Install
$ agentstack add mcp-devinoldenburg-shannon-mcp ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
About
Shannon Lite MCP
Model Context Protocol server for end-to-end Shannon Lite security workflows
This package enables AI assistants and applications to configure Shannon, start scans, monitor runtime, inspect workspaces, and read reports programmatically.
Features
- Full Shannon Lite workflow support through MCP tools
- Built-in config management for
~/.shannon/config.toml - Scan orchestration (
start,status,workspaces, logs, report reads) - Safe destructive operations with explicit confirmation tokens
- Smart CLI execution (
shannonbinary or fallback tonpx @keygraph/shannon) - TypeScript implementation with strict Zod validation
Setup
Prerequisites
- Node.js 18+
- Docker (daemon running)
- Shannon CLI access (
shannoninPATHornpxavailable)
MCP Configuration
If you are running this repo locally (unpublished package), build first:
npm install
npm run build
Then use command node with args [/absolute/path/to/shannon-mcp/dist/index.js] in your MCP client configuration.
For Claude Desktop
Add to your Claude Desktop configuration file (~/Library/Application Support/Claude/claude_desktop_config.json on macOS):
{
"mcpServers": {
"shannon-lite": {
"command": "npx",
"args": ["-y", "shannon-lite-mcp"]
}
}
}
For Cursor
Add the configuration to your Cursor settings:
{
"mcpServers": {
"shannon-lite": {
"command": "npx",
"args": ["-y", "shannon-lite-mcp"]
}
}
}
For Windsurf
Add the configuration to your Windsurf settings:
{
"mcpServers": {
"shannon-lite": {
"command": "npx",
"args": ["-y", "shannon-lite-mcp"]
}
}
}
For Warp
Add the following to your Warp session setup:
{
"shannon-lite": {
"command": "npx",
"args": ["-y", "shannon-lite-mcp"],
"working_directory": null,
"start_on_launch": true
}
}
For Other MCP Clients
Use standard MCP server settings:
- Command:
npx -y shannon-lite-mcpornode /path/to/shannon-mcp/dist/index.js - Transport: stdio
Available MCP Tools
shannon_health- Check Docker/Node/CLI readiness, config, and workspace stateshannon_config_set- Write~/.shannon/config.tomlforanthropic,custom_base_url,bedrock,vertex, orroutershannon_config_get- Read current config with secret maskingshannon_start_scan- Start a scan withurl,repo, and optionalconfig,workspace,output,pipeline_testing,routershannon_status- Get Temporal + worker runtime statusshannon_list_workspaces- List known Shannon workspacesshannon_get_workspace- Return detailed workspace/session metadatashannon_read_workflow_log- Read workspaceworkflow.log(tail by default)shannon_read_report- Read final report from workspace deliverablesshannon_stop- Stop Shannon runtime (clean mode requires confirmation token)shannon_uninstall- Remove~/.shannonand stop runtime (requires confirmation token)
Safety Notice
Shannon Lite can run real security test flows. Use only on systems you are authorized to test.
Destructive operations require exact confirmation tokens:
shannon_stopwithclean=true:I_UNDERSTAND_THIS_WILL_REMOVE_SHANNON_DATAshannon_uninstall:DELETE_SHANNON_HOME_AND_STOP_SHANNON
Usage Examples
Configure Anthropic API Key
await mcp.callTool("shannon_config_set", {
provider: "anthropic",
auth_method: "api_key",
api_key: "sk-ant-..."
});
Start a Scan
await mcp.callTool("shannon_start_scan", {
url: "https://example.com",
repo: "/absolute/path/to/repo",
workspace: "q2-audit"
});
Read Final Report
await mcp.callTool("shannon_read_report", {
workspace: "q2-audit"
});
Clean Stop (destructive)
await mcp.callTool("shannon_stop", {
clean: true,
confirm_destructive: "I_UNDERSTAND_THIS_WILL_REMOVE_SHANNON_DATA"
});
Development Setup
Prerequisites
- Node.js 18+
- npm
Local Development
- Install dependencies:
``bash npm install ``
- Build the project:
``bash npm run build ``
- Run in development mode:
``bash npm run dev ``
- Run tests:
``bash npm run test:run ``
Contributing
- Fork the repository
- Create your feature branch (
git checkout -b feature/amazing-feature) - Commit your changes (
git commit -m 'Add some amazing feature') - Push to the branch (
git push origin feature/amazing-feature) - Open a Pull Request
License
This project is licensed under the MIT License - see the LICENSE file for details.
Links
Support
- Create an issue for bug reports or feature requests
- Check existing issues before creating new ones
- Include reproduction steps, environment info, and relevant logs
Made with care for the security engineering community.
Source & license
This open-source MCP server is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: devinoldenburg
- Source: devinoldenburg/shannon-mcp
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.