Darkmoon icon

Darkmoon

Start authorized autonomous AI pentest runs, poll status, list campaigns and read findings on your own self-hosted Darkmoon Pro through MCP.

asc-it/darkmoon · v0.1.0 · Tools & Integrations

ASC-ITsafe

Trust Score

83

Security

100

Surfaces

2

What is Darkmoon?

Darkmoon is a published tools & integrations plugin for AI coding agents in the mcp ecosystem, developed by ASC-IT and distributed through the HOL AI plugin registry. Start authorized autonomous AI pentest runs, poll status, list campaigns and read findings on your own self-hosted Darkmoon Pro through MCP.

Canonical slug
asc-it/darkmoon
Version
v0.1.0 · updated Oct 5, 2026

Trust & Reputation

HOL Trust Score
83

Factor Analysis

Per-metric points (0–100 each) combined via a weighted average into the overall score.

Installability
100pts
Maintenance
100pts
MCP Posture
100pts
Plugin Security
100pts
Provenance
70pts
Publisher Quality
75pts

Registry Snapshot

Publisher verification
No
Marketplace source
Unknown
Scanner
Broker fallback
Safety label
safe
Digest verified
Yes
1 bundled skill — copy or download SKILL.mdOpen skills

Trust & reputation

Trust & Reputation

HOL Trust Score
83

Factor Analysis

Per-metric points (0–100 each) combined via a weighted average into the overall score.

Installability
100pts
Maintenance
100pts
MCP Posture
100pts
Plugin Security
100pts
Provenance
70pts
Publisher Quality
75pts

Provenance

Plugin root
.
Source repo
https://github.com/ASCIT31/darkmoon-mcp-server
Source commit
eb39b74ce0e8…
Publisher verified
No
Owner verified
Not owner verified

Continuous scanner CI not detected

This plugin remains listed. Its overall trust score is reduced by 10% because security checks are not maintained in the source repository's CI.

Optional: maintain the scanner in the source repository's CI to receive the full trust score. Listing does not require that change.

Verified badge not detected

Add the HOL verified badge to the repository README to score +2% trust. Plugin owners can open that pull request from Guard Plugins.

Security Posture

safe
Safety label
100
Security score
0
High findings
Provider
registry-broker-fallback
Grade
A · safe
Version
Unknown
cisco-skill-scanner: unknown

Findings

infoskill-securityskill-scan.unavailable

Cisco skill scanner timed out after 60000 ms

Darkmoon — Frequently asked questions

What is Darkmoon?
Darkmoon is an AI plugin in the HOL registry. Start authorized autonomous AI pentest runs, poll status, list campaigns and read findings on your own self-hosted Darkmoon Pro through MCP.
How do I install Darkmoon?
Install Darkmoon in your harness: Codex — codex plugin marketplace add ASCIT31/darkmoon-mcp-server; Claude Code — /plugin marketplace add ASCIT31/darkmoon-mcp-server; Antigravity CLI — npx skills add ASCIT31/darkmoon-mcp-server. Full step-by-step guidance is on the HOL plugin page.
How do I install Darkmoon in Codex?
To install Darkmoon in Codex, start with codex plugin marketplace add ASCIT31/darkmoon-mcp-server. The complete step-by-step install guide for Codex is on the HOL plugin page.
How do I install Darkmoon in Claude Code?
To install Darkmoon in Claude Code, start with /plugin marketplace add ASCIT31/darkmoon-mcp-server. The complete step-by-step install guide for Claude Code is on the HOL plugin page.
How do I install Darkmoon in Antigravity CLI?
To install Darkmoon in Antigravity CLI, start with npx skills add ASCIT31/darkmoon-mcp-server. The complete step-by-step install guide for Antigravity CLI is on the HOL plugin page.
Is Darkmoon free?
Pricing for Darkmoon is published on its HOL plugin page when the maker schedules a launch.
Who publishes Darkmoon?
Darkmoon is published by ASC-IT and listed on HOL.
Is Darkmoon available now?
Darkmoon availability is listed on its HOL plugin page.

Install Guidance

Install in Claude Code

Install through the Claude Code plugin marketplace.

