Back to Browse

Darkmoon MCP Server

Developer ToolsScan in ProgressMCP RegistryLocal
Free

Server data from the Official MCP Registry

Drive a self-hosted Darkmoon Pro AI pentest instance: start runs, read campaigns and findings.

About

Drive a self-hosted Darkmoon Pro AI pentest instance: start runs, read campaigns and findings.

Security Report

0.0
Use Caution0.0Moderate Risk

5 tools verified · Open access · No issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Remote servers are capped at 8.0 because source code is not available for review. The score reflects endpoint verification only.

What You'll Need

Set these up before or after installing:

Base URL of your self-hosted Darkmoon Pro Dashboard APIOptional

Environment variable: DARKMOON_BASE_URL

Dashboard userOptional

Environment variable: DARKMOON_USERNAME

Dashboard passwordRequired

Environment variable: DARKMOON_PASSWORD

Pre-issued JWT, alternative to username/passwordRequired

Environment variable: DARKMOON_TOKEN

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-ascit31-darkmoon-mcp-server": {
      "env": {
        "DARKMOON_TOKEN": "your-darkmoon-token-here",
        "DARKMOON_BASE_URL": "your-darkmoon-base-url-here",
        "DARKMOON_PASSWORD": "your-darkmoon-password-here",
        "DARKMOON_USERNAME": "your-darkmoon-username-here"
      },
      "args": [
        "-y",
        "@darkmoon_ai/mcp-server"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

@darkmoon_ai/mcp-server

A Model Context Protocol server that lets an MCP client (Claude Desktop, Goose, Continue, LibreChat, ...) drive Darkmoon, an open source (GPL-3.0) autonomous AI penetration testing platform.

Requires Darkmoon Pro

The Darkmoon engine and CLI are open source. This server talks to the Darkmoon Dashboard API, which is part of Darkmoon Pro and always self-hosted: there is no public hosted endpoint, so you supply the base URL of your own instance. It does not work against the open source CLI alone.

Tools

ToolDescription
run_pentestStart an autonomous pentest against one authorized target and return the run_id
get_run_statusReport running, completed, error or unknown for a run, from its run log
list_campaignsList campaigns visible to the dashboard user (read only)
get_findingsVulnerabilities and severity statistics for a campaign (read only)

Only run assessments against systems you own or are explicitly authorized in writing to test. Findings can include false positives and must be reviewed by a qualified human.

Configuration

VariableDescription
DARKMOON_BASE_URLBase URL of your Darkmoon Pro Dashboard API (required)
DARKMOON_USERNAME, DARKMOON_PASSWORDDashboard credentials; a JWT is requested on each call and never cached
DARKMOON_TOKENAlternative to username/password: a pre-issued JWT
DARKMOON_TIMEOUT_MSOptional per-request timeout, default 60000

Client configuration

Claude Desktop (claude_desktop_config.json), Continue and LibreChat use the same mcpServers shape:

{
  "mcpServers": {
    "darkmoon": {
      "command": "npx",
      "args": ["-y", "@darkmoon_ai/mcp-server"],
      "env": {
        "DARKMOON_BASE_URL": "https://darkmoon.example.internal",
        "DARKMOON_USERNAME": "your-dashboard-user",
        "DARKMOON_PASSWORD": "your-dashboard-password"
      }
    }
  }
}

Goose (~/.config/goose/config.yaml):

extensions:
  darkmoon:
    type: stdio
    enabled: true
    name: darkmoon
    cmd: npx
    args: ["-y", "@darkmoon_ai/mcp-server"]
    envs:
      DARKMOON_BASE_URL: https://darkmoon.example.internal
      DARKMOON_USERNAME: your-dashboard-user
      DARKMOON_PASSWORD: your-dashboard-password

Continue (.continue/mcpServers/darkmoon.yaml):

name: Darkmoon
version: 0.1.0
schema: v1
mcpServers:
  - name: darkmoon
    command: npx
    args: ["-y", "@darkmoon_ai/mcp-server"]
    env:
      DARKMOON_BASE_URL: https://darkmoon.example.internal
      DARKMOON_USERNAME: your-dashboard-user
      DARKMOON_PASSWORD: your-dashboard-password

Develop

npm install
npm run build
npm test      # mocked Dashboard API, in-memory MCP client and a real stdio process

License

GPL-3.0-only, same as Darkmoon.

Reviews

No reviews yet

Be the first to review this server!