shannon
Installation
SKILL.md
Shannon
Use Shannon only when the task is explicitly security-focused and the scan cost is justified by the scope of work.
Workflow
- Confirm the target before running anything.
- Collect the app URL, repo path, and intended environment.
- Treat production targets as high risk. Restate the URL and ask for confirmation before running against production or other sensitive environments.
- Do not run Shannon as part of ordinary repo exploration, routine code review, or every implementation task.
- Check local prerequisites.
- Verify Docker is available because Shannon pulls and runs a worker container.
- Expect network access for
npx, Docker image pulls, and live target interaction. - If the CLI may not already be configured, plan to run setup first.
- Configure Shannon when needed.