Skip to content
@KeygraphHQ

Keygraph

Open source AI Pentester, part of the broader AppSec platform (Shannon Pro)
Shannon: AI Pentester for Web Applications and APIs

We build Shannon, an open source AI pentester for web applications and APIs.

Join Discord Visit Keygraph.io


How Shannon works

Shannon analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities, not flag theoretical risks. It combines static code review with dynamic exploitation across four phases: reconnaissance, parallel vulnerability analysis, parallel exploitation, and reporting.

It targets injection, XSS, SSRF, and broken authentication/authorization, validating every finding with a reproducible proof-of-concept. If it can't exploit it, it doesn't report it.

Get started


Get involved


About the company

Keygraph is a security and compliance platform for modern engineering teams, covering application security and compliance automation. Shannon is the AppSec layer.

Shannon Lite (this repo) is the open source core. Shannon Pro is the full all-in-one AppSec platform that extends it with agentic SAST, SCA with reachability analysis, secrets detection, business logic testing, and CI/CD integration.

keygraph.io

Pinned Loading

  1. shannon shannon Public

    Shannon Lite is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities bef…

    TypeScript 34k 3.4k

Repositories

Showing 6 of 6 repositories

People

This organization has no public members. You must be a member to see who’s a part of this organization.

Top languages

Loading…

Most used topics

Loading…