{"id":45903420,"url":"https://github.com/pitimon/shannon-pentest","last_synced_at":"2026-05-12T00:00:28.931Z","repository":{"id":341091988,"uuid":"1168497546","full_name":"pitimon/shannon-pentest","owner":"pitimon","description":"Claude Code plugin to orchestrate Shannon autonomous pentester — configure, launch, monitor, and analyze security assessments with bilingual Thai+English output","archived":false,"fork":false,"pushed_at":"2026-05-11T22:00:47.000Z","size":312,"stargazers_count":1,"open_issues_count":6,"forks_count":1,"subscribers_count":1,"default_branch":"main","last_synced_at":"2026-05-12T00:00:15.224Z","etag":null,"topics":["autonomous-security","bug-bounty","claude-code-plugin","owasp","penetration-testing","pentest","security-audit","shannon","vulnerability-scanner","web-security"],"latest_commit_sha":null,"homepage":"https://github.com/KeygraphHQ/shannon","language":"Shell","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/pitimon.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.md","contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2026-02-27T13:10:41.000Z","updated_at":"2026-05-11T22:00:31.000Z","dependencies_parsed_at":null,"dependency_job_id":null,"html_url":"https://github.com/pitimon/shannon-pentest","commit_stats":null,"previous_names":["pitimon/shannon-pentest"],"tags_count":20,"template":false,"template_full_name":null,"purl":"pkg:github/pitimon/shannon-pentest","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/pitimon%2Fshannon-pentest","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/pitimon%2Fshannon-pentest/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/pitimon%2Fshannon-pentest/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/pitimon%2Fshannon-pentest/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/pitimon","download_url":"https://codeload.github.com/pitimon/shannon-pentest/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/pitimon%2Fshannon-pentest/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":32917885,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-05-11T17:09:15.040Z","status":"ssl_error","status_checked_at":"2026-05-11T17:08:45.420Z","response_time":120,"last_error":"SSL_connect returned=1 errno=0 peeraddr=140.82.121.5:443 state=error: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["autonomous-security","bug-bounty","claude-code-plugin","owasp","penetration-testing","pentest","security-audit","shannon","vulnerability-scanner","web-security"],"created_at":"2026-02-28T00:56:10.370Z","updated_at":"2026-05-12T00:00:28.922Z","avatar_url":"https://github.com/pitimon.png","language":"Shell","funding_links":[],"categories":[],"sub_categories":[],"readme":"# Shannon Pentest — Claude Code Plugin\n\n[![Version](https://img.shields.io/badge/version-3.7.2-blue.svg)](CHANGELOG.md)\n[![Validation](https://github.com/pitimon/shannon-pentest/actions/workflows/validate.yml/badge.svg)](https://github.com/pitimon/shannon-pentest/actions/workflows/validate.yml)\n[![License: MIT](https://img.shields.io/badge/License-MIT-green.svg)](LICENSE)\n[![Plugin](https://img.shields.io/badge/Claude%20Code-Plugin-8A2BE2.svg)](https://github.com/pitimon/shannon-pentest)\n\n**Orchestrate autonomous penetration testing from Claude Code** — describe your target in plain language, and Shannon handles the rest: configuration, launch, monitoring, and findings analysis with bilingual Thai+English output.\n\n### Why Shannon?\n\n| Problem                                         | Shannon's Solution                                                          |\n| ----------------------------------------------- | --------------------------------------------------------------------------- |\n| Manual pentest setup takes hours of config      | **Natural language** — just say \"pentest my staging app\"                    |\n| Missed vulnerability classes from narrow scopes | **9 parallel agents** — XSS, SQLi, SSRF, auth bypass, and more              |\n| Reports require security expertise to interpret | **Auto-analysis** with CVSS v4.0, OWASP Top 10, MITRE ATT\u0026CK mapping        |\n| Tool context-switching slows you down           | **Stays in Claude Code** — configure, launch, monitor, analyze in one place |\n| Repeated scans waste API budget                 | **v1.2.0 optimizations** — 17.7% cheaper with smarter pre-recon             |\n\n---\n\n## Proven Results\n\n\u003e Real metrics from QA testing on a live WordPress target (v1.2.0):\n\n| Metric             | Value                                               |\n| ------------------ | --------------------------------------------------- |\n| Total duration     | **81.4 minutes**                                    |\n| Total cost         | **$18.71**                                          |\n| Pre-recon savings  | **76% cheaper** vs previous version                 |\n| Config validation  | **First-try success** (3-step pre-validation)       |\n| Findings           | **6 confirmed vulnerabilities** across 3 categories |\n| Agent success rate | **9/9 agents** completed                            |\n\n---\n\n## Quick Start\n\n```bash\n# 1. Install the plugin\nclaude plugin marketplace add pitimon/shannon-pentest\nclaude plugin install shannon-pentest@pitimon-shannon\n\n# 2. Launch a pentest (just describe your target)\n```\n\nThen in Claude Code:\n\n```\n\"pentest my web app at https://staging.example.com\"\n```\n\nShannon walks you through target configuration, launches the scan, monitors progress automatically, and delivers a structured findings report — all within your Claude Code session.\n\n---\n\n## How It Works\n\n```\nPhase 0        Phase 1         Phase 2          Phase 3          Phase 4            Phase 4.5        Phase 5\n Setup    →    Configure   →    Launch     →    Monitor     →    Analyze       →    Inline      →    Handoff\n Docker        Target URL       Config           Auto-poll        Parallel           Defense          Defensive\n Shannon       Auth type        validation       every 2-5min     Read calls         IR checklist     docs prompt\n API key       YAML config      Pre-flight       Stall detect     CVSS/OWASP         Remediation      Clipboard\n (auto)        Web-only         Safety confirm   Auto-transition  PDF/SARIF/HTML     Compliance       copy\n               detection        ./shannon start  → Phase 4        Finding tags       quick-map        → cyber-pro\n```\n\n| Phase            | What happens                                                                                                |\n| ---------------- | ----------------------------------------------------------------------------------------------------------- |\n| **0. Setup**     | Verify Docker \u0026 Shannon, auto-configure API key from your Claude Code session                               |\n| **1. Configure** | You provide a target URL and auth type → plugin generates YAML config with smart target-type detection      |\n| **2. Launch**    | Config pre-validation (YAML/schema/types) → pre-flight checks → safety confirmation → `./shannon start`     |\n| **3. Monitor**   | Auto-poll every 2-5 min, stall detection at 10 min, auto-transition when scan completes                     |\n| **4. Analyze**   | Parallel read → severity summary, CVSS v4.0, OWASP Top 10, PDF/SARIF/HTML export, finding lifecycle tags    |\n| **4.5. Defense** | Inline IR checklist, per-finding remediation skeleton, OWASP/NIST compliance quick-map (no plugin needed)   |\n| **5. Handoff**   | Pre-generate cybersecurity-pro prompt, clipboard copy, structured manifest for full defensive documentation |\n\n---\n\n## Usage Examples\n\n### Natural Language\n\nType `/shannon-pentest` or ask naturally:\n\n```\n\"pentest my web app at https://staging.example.com\"\n\"run Shannon against the staging environment\"\n\"security audit my application\"\n\"ทดสอบเจาะระบบ staging\"\n\"find vulnerabilities in my app\"\n```\n\n### Direct Routing\n\nSkip to a specific phase or reference:\n\n```\n\"analyze Shannon report\"           → Phase 4 (report analysis)\n\"export Shannon report as PDF\"     → Multi-format export (PDF/SARIF/HTML)\n\"generate SARIF from findings\"     → SARIF export for GitHub Security tab\n\"tag finding as false positive\"    → Finding lifecycle (status tagging)\n\"show remediation status\"          → Remediation status report\n\"list Shannon workspaces\"          → CLI workspace manager\n\"inline defense from findings\"     → Phase 4.5 (IR checklist + remediation)\n\"create tickets from findings\"     → Issue template generation (GitHub/Jira)\n\"export SARIF report\"              → SARIF export for GitHub Security tab\n\"integrate Shannon with CI/CD\"     → CI/CD pipeline templates\n\"verify fix for stored XSS\"        → Remediation verification (retest)\n\"save this scan config\"            → Scan templates (save/load profiles)\n\"suppress this finding\"            → Finding suppression (whitelist)\n\"correlate