ML-KEM is built on SHAKE, and a protocol that adopts ML-KEM often needs SHAKE itself: HPKE, for one, derives an ML-KEM key pair from keying material with SHAKE256. These are the functions ML-KEM runs on, exposed so that such a protocol does not carry a second Keccak.
Both are one-shot. For inputs of one length they perform the same operations whatever the input holds, so the input may be secret, within the limits on constant-time execution that apply to this whole library. Outputs for one input are prefixes of each other.
shake128 ~output_length input is the first output_length bytes of SHAKE128 over input, which has 128 bits of security strength. A negative output_length raises Invalid_argument.
shake256 ~output_length input is the first output_length bytes of SHAKE256 over input, which has 256 bits of security strength. A negative output_length raises Invalid_argument.