Prove web vulnerabilities before they reach production.
application security
Produces proof-backed vulnerability findings for web apps and APIs by analyzing source code and executing real exploits.
When to use it
Use for white-box pentests, security audits, or vulnerability scans of web applications and APIs.
Give it a target URL and source project; after authorization and launch confirmations, it saves a pentest report and presents a summary.
What you provide
This skill
Anthropic API
Sends paid prompts to Anthropic (irreversible)
target application
Attacks the target application
Shannon repository on GitHub
Fetches Shannon from GitHub
Shannon
Mutable Shannon code
Docker must be installed because Shannon runs its attack tools in containers.
Requires access to one supported provider: Anthropic API or OAuth, AWS Bedrock, or Google Vertex AI.
Reads the primary direct Anthropic API key from the environment; it is one alternative authentication path.
Reads an Anthropic OAuth token from the environment as an alternative to the direct API key.