agentreadme

Report · marked 10 Oct 2026

KeygraphHQ/shannon

Ready for an agent to work in without hand-holding.

TypeScript · 48,722 stars · 370 files · branch main

Fix these first

01
Agent instruction file
Rename or symlink to AGENTS.md so tools other than one vendor's can read it. Keeping CLAUDE.md alongside it costs nothing.
02
Pinned runtime version
Add a .nvmrc, .python-version, or equivalent so the agent's toolchain matches yours.
03
Instruction quality
Worth fixing: it's 36k characters, which burns context on every single turn.

The full marking

Every deduction below names the file or setting it came from.

Instructions 22/27 A-

Whether the repo tells an agent how to behave before it starts guessing.

✗Agent instruction file 9/12
CLAUDE.md is present, but not the vendor-neutral AGENTS.md.
Rename or symlink to AGENTS.md so tools other than one vendor's can read it. Keeping CLAUDE.md alongside it costs nothing.
✗Instruction quality 10/12
Specific enough that an agent can act on it.
Worth fixing: it's 36k characters, which burns context on every single turn.
names the actual commands to run
uses headings, so an agent can skim it
includes copyable code blocks
✓README as an entry point 3/3
README has a clear getting-started section.
Setup 18/20 A

Whether an agent can install the project and get it running without a human.

✓Deterministic install 6/6
pnpm-lock.yaml pins the dependency tree.
Found pnpm-lock.yaml
✓Discoverable commands 6/6
Commands are declared where an agent will look for them.
package.json scripts (build, check, biome, biome:fix, clean, temporal:worker…)
✓Environment config 4/4
.env.example documents what the app needs to run.
✗Pinned runtime version 0/2
No pinned runtime version.
Add a .nvmrc, .python-version, or equivalent so the agent's toolchain matches yours.
✓Reproducible environment 2/2
dockerfile gives a known-good environment.
Verification loop 22/25 A

Whether an agent can check its own work. This is the category that most decides whether agent output is trustworthy.

✗Tests exist 6/8
11 test files against 207 source files.
e.g. apps/cli/src/model-spec.ts, apps/worker/prompts/sast/capella/architecture.test.hbs, apps/worker/prompts/sast/capella/calibrate.test.hbs
✓Test command is discoverable 7/7
An agent can find and run `npm run check`.
✓Continuous integration 4/4
4 GitHub Actions workflows define what "passing" means.
✓Lint and format rules 3/3
biome.json encodes the house style.
✗Static type checking 2/3
Type checking is configured, but not in strict mode.
Turn on `"strict": true`. Type errors are the fastest feedback an agent gets, and non-strict mode silently discards most of them.
Context economy 19/20 A+

Whether the repo fits in a context window, or fights it.

✓No committed build output 6/6
No generated directories committed.
✓.gitignore hygiene 3/3
.gitignore covers 7 patterns.
✓File sizes fit in context 6/6
No source file is large enough to crowd out a context window.
✗Repository weight 4/5
About 92.7MB checked out, which is comfortable.

Here is your AGENTS.md

Drafted from what is actually in this repository: the install command from your lockfile, the commands you already declare, your real directory layout. Anything marked TODO needs a person. Save it at the root as AGENTS.md.

AGENTS.md — drafted for KeygraphHQ/shannon
# AGENTS.md

Shannon is an AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities before they reach production.

## Setup

```
pnpm install
```

## Commands

```
pnpm build             # produce a build
pnpm check             # lint and type check
pnpm biome
pnpm biome:fix
pnpm clean
pnpm temporal:worker
pnpm temporal:start
```

## Layout

- `apps/` 206 source files

## Conventions

- Tests live alongside the code they cover, following `apps/cli/src/model-spec.ts`.
- TypeScript is not in strict mode. Turning it on catches a whole class of mistakes before they run.
- CI defines what passing means. See `.github/workflows/release-beta.yml`, and keep it green.
- TODO: add the two or three conventions a newcomer always gets wrong here.

## Gotchas

- Copy `.env.example` before running anything that needs configuration.

---

Drafted by agentreadme.com from what is in this repository. Everything marked TODO
needs a human. Check it in as AGENTS.md at the root.

Open the raw markdown  or  curl -o AGENTS.md agentreadme.com/draft/KeygraphHQ/shannon.md

A draft gets the commands right and stops at the things only a maintainer knows. What a good TypeScript AGENTS.md looks like covers what to add by hand, and what AGENTS.md is explains the format itself.

Show the mark

The badge re-checks daily, so it keeps up as the repository changes. Use mark again to force it now.

agent ready 89 out of 100

[![agent ready](https://agentreadme.com/badge/KeygraphHQ/shannon.svg)](https://agentreadme.com/KeygraphHQ/shannon)

Other TypeScript repositories, marked

freeCodeCamp/freeCodeCamp 69 B openclaw/openclaw 73 B+ nilbuild/developer-roadmap 45 C deepseek-ai/deepseek-harness 82 A- vuejs/vue 67 B anomalyco/opencode 78 A-

All TypeScript repositories

Think this mark is wrong?

Every deduction above names the file it came from, so this can be settled by looking. If a check missed something, that is a rule worth fixing.

Open an issue, already filled in