档案库 · 开发与企业工具 · 产品决策 · 2025–2026
Keygraph开源AI渗透测试工具Shannon,一年收获47k GitHub星标
Keygraph押注LLM代理能让渗透测试从年度仪式变成按需命令——然后开源了整个代理来证明这一点。
Keygraph (KeygraphHQ)
做的是什么生意
Shannon is an autonomous AI pentester: it analyzes a web app's source code, attacks the running app with browser automation, and reports only confirmed exploits.
起因
Keygraph, a US AppSec startup, built Shannon as the agent inside its commercial pentesting platform. On 2025-09-27 it open-sourced the full agent under AGPL-3.0, betting that developers would trust a tool whose reports prove every finding with a working exploit, and that the trust would backfill its paid Shannon Pro platform.
经过
The repo went viral: 44k+ stars within its first months, 5.5k forks, Trendshift-tracked. In Dec 2025 gbhackers detailed it finding 20+ critical vulnerabilities in one OWASP Juice Shop run and 15 in the Checkmarx Capital API. In Feb 2026 Cisco Talos discussed the hype wave and warned about the trade-off of feeding private source code and API keys to an agentic engine. Shannon 3.0 later added native CI/CD workflows (GitHub Actions, GitLab CI), SARIF output, PDF reports, and provider-agnostic model support including self-hosted endpoints.
还没有结局,它还在跑。
背景
美国AppSec初创公司Keygraph抓住了一个容易被忽视的事实:软件安全测试的规模与发布规模背道而驰——团队每天部署几十个版本,而渗透测试一年才一次。2025年9月27日,它在AGPL-3.0下开源了Shannon,这是其商业平台背后的代理。Shannon读取目标应用的源码来绘制攻击面,然后用内置浏览器执行真实的漏洞利用——注入、认证绕过、SSRF——并且拒绝报告任何它无法复现的东西。
这次押注是:开源的代理本身就是市场宣传。仓库中发布的基准声称在一次针对OWASP Juice Shop的自动运行中发现了20多个关键漏洞,对Checkmarx Capital API发现了15个。到2025年12月,gbhackers报道了该工具;到2026年2月,Cisco Talos的Threat Source通讯报道了这波热炒及其引发的隐私问题:Shannon需要源代码、仓库布局和AI API密钥,因此组织必须权衡它们向代理引擎提供了什么。
数据支持这一策略:发布几个月内就有44k+星标(据keygraph.io),到2026年9月有47.6k星标和5.5k分支(GitHub API)。这个开源项目现在支撑着一个'持续代理化渗透测试'平台,提供白盒/黑盒渗透测试、代理化SAST、SCA和密钥扫描,并为早期初创公司和非营利组织提供免费层。
这件事要成立,得有什么
- '没有漏洞利用,就没有报告'反转了扫描器问题:Shannon只报告它验证过的内容,这使得产品值得信赖。
- AGPL下的开源让安全社区可以审计这个工具;在AppSec中,信任就是货币。
- GitHub上的病毒式采用成了漏斗:每一个星标开发者都是商业平台的合格线索。
- Anthropic和OpenAI的网络防护要求造成了竞争对手没有的准入成本,拓宽了护城河。
可借鉴之处
把核心产品作为开源发布可以成为最便宜的渠道:仓库成了演示,反哺付费平台。
后续进展
截至2026年9月3日,Shannon已上线;Keygraph销售持续代理化渗透测试,发现通过Jira路由、SLA策略和自动修复PR,并为早期初创公司和非营利组织提供免费访问。Shannon 3.0增加了CI/CD工作流、SARIF报告和自带模型支持,所以GitHub星星起到了公开演示的作用。没有确认融资;该公司总部在美国,通过keygraph.io运营。
资料来源
- Shannon: AI Pentesting Tool That Autonomously Identifies and Exploits Code Vulnerabilities
- Hand over the keys for Shannon's shenanigans
- KeygraphHQ/shannon
发现哪里写错了?告诉我们。
轮到你了
你刚读完一家。说说你在做什么,看看谁在赌同一件事。
免费账号 · 3 次免费提问 · 不用绑卡