Claude Code plugin docs
  1. 1

    Add the marketplace

    Run this inside a Claude Code session.

    claude code
  2. 2

    Install the plugin

    Use the plugin name and the marketplace name shown by the previous command.

    claude code
  3. 3

    Scripted alternative

    Non-interactive equivalent for scripts and CI pipelines. Add --scope project to pin the install to one repository.

    shell

Plugin Manifest

{
  "name": "darkmoon",
  "version": "0.1.0",
  "description": "Drive a self-hosted Darkmoon Pro instance over MCP: start an authorized autonomous AI pentest run, poll its status, list campaigns and read findings. Requires your own Darkmoon Pro dashboard; run_pentest is not read only.",
  "author": {
    "name": "ASC-IT",
    "url": "https://github.com/ASCIT31"
  },
  "homepage": "https://github.com/ASCIT31/Dark-Moon",
  "repository": "https://github.com/ASCIT31/darkmoon-mcp-server",
  "license": "GPL-3.0-only",
  "keywords": [
    "darkmoon",
    "mcp",
    "pentest",
    "security",
    "vulnerability-scanner",
    "ai-agent",
    "codex"
  ],
  "skills": "./",
  "mcpServers": "./.registry/mcp.json",
  "interface": {
    "displayName": "Darkmoon",
    "developerName": "ASC-IT",
    "shortDescription": "Run authorized autonomous AI pentests on your self-hosted Darkmoon Pro",
    "longDescription": "Darkmoon is an open source (GPL-3.0) autonomous AI penetration testing platform. This plugin exposes four MCP tools (run_pentest, get_run_status, list_campaigns, get_findings) that talk to the Dashboard API of your own self-hosted Darkmoon Pro instance. There is no public hosted endpoint: you supply DARKMOON_BASE_URL and dashboard credentials. run_pentest starts a real assessment and is not read only; only target systems you own or are explicitly authorized in writing to test. Findings can include false positives and must be reviewed by a qualified human.",
    "category": "Security",
    "capabilities": [
      "Interactive",
      "Read",
      "Write"
    ],
    "websiteURL": "https://dark-moon.org",
    "privacyPolicyURL": "https://github.com/ASCIT31/darkmoon-mcp-server/blob/main/SECURITY.md",
    "termsOfServiceURL": "https://github.com/ASCIT31/darkmoon-mcp-server/blob/main/LICENSE",
    "defaultPrompt": [
      "Start an authorized Darkmoon pentest on my staging host",
      "Show the status of my latest Darkmoon run",
      "List the high severity findings of my Darkmoon campaign"
    ],
    "brandColor": "#4F46E5",
    "composerIcon": "./assets/icon.svg",
    "logo": "./assets/icon.svg"
  },
  "registryIndexVersion": 5
}

Marketplace Source

Repo URL
https://github.com/ASCIT31/darkmoon-mcp-server
Marketplace path
Unknown
Source path
.
Install policy
Unspecified

Skills

1 SKILL.md file ship with this plugin. Preview, copy, or download each one, then install them with the Skills CLI.

Share
skills-cli
  • darkmoon-pentest

    plugins/darkmoon/skills/darkmoon-pentest/SKILL.md

    Use when the user wants to start or follow an autonomous penetration test with their own Darkmoon Pro instance, check the status of a Darkmoon run, list Darkmoon campaigns, or read and triage the findings of a campaign. Requires the darkmoon MCP server and an authorized target.

    SKILL.md content is not in this snapshot. Open the raw file to copy it from the source repository.

File Inventory

.codex-plugin/plugin.json

plugin-manifest

1,926 bytes

0994b14740b5eb91…

.mcp.json

file

304 bytes

6d5b28f9f90d8e0f…

.registry/mcp.json

mcp-config

222 bytes

70e983cd86f19756…

assets/icon.svg

asset

481 bytes

e00149390bc3e3f5…

gemini-extension.json

file

832 bytes

8c57f334a65b49f9…

GEMINI.md

file

1,650 bytes

fd990f8bbe8c8940…

package-lock.json

file

41,411 bytes

037b7ea8a4ff86a4…

package.json

file

1,321 bytes

2aaa0f18d38fe6bf…

plugins/darkmoon/skills/darkmoon-pentest/SKILL.md

skill

1,974 bytes

5817937a02976111…

README.md

file

2,956 bytes

014ff2a8fc5955ee…

SECURITY.md

file

1,664 bytes

cb65164a657a7e1f…

tsconfig.json

file

258 bytes

35ff006732eb9ee8…