Shannon
Autonomous white-box AI pentester for web apps and APIs, built on the Claude Agent SDK. Point it at your source code + app URL, it maps attack surface, executes real exploits via browser automation, and only reports findings with a reproducible proof-of-concept. Five phases: pre-recon, recon, analysis, exploitation, reporting. Targets injection, XSS, SSRF, and auth bypass.
Strengths
- 96.15% success on XBOW Benchmark hint-free source-aware (100/104 validated exploits)
- White-box approach, Shannon reads your source code in addition to runtime, deepening analysis quality
- Browser automation validation: no report without an executable proof-of-concept
- Built on Claude Agent SDK, multi-tier Claude Sonnet agents for recon/analysis/exploitation
Limitations
- $50 per run on Claude Sonnet 3.5, not negligible if you run it across multiple apps
- Strong legal surface, only use on environments you own or under authorized bug bounty
- AGPL-3.0 on Lite: if you integrate Shannon in a SaaS offering, you must publish your fork
- CI/CD integration and SAST/SCA features reserved for Shannon Pro (commercial)
Best for
- Security teams who want an autonomous second-read agent on their own stack
- Bug bounty hunters who want to automate the recon + exploitation phase
- White-box code review, Shannon reads your repo in addition to scanning runtime