Skip to content
@KeygraphHQ

Keygraph

Open source AI Pentester, part of the broader AppSec platform (Shannon Pro)
Shannon: AI Pentester for Web Applications and APIs

We build Shannon, an open source AI pentester for web applications and APIs.

Join Discord Visit Keygraph.io


How Shannon works

Shannon analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities, not flag theoretical risks. It combines static code review with dynamic exploitation across four phases: reconnaissance, parallel vulnerability analysis, parallel exploitation, and reporting.

It targets injection, XSS, SSRF, and broken authentication/authorization, validating every finding with a reproducible proof-of-concept. If it can't exploit it, it doesn't report it.

Get started


Get involved


About the company

Keygraph is a security and compliance platform for modern engineering teams, covering application security and compliance automation. Shannon is the AppSec layer.

Shannon Lite (this repo) is the open source core. Shannon Pro is the full all-in-one AppSec platform that extends it with agentic SAST, SCA with reachability analysis, secrets detection, business logic testing, and CI/CD integration.

keygraph.io

Pinned Loading

  1. shannon shannon Public

    Shannon Lite is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities bef…

    TypeScript 34.3k 3.5k

Repositories

Showing 6 of 6 repositories
  • shannon Public

    Shannon Lite is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities before they reach production.

    KeygraphHQ/shannon’s past year of commit activity
    TypeScript 34,338 AGPL-3.0 3,458 10 12 Updated Mar 22, 2026
  • .github Public
    KeygraphHQ/.github’s past year of commit activity
    0 0 0 0 Updated Mar 18, 2026
  • KeygraphHQ/xbow-validation-benchmarks’s past year of commit activity
    PHP 24 Apache-2.0 5 0 0 Updated Feb 14, 2026
  • hipaa-baa-tax Public

    HIPAA (BAA) Tax

    KeygraphHQ/hipaa-baa-tax’s past year of commit activity
    HTML 3 Apache-2.0 1 0 0 Updated Dec 4, 2025
  • KeygraphHQ/validation-benchmarks’s past year of commit activity
    PHP 0 Apache-2.0 1 0 0 Updated Oct 31, 2025
  • juice-shop Public Forked from juice-shop/juice-shop

    OWASP Juice Shop: Probably the most modern and sophisticated insecure web application

    KeygraphHQ/juice-shop’s past year of commit activity
    TypeScript 10 MIT 17,084 0 2 Updated Oct 7, 2025

People

This organization has no public members. You must be a member to see who’s a part of this organization.

Most used topics

Loading…