🔧 Công cụ lập trình•Mã nguồn mở•Đang hoạt động

Shannon

AI pentester white-box cho web apps và APIs, phân tích source code rồi chạy exploit thật để chứng minh lỗ hổng trước khi lên production.

#shannon
Danh mục
🔧 Công cụ lập trình
Giá
Mã nguồn mở
GitHub Stars
⭐ 48,532
Ngôn ngữ
TypeScript
License
AGPL-3.0
Ngày thêm
2026-04-07
Tóm tắt từ README GitHub
Shannon 3.0 is live: deeper security code analysis, more thoroughly vetted findings, a rebuilt CLI, native CI/CD, professional PDF reports, and SARIF. Shannon is an autonomous, AI pentester for web applications and APIs. It analyzes your source code, identifies attack paths, and executes real exploits to prove vulnerabilities before they reach production. No exploit, no report. This repository is Shannon Open Source: the full agent, run locally from your command line. Launch Shannon The interactive launcher will guide you through setup and your first pentest. ---        --- AI agents and LLMs: start with llms.txt for a concise map of this repository, or use llms-full.txt for the README and docs combined into one file. Table of Contents - Table of Contents - What is Shannon? - Why Shannon Exists - Why "Shannon"? - Not a replacement for human pentesters - Shannon in Action - Quick Start - Prerequisites - Run Shannon - Key Capabilities - CI/CD Integrations - GitHub Actions - Editions - Architecture - Documentation - Safety, Scope, and Limitations - License - Acknowledgements - About Keygraph - Community and Support - Common
Xem thêm từ README.md

Đánh giá chi tiết

Tổng quan

Shannon là một AI pentester white-box cho web applications và APIs. Nói gọn là tool này đọc source code, tìm attack surface, rồi tự chạy các exploit thật để chứng minh lỗ hổng thay vì chỉ dừng ở mức cảnh báo lý thuyết.

Điểm mạnh nhất của Shannon là nó kết hợp code-aware analysis với dynamic exploitation. Kết quả cuối chỉ giữ lại những lỗi có proof-of-concept thực sự chạy được. Với đội sản phẩm ship liên tục, kiểu tiếp cận này thực tế hơn nhiều so với việc chờ pentest thủ công theo quý hoặc theo năm.

Tính năng chính

  • Phân tích source code để tìm attack vectors rồi khai thác trực tiếp trên app đang chạy
  • Chỉ report các lỗ hổng có exploit thành công, giảm noise kiểu false positive đẹp mà vô dụng
  • Cover nhiều nhóm lỗi như injection, XSS, SSRF, broken auth và authorization issues
  • Tận dụng browser automation cùng các tool như Nmap, WhatWeb, Schemathesis trong pipeline pentest
  • Hỗ trợ chạy bằng npx hoặc build từ source, có workspace để resume scan dang dở

Ai nên dùng

Hợp với team AppSec, developer platform, hoặc đội engineering muốn bổ sung một lớp pentest tự động cho ứng dụng web trước khi release.

Hạn chế

  • Đây là white-box pentester, nên cần access vào source code và repo layout
  • Workflow khá nặng, phụ thuộc Docker, Node.js và AI provider credentials
  • Shannon Lite dùng AGPL-3.0, nên cần để ý kỹ nếu định tích hợp sâu vào môi trường thương mại
Shannon | Atlas for AI