findings by root cause\" → Finding correlation (grouping)\n\"calculate risk scores\"            → Risk scoring (CVSS+Exploit+BizImpact)\n\"scan multiple targets\"            → Multi-target campaign (sequential)\n\"generate SOC 2 compliance report\" → Compliance frameworks (7 standards)\n\"show security metrics dashboard\"  → Security metrics (MTTR/density/cost)\n\"assign owner to finding\"          → Team remediation (ownership/SLA)\n\"SLA gating for deployment\"        → CI/CD gating strategies (advanced)\n\"show risk posture score\"          → Executive reporting (risk posture + trends)\n\"import Burp findings\"             → External tool import (Burp/ZAP/Nuclei/SARIF)\n\"set up Slack notifications\"       → Notification hub (webhooks + SLA alerts)\n\"schedule weekly pentest\"          → Scheduled scanning (cron/Actions/systemd)\n\"benchmark this target\"            → Historical benchmarking (trends + forecasting)\n\"generate HTML dashboard\"          → Standalone dashboard (self-contained HTML)\n\"Shannon config for OAuth\"         → Config templates\n\"validate my Shannon config\"       → Config pre-validation\n\"Docker error in Shannon\"          → Troubleshooting guide\n\"check Shannon status\"             → Monitoring with auto-poll\n\"handoff to cybersecurity-pro\"     → Phase 5 (defensive docs prompt)\n\"compare Shannon runs\"             → Session comparison (diff table)\n\"Shannon stats\"                    → Session analytics (cost/duration trends)\n\"set up engagement context\"       → Engagement setup (client/project info)\n```\n\n---\n\n## Configuration\n\nShannon config uses **3 root keys only** (`additionalProperties: false` at root):\n\n| Root Key         | Required | Purpose                                    |\n| ---------------- | -------- | ------------------------------------------ |\n| `authentication` | anyOf    | Login credentials, flow, success condition |\n| `rules`          | anyOf    | Focus/avoid paths for scoping              |\n| `pipeline`       | optional | Retry preset, concurrency limits           |\n\n\u003e `authentication` or `rules` (or both) must be present. Keys like `target:`, `auth:`, `scope:` will cause errors.\n\n### Quick Config (No Auth)\n\n```yaml\nrules:\n  focus:\n    - description: \"Focus on main application\"\n      type: path\n      url_path: \"/\"\n\npipeline:\n  retry_preset: \"subscription\"\n  max_concurrent_pipelines: \"3\"\n```\n\n### Auth Scenarios\n\n| Auth Type            | Config Key                           | Template                       |\n| -------------------- | ------------------------------------ | ------------------------------ |\n| No Auth (public)     | `rules` only                         | `config-templates-basic.md`    |\n| Form-based login     | `authentication` (login_type: form)  | `config-templates-basic.md`    |\n| TOTP / 2FA           | `authentication` (+ totp_secret)     | `config-templates-basic.md`    |\n| SSO (SAML/OIDC)      | `authentication` (login_type: sso)   | `config-templates-advanced.md` |\n| API Key / Basic Auth | `authentication` (login_type: api)   | `config-templates-advanced.md` |\n| Scoped testing       | `rules` (focus + avoid arrays)       | `config-templates-advanced.md` |\n| Local development    | `rules` + `host.docker.internal` URL | `config-templates-advanced.md` |\n\n### Pre-Validation (v1.2.0)\n\nBefore launch, the plugin runs 3-step validation:\n\n1. **YAML syntax** — `yaml.safe_load()` check\n2. **Root key validation** — only `authentication`, `rules`, `pipeline` allowed\n3. **Value type check** — e.g., `max_concurrent_pipelines` must be string `\"3\"` not integer `3`\n\n---\n\n## CLI Quick Reference\n\n```bash\n# Start pentest\n./shannon start URL=\u003curl\u003e REPO=\u003crepo\u003e\n./shannon start URL=\u003curl\u003e REPO=\u003crepo\u003e CONFIG=\u003cpath\u003e WORKSPACE=\u003cname\u003e\n\n# Monitor\n./shannon logs                          # Real-time logs\n./shannon query ID=\u003cworkflow-id\u003e        # Query specific workflow\n./shannon workspaces                    # List all workspaces\n\n# Stop\n./shannon stop                          # Graceful stop\n./shannon stop CLEAN=true               # Stop + cleanup\n./shannon stop WORKSPACE=\u003cname\u003e CLEAN=true\n```\n\n**Temporal UI:** `http://localhost:8233` (accessible after launch)\n\n---\n\n## Performance Optimizations\n\nv1.2.0 optimizations based on empirical testing:\n\n| Optimization             | Before                            | After                        | Impact                 |\n| ------------------------ | --------------------------------- | ---------------------------- | ---------------------- |\n| Smart target detection   | 165+ LLM turns for web-only repos | ~5-10 turns                  | ~3-5 min saved         |\n| Config template split    | ~2,500 tokens loaded always       | ~900 tokens for common cases | 64% token reduction    |\n| Config pre-validation    | Trial-and-error (2-3 attempts)    | Validate before launch       | Zero failed launches   |\n| Active monitoring        | Manual status checks              | Auto-poll every 2-5 min      | 2-3 fewer interactions |\n| Stall detection          | User discovers after 20+ min      | Auto-warn at 10 min          | Faster recovery        |\n| Parallel report analysis | Sequential file reads             | Concurrent Read calls        | Faster Phase 4         |\n\n---\n\n## Setup Guide\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cstrong\u003ePrerequisites\u003c/strong\u003e\u003c/summary\u003e\n\n| Tool               | Version     | Purpose                                                     | Install                                                                |\n| ------------------ | ----------- | ----------------------------------------------------------- | ---------------------------------------------------------------------- |\n| **Docker Desktop** | 24.0+       | Runs Shannon containers (Temporal, workers, browser agents) | [docker.com/get-docker](https://docs.docker.com/get-docker/)           |\n| **Docker Compose** | v2 (plugin) | Orchestrates multi-container Shannon stack                  | Included with Docker Desktop                                           |\n| **Git**            | 2.30+       | Repository management for target source code                | `brew install git` / `apt install git`                                 |\n| **Python 3**       | 3.8+        | Config validation, OAuth token extraction                   | Pre-installed on macOS/Linux                                           |\n| **Claude Code**    | Latest      | Plugin host environment                                     | [claude.ai/claude-code](https://claude.ai/claude-code)                 |\n| **Shannon**        | Latest      | Autonomous pentesting engine                                | [github.com/KeygraphHQ/shannon](https://github.com/KeygraphHQ/shannon) |\n\n### Shannon Installation\n\n```bash\ngit clone https://github.com/KeygraphHQ/shannon.git ~/shannon-tool\ncd ~/shannon-tool\ncp .env.example .env\nchmod +x ./shannon\n```\n\n### API Key Configuration\n\nThe plugin **auto-configures** the API key from your active Claude Code session — no manual setup needed.\n\n```\nClaude Code session → OAuth token → Shannon .env (automatic)\n```\n\nIf auto-detection fails, set an Anthropic API key manually:\n\n```bash\necho 'ANTHROPIC_API_KEY=sk-ant-...' \u003e ~/shannon-tool/.env\n```\n\n\u003c/details\u003e\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cstrong\u003ePre-flight Checklist\u003c/strong\u003e\u003c/summary\u003e\n\nRun these checks before your first pentest:\n\n```bash\n# 1. Docker running?\ndocker info \u003e /dev/null 2\u003e\u00261 \u0026\u0026 echo \"✓ Docker running\" || echo \"✗ Docker not found\"\n\n# 2. Shannon installed?\nSHANNON_DIR=\"${SHANNON_DIR:-$HOME/shannon-tool}\"\nls \"$SHANNON_DIR/shannon\" 2\u003e/dev/null \u0026\u0026 echo \"✓ Shannon found\" || echo \"✗ Not found at $SHANNON_DIR\"\n\n# 3. .env configured?\nls \"$SHANNON_DIR/.env\" 2\u003e/dev/null \u0026\u0026 echo \"✓ .env exists\" || echo \"✗ .env missing\"\n\n# 4. Docker Compose v2?\ndocker compose version \u003e /dev/null 2\u003e\u00261 \u0026\u0026 echo \"✓ Compose v2\" || echo \"✗ Compose not found\"\n\n# 5. Target reachable?\ncurl -s -o /dev/null -w \"✓ Target responded: %{http_code}\" \"https://your-staging.example.com\"\n```\n\n### Platform Notes\n\n| Platform                  | Notes                                                                                                                                 |\n| ------------------------- | ------------------------------------------------------------------------------------------------------------------------------------- |\n| **macOS (Apple Silicon)** | Docker Desktop supports ARM64 natively. `host.docker.internal` works out of the box.                                                  |\n| **Linux**                 | Add user to docker group: `sudo usermod -aG docker $USER`. May need `--add-host=host.docker.internal:host-gateway` for local targets. |\n| **Windows (WSL2)**        | Use WSL2 only. Clone Shannon inside WSL2 filesystem (`/home/user/`), not `/mnt/c/`.                                                   |\n\n\u003c/details\u003e\n\n---\n\n## Troubleshooting\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cstrong\u003eCommon issues and quick fixes\u003c/strong\u003e\u003c/summary\u003e\n\n| Issue                       | Cause                          | Fix                                                                 |\n| --------------------------- | ------------------------------ | ------------------------------------------------------------------- |\n| `docker: command not found` | Docker not installed           | Install Docker Desktop                                              |\n| `Not a git repository`      | Repo directory missing `.git/` | `cd repos/\u003cname\u003e \u0026\u0026 git init \u0026\u0026 git commit --allow-empty -m \"init\"` |\n| Workspace resume fails      | Cached failure state           | Use a new workspace name                                            |\n| Config schema error         | Invalid root keys              | Use only `authentication`, `rules`, `pipeline`                      |\n| Can't reach localhost       | Docker network isolation       | Use `host.docker.internal` instead of `localhost`                   |\n| Workflow stall (20+ min)    | Temporal/resource/rate limit   | See `troubleshooting.md` — Workflow stalling section                |\n| API rate limit / 429        | Too many concurrent pipelines  | Set `max_concurrent_pipelines: \"2\"`                                 |\n\n\u003e Full troubleshooting: `references/troubleshooting.md` (infra) + `references/troubleshooting-shannon.md` (app)\n\n\u003c/details\u003e\n\n---\n\n## Related Plugins\n\n| Plugin                                                                         | Description                                                                                                                | Install                                                         |\n| ------------------------------------------------------------------------------ | -------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------- |\n| **[cybersecurity-pro](https://github.com/pitimon/claude-cybersecurity-skill)** | 18-domain defensive security knowledge — IR playbooks, compliance, vulnerability management, API security, threat modeling | `claude plugin install cybersecurity-pro@pitimon-cybersecurity` |\n\n\u003e **Complementary workflow:** Shannon finds vulnerabilities (offensive) → cybersecurity-pro creates remediation plans, IR playbooks, compliance mapping (defensive)\n\n| Shannon Finding Type       | cybersecurity-pro Domain      | Use Case                               |\n| -------------------------- | ----------------------------- | -------------------------------------- |\n| Auth/AuthZ vulnerabilities | Domain 13: API Security       | JWT, OAuth, BOLA remediation           |\n| XSS/SQLi/Injection         | Domain 6: Code Security       | Semgrep/CodeQL rules, variant analysis |\n| OWASP Top 10 mapping       | Domain 8: Threat Modeling     | STRIDE/PASTA risk assessment           |\n| Vulnerability inventory    | Domain 14: Vulnerability Mgmt | CVSS+EPSS+KEV prioritization           |\n| Infrastructure findings    | Domain 10: Cloud Security     | CIS Benchmarks, CSPM remediation       |\n\n---\n\n## Project Structure\n\n```\nshannon-pentest/\n├── .claude-plugin/\n│   ├── marketplace.json              # Marketplace registry entry\n│   └── plugin.json                   # Plugin manifest (name, version, skills)\n├── skills/\n│   └── shannon-pentest/\n│       ├── SKILL.md                  # Core skill (~566 lines) — phases, safety, decision tree\n│       └── references/\n│           ├── ci-cd-gating-strategies.md     # CI/CD advanced gating: risk score, campaign, SLA, cost\n│           ├── ci-cd-integration.md           # CI/CD severity gating policy (basic)\n│           ├── companion-tools-fingerprint.md # WhatWeb CMS detection + scanner routing (v3.4.0)\n│           ├── companion-tools-orchestration.md # Phase 1.5/3/4 workflow + parallel monitoring (v3.4.0)\n│           ├── companion-tools-overview.md    # Kali tool catalog + concurrency + safety (v3.4.0)\n│           ├── companion-tools-parsers.md     # WPScan/ffuf/testssl parsers → Shannon schema (v3.4.0)\n│           ├── companion-tools-ncsa.md        # NCSA compliance mapping + VTS bulk scan (v3.5.0)\n│           ├── companion-tools-safety.md      # Rate limiting + scope enforcement (v3.4.0)\n│           ├── companion-tools-scanners.md    # Docker commands for all companion tools (v3.6.0)\n│           ├── ci-cd-templates.md             # GitHub Actions + GitLab CI YAML templates\n│           ├── compliance-framework-reports.md # Compliance reports (OWASP/NIST/ISO/SOC2/PCI-DSS/HIPAA/GDPR)\n│           ├── config-templates-basic.md      # No Auth, Form, TOTP (~900 tokens)\n│           ├── config-templates-advanced.md   # SSO, API, Scoped, Pipeline, WordPress\n│           ├── config-validation.md           # Phase 2 validation scripts + common fixes\n│           ├── docker-runtime-detection.md    # Phase 0: Colima vs Docker Desktop detection (v3.7.0)\n│           ├── defensive-handoff.md           # Phase 5 handoff manifest + prompt generation\n│           ├── engagement-context.md          # Engagement context: client, project, scope\n│           ├── evidence-packaging.md          # Evidence archive + manifest schema\n│           ├── external-findings-comparison.md # Compare Shannon vs external findings.json (v3.7.0)\n│           ├── external-tool-import.md        # Import Burp/ZAP/Nuclei/SARIF findings (v3.3.0)\n│           ├── finding-comparison.md          # Finding comparison diff between sessions\n│           ├── finding-correlation.md         # Root cause grouping, OWASP + endpoint correlation\n│           ├── finding-lifecycle.md           # Finding status tags, transitions, tracking\n│           ├── finding-suppression.md         # Cross-session finding whitelist management\n│           ├── historical-benchmarking.md     # Date-range queries, trends, forecasting (v3.3.0)\n│           ├── inline-defense.md              # IR checklist, remediation, compliance map\n│           ├── issue-templates.md             # Finding → GitHub/Jira issue template generation\n│           ├── monitoring-guide.md            # Phase 3 polling scripts + stall detection\n│           ├── multi-format-export.md         # PDF/HTML export pipeline\n│           ├── multi-target-campaign.md       # Campaign orchestration: multi-target + aggregate\n│           ├── notification-hub.md            # Slack/Discord/webhook/email notifications (v3.3.0)\n│           ├── preflight-checks.md            # 5-step pre-flight validation (v3.3.0)\n│           ├── remediation-verification.md    # Targeted retest, before/after evidence, verification report\n│           ├── report-interpretation.md       # CVSS v4.0, OWASP, MITRE ATT\u0026CK mapping\n│           ├── report-templates.md            # 3 report templates (executive/technical/compliance)\n│           ├── risk-scoring.md                # Custom risk scoring (CVSS+Exploit+BizImpact)\n│           ├── sarif-export.md                # SARIF v2.1.0 export + GitHub Security tab upload\n│           ├── scan-templates.md              # Save/load reusable scan profiles\n│           ├── scheduled-scanning.md          # Automated recurring scans + regression (v3.3.0)\n│           ├── security-metrics-dashboard.md  # Security KPIs: MTTR, density, cost, risk posture, trends\n│           ├── session-analytics.md           # Session analytics: cost estimation + basic stats\n│           ├── session-management.md          # Session registry, auto-append logic\n│           ├── setup-automation.md            # Phase 0 OAuth token extraction + .env config\n│           ├── standalone-dashboard.md        # Self-contained HTML security dashboard (v3.3.0)\n│           ├── target-detection.md            # Web-only vs source-available detection (v3.3.0)\n│           ├── team-remediation-dashboard.md  # Enterprise workflow: ownership, SLA, audit trail\n│           ├── troubleshooting.md             # Docker, Temporal, Network, Platform issues\n│           └── troubleshooting-shannon.md     # Shannon app, config, API, workspace issues\n├── hooks/\n│   ├── hooks.json                    # Pre-validation hook config (PreToolUse)\n│   └── pre-shannon-start.sh          # Config YAML validation before ./shannon start\n├── tests/\n│   ├── smoke-test-prompts.md         # 172 test cases for 42 decision tree routes\n│   └── validate-plugin.sh           # Structure + size + content validation (auto-counted checks)\n├── .github/\n│   └── workflows/\n│       └── validate.yml              # CI/CD: automated validation on push/PR\n├── CHANGELOG.md                      # Version history (v1.0.0 → v3.7.0)\n├── CLAUDE.md                         # Project instructions for Claude Code\n├── LICENSE                           # MIT License\n└── README.md                         # This file\n```\n\n---\n\n## Man-Day Cost Estimation (v2.4.0)\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cstrong\u003eTraditional vs AI-assisted development cost analysis\u003c/strong\u003e\u003c/summary\u003e\n\n### Plugin Scope\n\n| Metric          | Value                            |\n| --------------- | -------------------------------- |\n| Total files     | 30                               |\n| Total lines     | 5,140                            |\n| Reference files | 46 (domain-specific content)     |\n| SKILL.md        | ~566 lines (8 phases, 40 routes) |\n| Validator       | auto-counted checks, 7 sections  |\n| Smoke tests     | 172 cases                        |\n| Releases        | 24 (v1.0.0 → v3.7.0)             |\n\n### Traditional Estimate (Senior Security Engineer)\n\n| Category              | Scope                                                                                                                                                                | Man-Days        |\n| --------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------- |\n| Architecture \u0026 Design | Plugin architecture, 8-phase workflow, decision tree (20 routes), safety framework, bilingual policy                                                                 | 2.5             |\n| Core SKILL.md         | Phase 0-5 logic, config generation, CLI workspace manager, inline defense trigger                                                                                    | 3.5             |\n| Reference Files (19)  | session-management (split), troubleshooting (split), report-templates, config-templates, finding-lifecycle, multi-format-export, sarif-export, issue-templates, etc. | 9.5             |\n| Testing \u0026 Validation  | validate-plugin.sh (auto-counted checks), smoke-test-prompts.md (64 tests), live QA run                                                                              | 3.5             |\n| CI/CD \u0026 Hooks         | GitHub Actions workflow, PreToolUse hook, YAML fallback                                                                                                              | 1.0             |\n| Documentation         | README, CHANGELOG (12 versions), CLAUDE.md, PR/release management                                                                                                    | 2.5             |\n| Iteration \u0026 Fixes     | Config schema fix, perf optimization, quality polish, CI fix across 12 releases                                                                                      | 2.5             |\n| **Total**             |                                                                                                                                                                      | **25 man-days** |\n\n### Cost Comparison\n\n| Metric               | Traditional            | AI-Assisted (Claude Code) |\n| -------------------- | ---------------------- | ------------------------- |\n| Elapsed time         | 25 man-days (~5 weeks) | ~3-4 hours                |\n| Cost (Thailand rate) | 125,000-200,000 THB    | API cost ~$50-80          |\n| Quality assurance    | Manual review          | auto-counted checks + CI  |\n| Iteration speed      | Days per version       | Minutes per version       |\n| **Time savings**     | —                      | **~98%**                  |\n| **Cost savings**     | —                      | **~99%**                  |\n\n\u003c/details\u003e\n\n---\n\n## Safety \u0026 License\n\nThis plugin enforces mandatory safety rules: **never run on production** (staging/test only), **written authorization required** before launch, **target URL confirmed** before every scan, **no credential storage** outside Shannon config, and **strict scope boundaries** (no expansion beyond specified target).\n\nMIT License — see [LICENSE](LICENSE) for details.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fpitimon%2Fshannon-pentest","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fpitimon%2Fshannon-pentest","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fpitimon%2Fshannon-pentest/lists"}