Shannon

Autonomous white-box AI pentester for web apps and APIs, built on the Claude Agent SDK. Point it at your source code + app URL, it maps attack surface, executes real exploits via browser automation, and only reports findings with a reproducible proof-of-concept. Five phases: pre-recon, recon, analysis, exploitation, reporting. Targets injection, XSS, SSRF, and auth bypass.

Strengths

Limitations

Best for

Official site

View on Coeurdar