
Darkmoon
io.github.ASCIT31v0.1.0Updated Oct 5, 2026
Drive a self-hosted Darkmoon Pro AI pentest instance: start runs, read campaigns and findings.
Overview
Lets an assistant drive a self-hosted Darkmoon Pro AI penetration-testing dashboard: start runs, check status, list campaigns, and read findings.
- What it does
- This MCP server connects an assistant to the Darkmoon Dashboard API of a self-hosted Darkmoon Pro instance. It exposes four tools: run_pentest starts an autonomous pentest against one authorized target and returns a run_id; get_run_status reports running, completed, error or unknown from the run log; list_campaigns lists campaigns visible to the dashboard user; and get_findings returns vulnerabilities and severity statistics for a campaign. The two listing tools are read only.
- When to use it
- Use it when you already run a self-hosted Darkmoon Pro instance and want an assistant to launch authorized penetration tests and review campaign results without leaving the chat client. It is not useful with the open source Darkmoon CLI alone, since it talks only to the Pro Dashboard API.
- Requirements
- Runs locally over stdio, typically via npx @darkmoon_ai/mcp-server, so Node.js is needed. Requires the base URL of your own Darkmoon Pro Dashboard API in DARKMOON_BASE_URL, plus either DARKMOON_USERNAME and DARKMOON_PASSWORD or a pre-issued JWT in DARKMOON_TOKEN. DARKMOON_TIMEOUT_MS is optional. Network access to that self-hosted endpoint is required; there is no public hosted endpoint.
Installation
In SourceWeft
- Open Darkmoon in the dashboard and add it to a workspace.
- Enable the server for the chats that should use its tools.
Desktop only via STDIO. STDIO servers start a local process, so they need the SourceWeft desktop host.
Other MCP clients
Follow the launch instructions in the repository.
README
@darkmoon_ai/mcp-server
A Model Context Protocol server that lets an MCP client (Claude Desktop, Goose, Continue, LibreChat, ...) drive Darkmoon, an open source (GPL-3.0) autonomous AI penetration testing platform.
Requires Darkmoon Pro
The Darkmoon engine and CLI are open source. This server talks to the Darkmoon Dashboard API, which is part of Darkmoon Pro and always self-hosted: there is no public hosted endpoint, so you supply the base URL of your own instance. It does not work against the open source CLI alone.
Tools
Only run assessments against systems you own or are explicitly authorized in writing to test. Findings can include false positives and must be reviewed by a qualified human.
Configuration
Client configuration
Claude Desktop (claude_desktop_config.json), Continue and LibreChat use the same mcpServers shape:
Goose (~/.config/goose/config.yaml):
Continue (.continue/mcpServers/darkmoon.yaml):
Develop
License
GPL-3.0-only, same as Darkmoon.
Source: README.md at commit 7d660cb
Tools
0Version history
1- v0.1.0LatestOct 5, 2026


