Shannon Pentest Phases Deliverables: A Complete Guide to the Five-Stage Security Assessment Workflow
Shannon generates structured markdown reports and JSON exploitation queues for each pentest phase, mapping deliverable types like CODE_ANALYSIS, RECON, and XSS_ANALYSIS to specific output files that create an auditable chain from initial code review to final executive reporting.
Shannon is an open-source automated penetration testing framework that orchestrates security assessments through a deterministic five-phase pipeline. Each phase consumes the deliverables of the previous stage and produces standardized outputs—both human-readable markdown reports and machine-readable JSON queues—that feed sequentially into vulnerability analysis, exploitation, and final reporting.
Phase 1: Pre-Reconnaissance and Code Analysis
The pre-recon phase performs static analysis of the target codebase to establish a foundational understanding of the application architecture before dynamic testing begins.
Primary Deliverable: CODE_ANALYSIS
Output File: code_analysis_deliverable.md
According to the implementation in [src/phases/pre-recon.ts](https://github.com/KeygraphHQ/shannon/blob/main/src/phases/pre-recon.ts), this phase analyzes repository structure, identifies entry points, maps technology stacks, and documents high-risk code patterns. The deliverable is saved via the save_deliverable MCP tool with the type string CODE_ANALYSIS, creating a markdown report that feeds directly into the reconnaissance phase.
Phase 2: Reconnaissance
The recon phase consumes the code analysis deliverable to perform dynamic application mapping and threat modeling.
Primary Deliverable: RECON
Output File: recon_deliverable.md
As implemented in [src/phases/recon.ts](https://github.com/KeygraphHQ/shannon/blob/main/src/phases/recon.ts), this phase parses the pre-recon data to generate an endpoint inventory, catalog input vectors (parameters, headers, cookies), and produce a threat model. The RECON deliverable type creates a comprehensive markdown report that serves as the input source for all subsequent vulnerability analysis sub-phases.
Phase 3: Vulnerability Analysis
The vulnerability-analysis phase is subdivided into specialized security domains, each producing dual deliverables: a markdown analysis report and a JSON exploitation queue.
Injection Analysis
Deliverable Type: INJECTION_ANALYSIS
Output Files: injection_analysis_deliverable.md, injection_exploitation_queue.json
The [src/phases/injection.ts](https://github.com/KeygraphHQ/shannon/blob/main/src/phases/injection.ts) module analyzes the recon deliverable for SQL injection and command injection vectors. It outputs a markdown vulnerability report and a structured JSON queue containing confirmed injection points ready for exploitation testing.
Cross-Site Scripting (XSS) Analysis
Deliverable Type: XSS_ANALYSIS
Output Files: xss_analysis_deliverable.md, xss_exploitation_queue.json
Implemented in [src/phases/xss.ts](https://github.com/KeygraphHQ/shannon/blob/main/src/phases/xss.ts), this phase identifies reflected, stored, and DOM-based XSS vulnerabilities. The deliverable includes a detailed analysis markdown file and a JSON exploitation queue mapping vulnerable endpoints to payload strategies.
Server-Side Request Forgery (SSRF) Analysis
Deliverable Type: SSRF_ANALYSIS
Output Files: ssrf_analysis_deliverable.md, ssrf_exploitation_queue.json
The [src/phases/ssrf.ts](https://github.com/KeygraphHQ/shannon/blob/main/src/phases/ssrf.ts) module detects SSRF vulnerabilities in URL parameters and request headers. It produces a markdown analysis and a JSON queue for internal network probing and cloud metadata extraction attempts.
Authentication Analysis
Deliverable Type: AUTH_ANALYSIS
Output Files: auth_analysis_deliverable.md, auth_exploitation_queue.json
As defined in [src/phases/auth.ts](https://github.com/KeygraphHQ/shannon/blob/main/src/phases/auth.ts), this phase evaluates session management, credential handling, and multi-factor authentication implementations. The deliverable includes vulnerability findings and a JSON queue for authentication bypass testing.
Authorization Analysis
Deliverable Type: AUTHZ_ANALYSIS
Output Files: authz_analysis_deliverable.md, authz_exploitation_queue.json
The [src/phases/authz.ts](https://github.com/KeygraphHQ/shannon/blob/main/src/phases/authz.ts) module analyzes role-based access control (RBAC) and horizontal/vertical privilege escalation vectors. It outputs an authorization architecture report and a JSON exploitation queue for privilege escalation testing.
Phase 4: Exploitation
The exploitation phase consumes the JSON exploitation queues generated during vulnerability analysis to perform automated or semi-automated proof-of-concept validation.
Input: *_exploitation_queue.json files (injection, XSS, SSRF, auth, authz)
Output: *_evidence.md files containing confirmed vulnerability evidence, payload details, and risk ratings.
According to the utility modules in [src/utils/output-formatter.ts](https://github.com/KeygraphHQ/shannon/blob/main/src/utils/output-formatter.ts), exploitation agents read the structured JSON queues, execute targeted attacks against the identified vectors, and generate markdown evidence files that document successful exploits with screenshots, request/response pairs, and reproduction steps.
Phase 5: Reporting
The reporting phase consolidates all previous deliverables into a comprehensive security assessment report suitable for executive stakeholders and technical remediation teams.
Primary Deliverable: COMPREHENSIVE_SECURITY_ASSESSMENT
Output File: comprehensive_security_assessment_report.md
As implemented in [src/phases/reporting.ts](https://github.com/KeygraphHQ/shannon/blob/main/src/phases/reporting.ts), this phase aggregates the code analysis, reconnaissance data, vulnerability findings, exploitation evidence, and risk ratings into a polished markdown report. The deliverable includes executive summaries, technical vulnerability details, CVSS scores, and prioritized remediation guidance. Sample outputs are available in [sample-reports/shannon-report-juice-shop.md](https://github.com/KeygraphHQ/shannon/blob/main/sample-reports/shannon-report-juice-shop.md).
Running Shannon: Practical Examples
CLI Execution
Run a complete five-phase assessment using the Shannon CLI:
# Execute full pipeline against a local target
shannon run \
--target http://localhost:8080 \
--config ./configs/example-config.yaml \
--output ./audit-logs
Configuration File
Define your assessment scope using a YAML configuration validated against [configs/config-schema.json](https://github.com/KeygraphHQ/shannon/blob/main/configs/config-schema.json):
target: http://localhost:8080
phases:
- pre-recon
- recon
- injection
- xss
- ssrf
- auth
- authz
- reporting
output_dir: ./deliverables
git_integration: true
Programmatic Integration
Invoke Shannon programmatically from a TypeScript application:
import { Shannon } from './src/cli/ui';
const shannon = new Shannon({
target: 'http://localhost:8080',
configPath: './configs/example-config.yaml',
outputDir: './audit-logs',
enableGitLog: true
});
// Execute all phases sequentially
await shannon.execute();
Customizing Prompt Templates
Override default prompt templates by replacing files in the prompt library:
# Replace the reconnaissance prompt with custom logic
cp my-custom-recon-prompt.txt src/prompts/recon.txt
# Run assessment with custom prompt
shannon run --target http://example.com
Key Files Reference
Summary
- Shannon pentest phases deliverables follow a strict pipeline:
CODE_ANALYSIS→RECON→ vulnerability-specific analyses (INJECTION_ANALYSIS,XSS_ANALYSIS, etc.) → exploitation evidence → comprehensive final report. - Each vulnerability analysis phase produces dual deliverables: a human-readable markdown analysis (
*_analysis_deliverable.md) and a machine-readable JSON exploitation queue (*_exploitation_queue.json). - The
save_deliverableMCP tool persists all outputs using standardizeddeliverable_typestrings, ensuring consistent formatting across the assessment lifecycle. - Final reporting consolidates all phase outputs into a single
comprehensive_security_assessment_report.mdsuitable for executive stakeholders and remediation teams.
Frequently Asked Questions
What file formats does Shannon generate for each pentest phase?
Shannon generates markdown files for human-readable reports and JSON files for machine-readable exploitation queues. Each vulnerability analysis phase produces both formats: for example, xss_analysis_deliverable.md contains the detailed findings, while xss_exploitation_queue.json provides structured data for the exploitation phase to execute proof-of-concept attacks.
How does Shannon ensure deliverables are preserved across pipeline stages?
Shannon uses the save_deliverable MCP tool with standardized deliverable_type strings (such as CODE_ANALYSIS, RECON, and AUTHZ_ANALYSIS) to persist outputs. The [src/utils/git-manager.ts](https://github.com/KeygraphHQ/shannon/blob/main/src/utils/git-manager.ts) module optionally commits each deliverable to a git-backed audit log, creating an immutable chain of evidence from initial code analysis through final reporting.
Can I customize the deliverables generated during the vulnerability analysis phases?
Yes. You can override the LLM prompt templates in src/prompts/*.txt to modify how Shannon analyzes vulnerabilities and structures its deliverables. Additionally, the [configs/config-schema.json](https://github.com/KeygraphHQ/shannon/blob/main/configs/config-schema.json) allows you to define which phases execute, effectively controlling which deliverable types are generated during an assessment.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →