
Darkmoon
io.github.ASCIT31v0.1.0更新于 Oct 5, 2026
Drive a self-hosted Darkmoon Pro AI pentest instance: start runs, read campaigns and findings.
概览
让助手驱动自托管的 Darkmoon Pro AI 渗透测试仪表盘:启动测试、查看状态、列出行动并读取发现。
- 功能
- 该 MCP 服务器将助手连接到自托管 Darkmoon Pro 实例的 Darkmoon Dashboard API。它提供四个工具:run_pentest 针对一个已授权目标启动自主渗透测试并返回 run_id;get_run_status 根据运行日志报告 running、completed、error 或 unknown;list_campaigns 列出仪表盘用户可见的行动;get_findings 返回某个行动的漏洞与严重性统计。两个列表工具为只读。
- 适用场景
- 当你已经运行自托管的 Darkmoon Pro 实例,并希望助手在聊天客户端内发起已授权的渗透测试并查看行动结果时使用。仅使用开源 Darkmoon CLI 时没有用处,因为它只与 Pro Dashboard API 通信。
- 运行要求
- 通过 stdio 在本地运行,通常使用 npx @darkmoon_ai/mcp-server,因此需要 Node.js。需要在自己的 Darkmoon Pro Dashboard API 基础地址填入 DARKMOON_BASE_URL,并提供 DARKMOON_USERNAME 与 DARKMOON_PASSWORD,或在 DARKMOON_TOKEN 中提供预签发的 JWT。DARKMOON_TIMEOUT_MS 为可选项。需要能访问该自托管端点;没有公开的托管端点。
安装
在 SourceWeft 中
- 打开 控制台中的 Darkmoon,将其添加到工作区。
- 为需要使用其工具的对话启用该服务。
Desktop only,通过 STDIO。 STDIO 服务会启动本地进程,因此需要 SourceWeft 桌面宿主。
其他 MCP 客户端
参照 仓库 中的启动说明。
README
@darkmoon_ai/mcp-server
A Model Context Protocol server that lets an MCP client (Claude Desktop, Goose, Continue, LibreChat, ...) drive Darkmoon, an open source (GPL-3.0) autonomous AI penetration testing platform.
Requires Darkmoon Pro
The Darkmoon engine and CLI are open source. This server talks to the Darkmoon Dashboard API, which is part of Darkmoon Pro and always self-hosted: there is no public hosted endpoint, so you supply the base URL of your own instance. It does not work against the open source CLI alone.
Tools
Only run assessments against systems you own or are explicitly authorized in writing to test. Findings can include false positives and must be reviewed by a qualified human.
Configuration
Client configuration
Claude Desktop (claude_desktop_config.json), Continue and LibreChat use the same mcpServers shape:
Goose (~/.config/goose/config.yaml):
Continue (.continue/mcpServers/darkmoon.yaml):
Develop
License
GPL-3.0-only, same as Darkmoon.
来源:README.md,提交 7d660cb
工具
0版本历史
1- v0.1.0最新Oct 5, 2026


