The archive · Developer & Business Tools · Product decision · 2025–2026
Keygraph open-sources Shannon, an AI pentester; 47k GitHub stars in a year
Keygraph bet LLM agents could make pentesting an on-demand command instead of a yearly ritual — then open-sourced the whole agent to prove it.
Keygraph (KeygraphHQ)
What the business is
Shannon is an autonomous AI pentester: it analyzes a web app's source code, attacks the running app with browser automation, and reports only confirmed exploits.
How it started
Keygraph, a US AppSec startup, built Shannon as the agent inside its commercial pentesting platform. On 2025-09-27 it open-sourced the full agent under AGPL-3.0, betting that developers would trust a tool whose reports prove every finding with a working exploit, and that the trust would backfill its paid Shannon Pro platform.
What happened
The repo went viral: 44k+ stars within its first months, 5.5k forks, Trendshift-tracked. In Dec 2025 gbhackers detailed it finding 20+ critical vulnerabilities in one OWASP Juice Shop run and 15 in the Checkmarx Capital API. In Feb 2026 Cisco Talos discussed the hype wave and warned about the trade-off of feeding private source code and API keys to an agentic engine. Shannon 3.0 later added native CI/CD workflows (GitHub Actions, GitLab CI), SARIF output, PDF reports, and provider-agnostic model support including self-hosted endpoints.
No ending yet — it is still running.
Background
Keygraph, a US AppSec startup, pressed the easy-to-miss fact that software security testing scales opposite to shipping: teams deploy dozens of builds a day while penetration tests happen once a year. On 2025-09-27 it open-sourced Shannon, the agent that powers its commercial platform, under AGPL-3.0. Shannon reads the target application's source code to map attack surfaces, then uses a built-in browser to execute real exploits — injection, auth bypass, SSRF — and refuses to report anything it could not reproduce.
The bet was that the open-source agent itself would be the marketing. Benchmarks published in the repo claim 20+ critical vulnerabilities found in a single automated run against OWASP Juice Shop and 15 against the Checkmarx Capital API. By December 2025 gbhackers profiled the tool; by February 2026 Cisco Talos' Threat Source newsletter covered the hype and the privacy questions it raises: Shannon needs source code, repo layout and AI API keys, so organizations must weigh what they feed an agentic engine.
The numbers supported the strategy: 44k+ stars within months of launch (per keygraph.io), 47.6k stars and 5.5k forks by September 2026 (GitHub API). The open-source project now feeds a 'continuous agentic pentesting' platform with whitebox/blackbox pentests, agentic SAST, SCA and secrets scanning, plus a free tier for early-stage startups and nonprofits.
What has to be true
- 'No exploit, no report' inverted the scanner problem: Shannon only reports what it proved, making the product credible.
- Open-sourcing under AGPL made the tool auditable by the security community it courts; trust is currency in AppSec.
- Viral GitHub adoption was the funnel: every starred developer is a qualified lead for the commercial platform.
- Anthropic's and OpenAI's cyber-safeguard requirements created an onboarding tax competitors lacked, widening the moat.
What can be applied
Shipping the core product as open source can be the cheapest distribution channel: the repo becomes the demo that backfills a paid platform.
Aftermath
As of 2026-09-03 Shannon is live; Keygraph sells continuous agentic pentesting with findings routed to Jira, SLA policies, and automated remediation PRs, and gives early-stage startups and nonprofits free access. Shannon 3.0 added CI/CD workflows, SARIF reports, and bring-your-own-model support, so GitHub stars serve as a public demo. No funding is confirmed; the company is US-based via keygraph.io.
Sources
- Shannon: AI Pentesting Tool That Autonomously Identifies and Exploits Code Vulnerabilities
- Hand over the keys for Shannon's shenanigans
- KeygraphHQ/shannon
spotted an error? The archive wants to know.
Your turn
You just read one. Describe what you are building, and see who is betting on the same thing.
Free account · 3 free questions · no card