ShakerScan Open Source documentation, pinned to v2.5.4.
Every page here is rendered from the repository at the current stable release tag, so what you read matches what the installer runs. No account is required. When a document and the implementation disagree, the code, schema, and tests at that tag are authoritative.
Getting started
- README: install and first scanInstall, first scan, workflow selection, UI, CLI, and API orientation, safety, troubleshooting.
- First-run walkthroughConcise first-run and day-to-day operator walkthrough.
- Upgrade and rollbackBackup, upgrade verification, failure handling, and database rollback.
- Client, CLI and public checksEngine-less client install, shakerscan check, LAN and Enterprise connections, MCP, and scripted Hunt.
- Agent skills and setupHow Codex, Claude Code, and OpenCode load ShakerScan instructions and skills.
Workflows
- Product model and vocabularyCanonical names for Scan, Hunt, Findings, ASM, AI Gate, Model Intake, and devices.
- Hunt architectureHuman judgment, AI reasoning, deterministic execution and proof.
- Hunt authorization workflowSupported investigation flow, safety boundaries, and limitations.
- Hunt authorization behaviorAs-built selected-object authorization behavior and its limits.
- AI test workflowsAI Gate and Model Intake operator reference.
- Connected-device securityDevice product boundary, coverage and safety profiles, health checkpoints.
- Model Intake boundarySupported acquisition, evidence, isolation, and admission contract.
Architecture and operations
- DAST execution and Continuous ASMLocal and broker execution model and safety boundaries.
- Multi-node Fleet guideFleet setup, enrollment, drain, resume, and revoke.
- Multi-node architectureTrust model, placement, scaling, and artifact storage.
- MCP adapterRead-only Arsenal and target-bound Hunt trust levels over MCP.
- OWASP coverage matrixMapped coverage and intentional gaps.
- Functionality referenceExhaustive product map plus generated inventory of routes, commands, and tables.
Releases and process
- Release processBuild-once candidates, exact-SHA gates, digest promotion, public smoke.
- Release SBOMsSPDX and CycloneDX inventories, the Sigstore-signed index, and their stated partial coverage.
- Release notes indexImmutable release-note index, including failed or cancelled candidates.
- Release mappingRelease-to-commit and image-digest provenance.
- Benchmark fixturesJuice Shop and crAPI expected-family fixtures used for miss analysis.
- Agent operating policyCompact, always-loaded coding-agent policy and safety rules.
Full index from the repository
docs/README.md at v2.5.4ShakerScan documentation
Status: maintained documentation index; reviewed 2026-09-23.
The root README is intentionally a short operator quick start. This directory is for maintained engineering, architecture, and advanced-operation references.
Runtime behavior is authoritative in code, database migrations, tests, and the live API contracts. Point-in-time plans, release readiness notes, completed implementation diaries, and obsolete claims belong in Git history or immutable release notes rather than the active documentation set.
Core architecture
- Product model — canonical product names and boundaries.
- Functionality reference — exhaustive generated/current product map.
- AI-native architecture — Scan/Hunt architecture direction.
- Hunt architecture — adaptive investigation model.
- DAST and ASM architecture — deterministic Scan and attack-surface model.
- Service intelligence — service observations and investigation handoff.
- Multi-node architecture — distributed execution design.
Hunt and authenticated testing
- Hunt authorization behavior
- Hunt authorization workflow
- Hunt investigation evaluation
- Operator-complete Hunt implementation
- Hunt authorization proof completion
- Hunt review integrity
- Authenticated assurance
- Browser login QA
- Browser session integrity
Devices, AI, and model security
Operations
- Client
- LAN access
- Clean reinstall
- Upgrade and rollback
- Release process
- Release notes
- SBOM
- MCP
- Multi-node guide
- Data lifecycle
Engineering references
- End-to-end test plan
- API image boundary
- Compatibility
- Hosted connector
- OWASP coverage matrix
- Decisions
- Integrity ledgers
- Generated contracts and inventories
Historical release plans and superseded operating documents are intentionally not maintained here. Use Git history or immutable release notes when investigating an older release.