Get reproducible exploits and an actionable audit report.
application security
Finds confirmed web application and API vulnerabilities through source analysis and live exploit execution, then produces reproducible proofs of concept.
When to use it
Use it to pentest a web application or API, find vulnerabilities, or generate a security audit report.
Give it a running application URL and its source-code project; it writes the pentest report, findings, and logs into a workspace.
What you provide
This skill
live running application
Sends live exploit requests
Shannon
Installs Shannon from GitHub
Shannon containers
Starts Shannon in background
Docker is required because Shannon runs entirely in containers.
The target web application or API must be running and reachable for live testing.
An Anthropic account is one supported authentication alternative.
A Claude Code account is one supported authentication alternative.