Auto-detection and dispatch
The agent fingerprints OpenAI-compatible, Ollama, vLLM and TGI endpoints and dispatches like the GraphQL and Kubernetes agents, then profiles capabilities before attacking.
LLM features and MCP servers are a new attack surface. Darkmoon's llm agent tests OpenAI-compatible, Ollama, vLLM and TGI endpoints against the OWASP LLM Top 10, and proves each issue end to end.
Not a generic scanner pointed at an API, an agent that understands the AI layer.
System-prompt leakage, prompt injection and jailbreak, insecure output handling, unbounded consumption, SSRF and unauthenticated access, with the exact request and raw response for each.
Learn moreThe agent fingerprints OpenAI-compatible, Ollama, vLLM and TGI endpoints and dispatches like the GraphQL and Kubernetes agents, then profiles capabilities before attacking.
A bounded garak run complements the adaptive OWASP-LLM attacks, thorough, but capped so it never turns into a stress test of your endpoint.
Darkmoon exposes its own MCP tool layer and treats MCP servers as a first-class target, not an afterthought.
8 OWASP LLM Top 10 findings proven end to end on a real endpoint.
How prompt tokenization keeps your infrastructure out of the model.
Trigger a run from n8n, wire it into CI, or keep it fully local.
Darkmoon is open source (GPL-3.0). Clone it, authorize a target you own, and read every line.