S.01For AI developers

LLM & MCP security testing

LLM features and MCP servers are a new attack surface. Darkmoon's llm agent tests OpenAI-compatible, Ollama, vLLM and TGI endpoints against the OWASP LLM Top 10, and proves each issue end to end.

8
OWASP LLM Top 10 findings proven
4
Endpoint families auto-detected
50
Specialist AI agents
GPL-3.0
Open source, read every line
S.03Your wedge

Built for LLM and MCP surfaces

Not a generic scanner pointed at an API, an agent that understands the AI layer.

OWASP LLM Top 10

System-prompt leakage, prompt injection and jailbreak, insecure output handling, unbounded consumption, SSRF and unauthenticated access, with the exact request and raw response for each.

Learn more

S.04What you get
What an LLM engagement produces

01
$darkmoon run --scope identity
→AS-REP roast · 3 accounts
→Kerberoast · svc_sql cracked
→NTLM relay → DCSync
✓Domain Admin, proven

Auto-detection and dispatch

The agent fingerprints OpenAI-compatible, Ollama, vLLM and TGI endpoints and dispatches like the GraphQL and Kubernetes agents, then profiles capabilities before attacking.

02
Attack surfaceexposure

An optional bounded garak pass

A bounded garak run complements the adaptive OWASP-LLM attacks, thorough, but capped so it never turns into a stress test of your endpoint.

03
FindingsCVSS
SQL injection9.8
SSRF to metadata9.1
Broken access control8.7
JWT signature bypass7.5
Path traversal6.9

MCP tested as its own surface

Darkmoon exposes its own MCP tool layer and treats MCP servers as a first-class target, not an afterthought.

S.05Start here
The pieces that matter to you

S.06Next
Point it at your own AI endpoint

Darkmoon is open source (GPL-3.0). Clone it, authorize a target you own, and read every line.