If Darkmoon is useful, a star on the main repo helps others find it.
Run Darkmoon, the open source (GPLv3) autonomous penetration testing platform, against an authorized target inside your CI, and upload the findings report as a build artifact.
The open source Darkmoon CLI, darkmoon.sh --log streaming a run's live output, the same terminal engine this Action drives inside your CI.
Pro: the paid Darkmoon Pro web dashboard, campaigns, severity breakdown and findings. This Action uses the open source CLI and needs no license key.
Web dashboard and remediation are Darkmoon Pro (paid) features; the open source edition is the CLI shown above.
Darkmoon runs 50 specialist security agents over MCP orchestration, driving 50+ offensive tools across web, API, Active Directory, Kubernetes, cloud, CMS and network targets. Every finding ships with reproducible proof of exploitation. It is fully self hosted, and its Privacy Gateway tokenizes sensitive target values before any cloud model sees them, so real IPs, hostnames and credentials stay on your machine.
This action uses the open source distribution. It does not require any Darkmoon license key. You only provide your own LLM provider API key as a secret.
name: darkmoon-scan
on:
workflow_dispatch:
inputs:
target:
description: 'Authorized target'
required: true
default: 'TARGET: https://juice-shop.local'
jobs:
pentest:
runs-on: self-hosted # a runner with Docker and enough resources for the stack
steps:
- uses: ASCIT31/darkmoon-scan-action@v1
with:
target: ${{ inputs.target }}
provider: openrouter
model: ${{ secrets.OPENCODE_MODEL }}
api_key: ${{ secrets.OPENROUTER_API_KEY }}| Input | Required | Description |
|---|---|---|
target |
yes | Authorized target, for example TARGET: https://example.test or TARGET: 10.0.4.12. |
model |
yes | Model id for the reasoning engine. An Opus class model is recommended for full autonomous campaigns. |
api_key |
yes | LLM provider API key, provided as a repository secret. |
provider |
no | LLM provider (openrouter, anthropic, openai, or a local endpoint). Default openrouter. |
ref |
no | Darkmoon git ref to check out. Default main. |
Copy-paste workflows for autonomous penetration testing in CI/CD live in examples/. They run the open source Darkmoon CLI against an authorized staging URL, on a schedule and on deploy, and upload the Markdown findings as build artifacts. This is an automated pentest GitHub Action for real DAST in CI/CD and shift-left security AI.
| Platform | File | What it shows |
|---|---|---|
| GitHub Actions security testing | examples/github-actions-pentest.yml |
Autonomous pentest on a nightly schedule and after a successful deployment, using this action. |
| GitLab CI DAST | examples/gitlab-ci-pentest.yml |
.gitlab-ci.yml dynamic application security testing (DAST) stage, on deploy and from a pipeline schedule, calling the open source CLI directly. |
| Jenkins pipeline security scan | examples/jenkins-pipeline.groovy |
Declarative Jenkinsfile stage with a nightly cron trigger, archiving the findings reports. |
All three drive the same open source Darkmoon CLI: it finds, exploits and proves each issue against a target you are authorized to test, runs fully self hosted, and its Privacy Gateway tokenizes sensitive target values locally before any cloud model sees them. There is a matching walkthrough on the site, autonomous penetration testing in your CI/CD pipeline.
Open source vs Pro. The examples above use the open source CLI (find, prove, local, privacy). Scheduled orchestration at scale, the web dashboard, and finding-to-fix remediation pull requests are Darkmoon Pro (paid) features. No license key is required for the CLI or this action.
- Docker and Docker Compose v2 on the runner.
- An LLM provider API key. A capable model is needed for a full campaign. Small local models will not finish an autonomous campaign.
- The stack is resource heavy. A self hosted runner or a large runner is recommended rather than a standard hosted runner.
- Only run this against targets you are explicitly authorized to test. You are responsible for authorization and scope.
- Clones the open source Darkmoon repository.
- Runs
install.shnon interactively using the provider settings from your secrets, which pulls the publicascit/darkmoon:latestimage and starts the Compose stack. - Runs
darkmoon.sh run --agent pentest "<target>". - Collects the Markdown findings reports from the container and uploads them as an artifact.
GPLv3, same as Darkmoon.
