KeygraphHQ/shannon
- Source
- GitHub
- First trending
- Category
- Security
- GitHub stars
- 48,073
- Main language
- TypeScript
This page introduces an external open-source repository. It is not an HDATF product.

What it does
An AI agent that tests web applications and APIs for security flaws. It reads the source code, finds attack paths and runs real exploits, reporting only vulnerabilities it can prove, with CI/CD runs and SARIF output.
How it helps ATF
Its rule of reporting only what an exploit proves is a reference for how Harness checks results with evidence. It is also worth comparing as a security testing approach for web software like ATF Works.
License
AGPL-3.0 Network copyleft. Offering a modified version as a service also requires releasing the source. Review before any product use.
More in this category
- QuipNetwork/hashsigs-rs
A Rust workspace of hash-based post-quantum signature schemes, including WOTS+, SPHINCS+C and the hybrid SHRINCS signer and verifier. It also includes WebAssembly bindings and a verify-only Solana program. - pydantic/monty
A sandboxed Python interpreter written in Rust for running AI-written code without a container or VM. Code reaches the host only through functions and mounts passed in, and the interpreter enforces memory, time and recursion limits. - vxcontrol/pentagi
An autonomous AI agent system that carries out penetration testing tasks. It works with several LLM providers and includes agent supervision, Langfuse integration and a Graphiti knowledge graph. - lissy93/web-check
Web-Check is a dashboard that gathers public information about a website, such as IP details, SSL chain, DNS records, cookies, headers, open ports, trackers and redirects. It can be self-hosted, for example with Docker. - promptfoo/promptfoo
A CLI and library for evaluating and red-teaming LLM apps. It tests prompts, agents and RAG setups, compares models side by side, scans for vulnerabilities and runs checks in CI/CD from declarative configs.
Only repositories in the ranked Trendshift lists are included, and the lists are used only to find candidates. We do not copy their ranks. Descriptions, licenses and star counts come from each GitHub repository. The notes are our own reading. We have not tested these projects, and a place on a trending list does not prove quality.