S.01CI/CD

Autonomous penetration testing in your CI/CD pipeline

Autonomous penetration testing in CI/CD, from the open-source Darkmoon CLI. Run it as a security stage in GitHub Actions, GitLab CI, or Jenkins: it finds, exploits, and proves real issues against an authorized staging URL, on a schedule and on every deploy, then uploads a proof report as a build artifact. Real DAST in CI/CD, shift-left security AI, self hosted.

3
Pipelines: GitHub Actions, GitLab CI, Jenkins
50
Specialist AI agents
50+
Offensive tools, driven autonomously
GPLv3
CLI and Action, no license key

S.03Open source in CI
What the open-source CLI does in your pipeline

The same open-source engine you run locally, driven headless by your runner. Find, prove, local, private.

FindingsCVSS
SQL injection9.8
SSRF to metadata9.1
Broken access control8.7
JWT signature bypass7.5
Path traversal6.9

Finds

50 specialist agents drive 50+ offensive tools over web, API, Active Directory, Kubernetes, cloud, CMS and network targets, autonomously, from a single authorized target.

$darkmoon run --scope identity
→AS-REP roast · 3 accounts
→Kerberoast · svc_sql cracked
→NTLM relay → DCSync
✓Domain Admin, proven

Proves

Every finding ships with reproducible proof of exploitation, written to Markdown reports the job uploads as build artifacts, not a raw scanner dump.

Attack surfaceexposure

Local & private

Fully self hosted on your runner. The Privacy Gateway tokenizes sensitive target values locally, so real IPs, hostnames and credentials are kept off any cloud model.

darkmoon-licence.dmeDocker
LicencePro · annual
Machine code7F3A-…-C21E
Seats1 node
Statussealed ✓

No license key

The CLI and the GitHub Action are open source (GPLv3). You only provide your own LLM provider API key as a CI secret.

Open source

The open-source CLI

The examples below use the open-source CLI: it finds, proves, runs locally, and keeps sensitive target values off cloud models through the Privacy Gateway. No license key is required.

Pro

Darkmoon Pro

Managed scheduled orchestration across many targets, the web dashboard with campaign history and severity breakdown, and finding-to-fix remediation pull requests are paid Darkmoon Pro features.

GitHub Actions security testing
GitHub Actions

# examples/github-actions-pentest.yml
name: darkmoon-scheduled-and-deploy-pentest
on:
  schedule:
    - cron: "0 3 * * *"      # nightly re-test
  deployment_status:          # run on deploy
  workflow_dispatch:

jobs:
  pentest:
    if: ${{ github.event_name != 'deployment_status' || github.event.deployment_status.state == 'success' }}
    runs-on: self-hosted      # Docker + Compose v2, enough resources
    steps:
      - uses: ASCIT31/darkmoon-scan-action@v1
        with:
          target: 'TARGET: ${{ secrets.STAGING_URL }} PROGRAM="Staging (authorized)"'
          provider: openrouter
          model: ${{ secrets.OPENCODE_MODEL }}
          api_key: ${{ secrets.OPENROUTER_API_KEY }}
      # findings are uploaded as the "darkmoon-reports" artifact

GitLab CI DAST
GitLab CI

# examples/gitlab-ci-pentest.yml
# .gitlab-ci.yml: GitLab CI DAST (dynamic application security testing) stage
# Set OPENROUTER_API_KEY, OPENCODE_MODEL, STAGING_URL as masked variables.
darkmoon_dast:
  stage: dast
  tags: [docker]
  variables:
    OPENROUTER_PROVIDER: "openrouter"
    TARGET: 'TARGET: $STAGING_URL PROGRAM="Staging (authorized)"'
  script:
    - git clone --depth 1 https://github.com/ASCIT31/Dark-Moon.git darkmoon
    - cd darkmoon
    - chmod +x install.sh && ./install.sh
    - ./darkmoon.sh run --agent pentest "$TARGET"
  artifacts:
    when: always
    paths: [reports/]
  rules:
    - if: '$CI_PIPELINE_SOURCE == "schedule"'

Jenkins
Jenkins pipeline

# examples/jenkins-pipeline.groovy
pipeline {
  agent { label 'docker' }        // Docker + Compose v2, enough resources
  triggers { cron('H 3 * * *') }  // nightly
  environment {
    OPENROUTER_PROVIDER = 'openrouter'
    OPENROUTER_API_KEY  = credentials('openrouter-api-key')
    OPENCODE_MODEL      = credentials('opencode-model')
  }
  stages {
    stage('Darkmoon autonomous pentest') {
      steps {
        sh '''
          git clone --depth 1 https://github.com/ASCIT31/Dark-Moon.git darkmoon
          cd darkmoon && chmod +x install.sh && ./install.sh
          ./darkmoon.sh run --agent pentest "TARGET: ${STAGING_URL} PROGRAM=\"Staging (authorized)\""
        '''
      }
    }
  }
  post { always { archiveArtifacts artifacts: 'reports/**', allowEmptyArchive: true } }
}

S.06FAQ
Autonomous pentest in CI/CD, answered

How to run DAST in CI/CD with the open-source Darkmoon CLI, across GitHub Actions, GitLab CI, and Jenkins.

How do I run an autonomous pentest in GitHub Actions?

Add the ASCIT31/darkmoon-scan-action step to a workflow and pass an authorized target, your LLM provider, a model id, and your provider API key (as a repository secret). The open-source Darkmoon CLI then runs an autonomous penetration test in your CI/CD pipeline and uploads the Markdown findings as the darkmoon-reports build artifact. Trigger it on a schedule and on deploy. See examples/github-actions-pentest.yml.

Can I add DAST to my CI pipeline?

Yes. Darkmoon runs as a dynamic application security testing (DAST) stage in GitLab CI, GitHub Actions, or Jenkins. It clones the open-source engine, installs the stack, and runs darkmoon.sh run --agent pentest against an authorized staging URL. Every finding ships with reproducible proof of exploitation. See examples/gitlab-ci-pentest.yml for a GitLab CI DAST job.

Is the CI/CD security testing free and open source?

The Darkmoon CLI and the GitHub Action are open source (GPLv3) and need no license key; you only supply your own LLM provider API key. Managed scheduled orchestration, the web dashboard, and finding-to-fix remediation pull requests are paid Darkmoon Pro features.

How does shift-left security AI keep target data private?

Darkmoon runs fully self hosted on your own runner, and the Privacy Gateway tokenizes sensitive target values locally, so real IPs, hostnames, and credentials are kept off any cloud model. That lets you shift security testing left into CI/CD without shipping production data to a third party.

Open source vs Darkmoon Pro
A star helps other teams find it

Darkmoon is open source (GPLv3). If it helps, a star on the main repository helps other teams find it.

S.07Next
Put an autonomous pentest in your pipeline

Clone the Action, add your provider key as a secret, and gate builds on proven findings. The same open-source engine, in CI.