vulnerable endpoints to payload strategies.

Server-Side Request Forgery (SSRF) Analysis

Deliverable Type: SSRF_ANALYSIS
Output Files: ssrf_analysis_deliverable.md, ssrf_exploitation_queue.json

The [src/phases/ssrf.ts](https://github.com/KeygraphHQ/shannon/blob/main/src/phases/ssrf.ts) module detects SSRF vulnerabilities in URL parameters and request headers. It produces a markdown analysis and a JSON queue for internal network probing and cloud metadata extraction attempts.

Authentication Analysis

Deliverable Type: AUTH_ANALYSIS
Output Files: auth_analysis_deliverable.md, auth_exploitation_queue.json

As defined in [src/phases/auth.ts](https://github.com/KeygraphHQ/shannon/blob/main/src/phases/auth.ts), this phase evaluates session management, credential handling, and multi-factor authentication implementations. The deliverable includes vulnerability findings and a JSON queue for authentication bypass testing.

Authorization Analysis

Deliverable Type: AUTHZ_ANALYSIS
Output Files: authz_analysis_deliverable.md, authz_exploitation_queue.json

The [src/phases/authz.ts](https://github.com/KeygraphHQ/shannon/blob/main/src/phases/authz.ts) module analyzes role-based access control (RBAC) and horizontal/vertical privilege escalation vectors. It outputs an authorization architecture report and a JSON exploitation queue for privilege escalation testing.

Phase 4: Exploitation

The exploitation phase consumes the JSON exploitation queues generated during vulnerability analysis to perform automated or semi-automated proof-of-concept validation.

Input: *_exploitation_queue.json files (injection, XSS, SSRF, auth, authz)
Output: *_evidence.md files containing confirmed vulnerability evidence, payload details, and risk ratings.

According to the utility modules in [src/utils/output-formatter.ts](https://github.com/KeygraphHQ/shannon/blob/main/src/utils/output-formatter.ts), exploitation agents read the structured JSON queues, execute targeted attacks against the identified vectors, and generate markdown evidence files that document successful exploits with screenshots, request/response pairs, and reproduction steps.

Phase 5: Reporting

The reporting phase consolidates all previous deliverables into a comprehensive security assessment report suitable for executive stakeholders and technical remediation teams.

Primary Deliverable: COMPREHENSIVE_SECURITY_ASSESSMENT
Output File: comprehensive_security_assessment_report.md

As implemented in [src/phases/reporting.ts](https://github.com/KeygraphHQ/shannon/blob/main/src/phases/reporting.ts), this phase aggregates the code analysis, reconnaissance data, vulnerability findings, exploitation evidence, and risk ratings into a polished markdown report. The deliverable includes executive summaries, technical vulnerability details, CVSS scores, and prioritized remediation guidance. Sample outputs are available in [sample-reports/shannon-report-juice-shop.md](https://github.com/KeygraphHQ/shannon/blob/main/sample-reports/shannon-report-juice-shop.md).

Running Shannon: Practical Examples

CLI Execution

Run a complete five-phase assessment using the Shannon CLI:


# Execute full pipeline against a local target

shannon run \
  --target http://localhost:8080 \
  --config ./configs/example-config.yaml \
  --output ./audit-logs

Configuration File

Define your assessment scope using a YAML configuration validated against [configs/config-schema.json](https://github.com/KeygraphHQ/shannon/blob/main/configs/config-schema.json):

target: http://localhost:8080
phases:
  - pre-recon
  - recon
  - injection
  - xss
  - ssrf
  - auth
  - authz
  - reporting
output_dir: ./deliverables
git_integration: true

Programmatic Integration

Invoke Shannon programmatically from a TypeScript application:

import { Shannon } from './src/cli/ui';

const shannon = new Shannon({
  target: 'http://localhost:8080',
  configPath: './configs/example-config.yaml',
  outputDir: './audit-logs',
  enableGitLog: true
});

// Execute all phases sequentially
await shannon.execute();

Customizing Prompt Templates

Override default prompt templates by replacing files in the prompt library:


