Skip to content

Latest commit

 

History

7 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 

Repository files navigation

Darkmoon, autonomous AI penetration testing

Darkmoon Autonomous Pentest (GitHub Action)

Star Dark-Moon

License GPLv3 No license key required Self-hosted runner Website

If Darkmoon is useful, a star on the main repo helps others find it.

Run Darkmoon, the open source (GPLv3) autonomous penetration testing platform, against an authorized target inside your CI, and upload the findings report as a build artifact.

Darkmoon open source CLI, live terminal log of a pentest run streaming its commands

The open source Darkmoon CLI, darkmoon.sh --log streaming a run's live output, the same terminal engine this Action drives inside your CI.


Pro web dashboard, Darkmoon campaigns and severity breakdown

Pro: the paid Darkmoon Pro web dashboard, campaigns, severity breakdown and findings. This Action uses the open source CLI and needs no license key.

Web dashboard and remediation are Darkmoon Pro (paid) features; the open source edition is the CLI shown above.

Darkmoon runs 50 specialist security agents over MCP orchestration, driving 50+ offensive tools across web, API, Active Directory, Kubernetes, cloud, CMS and network targets. Every finding ships with reproducible proof of exploitation. It is fully self hosted, and its Privacy Gateway tokenizes sensitive target values before any cloud model sees them, so real IPs, hostnames and credentials stay on your machine.

No license required

This action uses the open source distribution. It does not require any Darkmoon license key. You only provide your own LLM provider API key as a secret.

Usage

name: darkmoon-scan
on:
  workflow_dispatch:
    inputs:
      target:
        description: 'Authorized target'
        required: true
        default: 'TARGET: https://juice-shop.local'

jobs:
  pentest:
    runs-on: self-hosted   # a runner with Docker and enough resources for the stack
    steps:
      - uses: ASCIT31/darkmoon-scan-action@v1
        with:
          target: ${{ inputs.target }}
          provider: openrouter
          model: ${{ secrets.OPENCODE_MODEL }}
          api_key: ${{ secrets.OPENROUTER_API_KEY }}

Inputs

Input Required Description
target yes Authorized target, for example TARGET: https://example.test or TARGET: 10.0.4.12.
model yes Model id for the reasoning engine. An Opus class model is recommended for full autonomous campaigns.
api_key yes LLM provider API key, provided as a repository secret.
provider no LLM provider (openrouter, anthropic, openai, or a local endpoint). Default openrouter.
ref no Darkmoon git ref to check out. Default main.

CI/CD examples: autonomous penetration testing in CI/CD

Copy-paste workflows for autonomous penetration testing in CI/CD live in examples/. They run the open source Darkmoon CLI against an authorized staging URL, on a schedule and on deploy, and upload the Markdown findings as build artifacts. This is an automated pentest GitHub Action for real DAST in CI/CD and shift-left security AI.

Platform File What it shows
GitHub Actions security testing examples/github-actions-pentest.yml Autonomous pentest on a nightly schedule and after a successful deployment, using this action.
GitLab CI DAST examples/gitlab-ci-pentest.yml .gitlab-ci.yml dynamic application security testing (DAST) stage, on deploy and from a pipeline schedule, calling the open source CLI directly.
Jenkins pipeline security scan examples/jenkins-pipeline.groovy Declarative Jenkinsfile stage with a nightly cron trigger, archiving the findings reports.

All three drive the same open source Darkmoon CLI: it finds, exploits and proves each issue against a target you are authorized to test, runs fully self hosted, and its Privacy Gateway tokenizes sensitive target values locally before any cloud model sees them. There is a matching walkthrough on the site, autonomous penetration testing in your CI/CD pipeline.

Open source vs Pro. The examples above use the open source CLI (find, prove, local, privacy). Scheduled orchestration at scale, the web dashboard, and finding-to-fix remediation pull requests are Darkmoon Pro (paid) features. No license key is required for the CLI or this action.

Requirements and limitations

  • Docker and Docker Compose v2 on the runner.
  • An LLM provider API key. A capable model is needed for a full campaign. Small local models will not finish an autonomous campaign.
  • The stack is resource heavy. A self hosted runner or a large runner is recommended rather than a standard hosted runner.
  • Only run this against targets you are explicitly authorized to test. You are responsible for authorization and scope.

How it works

  1. Clones the open source Darkmoon repository.
  2. Runs install.sh non interactively using the provider settings from your secrets, which pulls the public ascit/darkmoon:latest image and starts the Compose stack.
  3. Runs darkmoon.sh run --agent pentest "<target>".
  4. Collects the Markdown findings reports from the container and uploads them as an artifact.

License

GPLv3, same as Darkmoon.

About

GitHub Action: run the open source Darkmoon autonomous pentest platform in CI (no license). 50 agents, 50+ tools, Privacy Gateway.

Topics

Resources

Code of conduct

Security policy

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors