Finds
50 specialist agents drive 50+ offensive tools over web, API, Active Directory, Kubernetes, cloud, CMS and network targets, autonomously, from a single authorized target.
Autonomous penetration testing in CI/CD, from the open-source Darkmoon CLI. Run it as a security stage in GitHub Actions, GitLab CI, or Jenkins: it finds, exploits, and proves real issues against an authorized staging URL, on a schedule and on every deploy, then uploads a proof report as a build artifact. Real DAST in CI/CD, shift-left security AI, self hosted.
The same open-source engine you run locally, driven headless by your runner. Find, prove, local, private.
50 specialist agents drive 50+ offensive tools over web, API, Active Directory, Kubernetes, cloud, CMS and network targets, autonomously, from a single authorized target.
Every finding ships with reproducible proof of exploitation, written to Markdown reports the job uploads as build artifacts, not a raw scanner dump.
Fully self hosted on your runner. The Privacy Gateway tokenizes sensitive target values locally, so real IPs, hostnames and credentials are kept off any cloud model.
The CLI and the GitHub Action are open source (GPLv3). You only provide your own LLM provider API key as a CI secret.
The examples below use the open-source CLI: it finds, proves, runs locally, and keeps sensitive target values off cloud models through the Privacy Gateway. No license key is required.
Managed scheduled orchestration across many targets, the web dashboard with campaign history and severity breakdown, and finding-to-fix remediation pull requests are paid Darkmoon Pro features.
Real, working templates from the darkmoon-scan-action repository. GitHub Actions security testing, GitLab CI DAST and a Jenkins stage, accurate to how the Action and CLI actually run.
Runs nightly on a cron schedule, on every successful deploy and on demand, on a self-hosted runner with Docker and Compose v2. The target, model id and provider key come from repository secrets; the findings are uploaded as the darkmoon-reports artifact.
A dast stage on a docker runner: it clones the open-source engine, installs the stack and runs darkmoon.sh run --agent pentest against the authorized staging URL set as a masked variable. reports/ is kept as an artifact, on schedule.
A nightly cron trigger on a docker agent, with the provider key and model id read from Jenkins credentials. The pipeline clones and installs the engine, runs the pentest agent, and archives reports/** after every run.
name: darkmoon-scheduled-and-deploy-pentest
on:
schedule:
- cron: "0 3 * * *" # nightly re-test
deployment_status: # run on deploy
workflow_dispatch:
jobs:
pentest:
if: ${{ github.event_name != 'deployment_status' || github.event.deployment_status.state == 'success' }}
runs-on: self-hosted # Docker + Compose v2, enough resources
steps:
- uses: ASCIT31/darkmoon-scan-action@v1
with:
target: 'TARGET: ${{ secrets.STAGING_URL }} PROGRAM="Staging (authorized)"'
provider: openrouter
model: ${{ secrets.OPENCODE_MODEL }}
api_key: ${{ secrets.OPENROUTER_API_KEY }}
# findings are uploaded as the "darkmoon-reports" artifact# .gitlab-ci.yml: GitLab CI DAST (dynamic application security testing) stage
# Set OPENROUTER_API_KEY, OPENCODE_MODEL, STAGING_URL as masked variables.
darkmoon_dast:
stage: dast
tags: [docker]
variables:
OPENROUTER_PROVIDER: "openrouter"
TARGET: 'TARGET: $STAGING_URL PROGRAM="Staging (authorized)"'
script:
- git clone --depth 1 https://github.com/ASCIT31/Dark-Moon.git darkmoon
- cd darkmoon
- chmod +x install.sh && ./install.sh
- ./darkmoon.sh run --agent pentest "$TARGET"
artifacts:
when: always
paths: [reports/]
rules:
- if: '$CI_PIPELINE_SOURCE == "schedule"'pipeline {
agent { label 'docker' } // Docker + Compose v2, enough resources
triggers { cron('H 3 * * *') } // nightly
environment {
OPENROUTER_PROVIDER = 'openrouter'
OPENROUTER_API_KEY = credentials('openrouter-api-key')
OPENCODE_MODEL = credentials('opencode-model')
}
stages {
stage('Darkmoon autonomous pentest') {
steps {
sh '''
git clone --depth 1 https://github.com/ASCIT31/Dark-Moon.git darkmoon
cd darkmoon && chmod +x install.sh && ./install.sh
./darkmoon.sh run --agent pentest "TARGET: ${STAGING_URL} PROGRAM=\"Staging (authorized)\""
'''
}
}
}
post { always { archiveArtifacts artifacts: 'reports/**', allowEmptyArchive: true } }
}How to run DAST in CI/CD with the open-source Darkmoon CLI, across GitHub Actions, GitLab CI, and Jenkins.
Add the ASCIT31/darkmoon-scan-action step to a workflow and pass an authorized target, your LLM provider, a model id, and your provider API key (as a repository secret). The open-source Darkmoon CLI then runs an autonomous penetration test in your CI/CD pipeline and uploads the Markdown findings as the darkmoon-reports build artifact. Trigger it on a schedule and on deploy. See examples/github-actions-pentest.yml.
Yes. Darkmoon runs as a dynamic application security testing (DAST) stage in GitLab CI, GitHub Actions, or Jenkins. It clones the open-source engine, installs the stack, and runs darkmoon.sh run --agent pentest against an authorized staging URL. Every finding ships with reproducible proof of exploitation. See examples/gitlab-ci-pentest.yml for a GitLab CI DAST job.
The Darkmoon CLI and the GitHub Action are open source (GPLv3) and need no license key; you only supply your own LLM provider API key. Managed scheduled orchestration, the web dashboard, and finding-to-fix remediation pull requests are paid Darkmoon Pro features.
Darkmoon runs fully self hosted on your own runner, and the Privacy Gateway tokenizes sensitive target values locally, so real IPs, hostnames, and credentials are kept off any cloud model. That lets you shift security testing left into CI/CD without shipping production data to a third party.
Darkmoon is open source (GPLv3). If it helps, a star on the main repository helps other teams find it.
Clone the Action, add your provider key as a secret, and gate builds on proven findings. The same open-source engine, in CI.