# Replace the reconnaissance prompt with custom logic

cp my-custom-recon-prompt.txt src/prompts/recon.txt

# Run assessment with custom prompt

shannon run --target http://example.com

Key Files Reference

File Description
[src/cli/ui.ts](https://github.com/KeygraphHQ/shannon/blob/main/src/cli/ui.ts) Entry point implementing the shannon run command-line interface.
[src/phases/pre-recon.ts](https://github.com/KeygraphHQ/shannon/blob/main/src/phases/pre-recon.ts) Generates the CODE_ANALYSIS deliverable through static codebase examination.
[src/phases/recon.ts](https://github.com/KeygraphHQ/shannon/blob/main/src/phases/recon.ts) Produces the RECON deliverable containing endpoint inventory and threat models.
[src/phases/injection.ts](https://github.com/KeygraphHQ/shannon/blob/main/src/phases/injection.ts) Creates INJECTION_ANALYSIS deliverables and SQLi/command-injection exploitation queues.
[src/phases/xss.ts](https://github.com/KeygraphHQ/shannon/blob/main/src/phases/xss.ts) Generates XSS_ANALYSIS deliverables and cross-site scripting exploitation queues.
[src/phases/ssrf.ts](https://github.com/KeygraphHQ/shannon/blob/main/src/phases/ssrf.ts) Produces SSRF_ANALYSIS deliverables and server-side request forgery exploitation queues.
[src/phases/auth.ts](https://github.com/KeygraphHQ/shannon/blob/main/src/phases/auth.ts) Creates AUTH_ANALYSIS deliverables and authentication bypass exploitation queues.
[src/phases/authz.ts](https://github.com/KeygraphHQ/shannon/blob/main/src/phases/authz.ts) Generates AUTHZ_ANALYSIS deliverables and authorization privilege escalation queues.
[src/phases/reporting.ts](https://github.com/KeygraphHQ/shannon/blob/main/src/phases/reporting.ts) Consolidates all deliverables into the final comprehensive security assessment report.
[src/utils/file-io.ts](https://github.com/KeygraphHQ/shannon/blob/main/src/utils/file-io.ts) Handles reading and writing of markdown and JSON deliverable files.
[src/utils/output-formatter.ts](https://github.com/KeygraphHQ/shannon/blob/main/src/utils/output-formatter.ts) Formats LLM responses into structured deliverable documents.
[src/utils/git-manager.ts](https://github.com/KeygraphHQ/shannon/blob/main/src/utils/git-manager.ts) Manages git-backed audit logging for all generated deliverables.
src/prompts/*.txt LLM prompt templates that define the analysis criteria for each phase.
[sample-reports/shannon-report-juice-shop.md](https://github.com/KeygraphHQ/shannon/blob/main/sample-reports/shannon-report-juice-shop.md) Example of a completed comprehensive security assessment report.
[configs/config-schema.json](https://github.com/KeygraphHQ/shannon/blob/main/configs/config-schema.json) JSON schema validating the YAML configuration file structure.

Summary

  • Shannon pentest phases deliverables follow a strict pipeline: CODE_ANALYSIS → RECON → vulnerability-specific analyses (INJECTION_ANALYSIS, XSS_ANALYSIS, etc.) → exploitation evidence → comprehensive final report.
  • Each vulnerability analysis phase produces dual deliverables: a human-readable markdown analysis (*_analysis_deliverable.md) and a machine-readable JSON exploitation queue (*_exploitation_queue.json).
  • The save_deliverable MCP tool persists all outputs using standardized deliverable_type strings, ensuring consistent formatting across the assessment lifecycle.
  • Final reporting consolidates all phase outputs into a single comprehensive_security_assessment_report.md suitable for executive stakeholders and remediation teams.

Frequently Asked Questions

What file formats does Shannon generate for each pentest phase?

Shannon generates markdown files for human-readable reports and JSON files for machine-readable exploitation queues. Each vulnerability analysis phase produces both formats: for example, xss_analysis_deliverable.md contains the detailed findings, while xss_exploitation_queue.json provides structured data for the exploitation phase to execute proof-of-concept attacks.

How does Shannon ensure deliverables are preserved across pipeline stages?

Shannon uses the save_deliverable MCP tool with standardized deliverable_type strings (such as CODE_ANALYSIS, RECON, and AUTHZ_ANALYSIS) to persist outputs. The [src/utils/git-manager.ts](https://github.com/KeygraphHQ/shannon/blob/main/src/utils/git-manager.ts) module optionally commits each deliverable to a git-backed audit log, creating an immutable chain of evidence from initial code analysis through final reporting.

Can I customize the deliverables generated during the vulnerability analysis phases?

Yes. You can override the LLM prompt templates in src/prompts/*.txt to modify how Shannon analyzes vulnerabilities and structures its deliverables. Additionally, the [configs/config-schema.json](https://github.com/KeygraphHQ/shannon/blob/main/configs/config-schema.json) allows you to define which phases execute, effectively controlling which deliverable types are generated during an assessment.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →