# Shannon

> AI pentester for your web apps and APIs

Reads your source code, finds attack paths and runs real exploits against your own app to prove vulnerabilities before release.

- Source: https://github.com/KeygraphHQ/shannon
- Homepage: https://keygraph.io/
- License: AGPL-3.0
- Language: TypeScript
- Stars: 48559
- Forks: 5563
- Contributors: 9
- Last commit: 2026-09-30
- Latest release: v3.3.0 (2026-09-21)
- Purpose: AI & LLM tooling, Security & identity, Agents & frameworks
- Runs on: Docker / self-host, CLI
- For: Enterprise

## Worth score: 80/100

How much DigGitHub recommends it, from activity, adoption, docs, license and security signals.

- Popularity: 23/25
- Momentum: 10/20
- Maintenance: 25/25
- Community: 10/15
- Readiness: 12/15

## Alternatives

- [Strix](https://diggithub.com/usestrix/strix.md): AI agents that pentest your own apps
- [NemoClaw](https://diggithub.com/NVIDIA/NemoClaw.md): Run agents more securely in NVIDIA OpenShell
- [OpenClaw](https://diggithub.com/openclaw/openclaw.md): Personal AI assistant that acts on your behalf across apps
- [nanobot](https://diggithub.com/HKUDS/nanobot.md): Ultra-light self-hosted personal AI agent
- [Hermes Agent](https://diggithub.com/NousResearch/hermes-agent.md): Self-improving personal agent from Nous Research
- [Paperclip](https://diggithub.com/paperclipai/paperclip.md): Manage teams of AI agents at work
- [ZeroClaw](https://diggithub.com/zeroclaw-labs/zeroclaw.md): Small, fast autonomous assistant infrastructure
- [QwenPaw](https://diggithub.com/agentscope-ai/QwenPaw.md): Personal AI assistant you can self-host

---

Source page: https://diggithub.com/KeygraphHQ/shannon
Updated: 2026-10-04
