Skip to main content
ClaudeWave
ASCIT31 avatar
ASCIT31

darkmoon-mcp-server

View on GitHub

Standalone MCP server for Darkmoon (@darkmoon_ai/mcp-server): run_pentest/get_run_status/list_campaigns/get_findings over stdio. Requires a Darkmoon Pro endpoint; engine+CLI are OSS (GPL-3.0).

MCP ServersOfficial Registry0 stars0 forks● TypeScriptGPL-3.0Updated yesterday
ClaudeWave Trust Score
87/100
✓ Trusted
Passed
  • ✓Open-source license (GPL-3.0)
  • ✓Actively maintained (<30d)
  • ✓Clear description
  • ✓Documented (README)
Last scanned: 10/7/2026
Install in Claude Code / Claude Desktop
Method: NPX · args
Claude Code CLI
claude mcp add darkmoon -- npx -y args
claude_desktop_config.json (Claude Desktop)
{
  "mcpServers": {
    "darkmoon": {
      "command": "npx",
      "args": ["-y", "args"]
    }
  }
}
1. Run the command above in your terminal (Claude Code), or paste the JSON config into claude_desktop_config.json (Claude Desktop).
2. Replace any <placeholder> values with your API keys or paths.
3. Restart Claude. The MCP server and its tools appear automatically.
Use cases

MCP Servers overview

# @darkmoon_ai/mcp-server

A [Model Context Protocol](https://modelcontextprotocol.io) server that lets an MCP client (Claude Desktop, Goose, Continue, LibreChat, ...) drive [Darkmoon](https://github.com/ASCIT31/Dark-Moon), an open source (GPL-3.0) autonomous AI penetration testing platform.

## Requires Darkmoon Pro

The Darkmoon engine and CLI are open source. This server talks to the **Darkmoon Dashboard API**, which is part of **Darkmoon Pro** and always self-hosted: there is no public hosted endpoint, so you supply the base URL of your own instance. It does not work against the open source CLI alone.

## Tools

| Tool | Description |
|---|---|
| `run_pentest` | Start an autonomous pentest against one authorized target and return the `run_id` |
| `get_run_status` | Report `running`, `completed`, `error` or `unknown` for a run, from its run log |
| `list_campaigns` | List campaigns visible to the dashboard user (read only) |
| `get_findings` | Vulnerabilities and severity statistics for a campaign (read only) |

Only run assessments against systems you own or are explicitly authorized in writing to test. Findings can include false positives and must be reviewed by a qualified human.

## Configuration

| Variable | Description |
|---|---|
| `DARKMOON_BASE_URL` | Base URL of your Darkmoon Pro Dashboard API (required) |
| `DARKMOON_USERNAME`, `DARKMOON_PASSWORD` | Dashboard credentials; a JWT is requested on each call and never cached |
| `DARKMOON_TOKEN` | Alternative to username/password: a pre-issued JWT |
| `DARKMOON_TIMEOUT_MS` | Optional per-request timeout, default 60000 |

## Client configuration

Claude Desktop (`claude_desktop_config.json`), Continue and LibreChat use the same `mcpServers` shape:

```json
{
  "mcpServers": {
    "darkmoon": {
      "command": "npx",
      "args": ["-y", "@darkmoon_ai/mcp-server"],
      "env": {
        "DARKMOON_BASE_URL": "https://darkmoon.example.internal",
        "DARKMOON_USERNAME": "your-dashboard-user",
        "DARKMOON_PASSWORD": "your-dashboard-password"
      }
    }
  }
}
```

Goose (`~/.config/goose/config.yaml`):

```yaml
extensions:
  darkmoon:
    type: stdio
    enabled: true
    name: darkmoon
    cmd: npx
    args: ["-y", "@darkmoon_ai/mcp-server"]
    envs:
      DARKMOON_BASE_URL: https://darkmoon.example.internal
      DARKMOON_USERNAME: your-dashboard-user
      DARKMOON_PASSWORD: your-dashboard-password
```

Continue (`.continue/mcpServers/darkmoon.yaml`):

```yaml
name: Darkmoon
version: 0.1.0
schema: v1
mcpServers:
  - name: darkmoon
    command: npx
    args: ["-y", "@darkmoon_ai/mcp-server"]
    env:
      DARKMOON_BASE_URL: https://darkmoon.example.internal
      DARKMOON_USERNAME: your-dashboard-user
      DARKMOON_PASSWORD: your-dashboard-password
```

## Develop

```bash
npm install
npm run build
npm test      # mocked Dashboard API, in-memory MCP client and a real stdio process
```

## License

GPL-3.0-only, same as Darkmoon.

What people ask about darkmoon-mcp-server

What is ASCIT31/darkmoon-mcp-server?

+

ASCIT31/darkmoon-mcp-server is mcp servers for the Claude AI ecosystem. Standalone MCP server for Darkmoon (@darkmoon_ai/mcp-server): run_pentest/get_run_status/list_campaigns/get_findings over stdio. Requires a Darkmoon Pro endpoint; engine+CLI are OSS (GPL-3.0). It has 0 GitHub stars and its last recorded update is dated 2026-10-05.

How do I install darkmoon-mcp-server?

+

You can install darkmoon-mcp-server by cloning the repository (https://github.com/ASCIT31/darkmoon-mcp-server) or following the README instructions on GitHub. ClaudeWave also provides quick install blocks on this page.

Is ASCIT31/darkmoon-mcp-server safe to use?

+

Our security agent has analyzed ASCIT31/darkmoon-mcp-server and assigned a Trust Score of 87/100 (tier: Trusted). See the full breakdown of passed checks and flags on this page.

Who maintains ASCIT31/darkmoon-mcp-server?

+

ASCIT31/darkmoon-mcp-server is maintained by ASCIT31. The last recorded GitHub activity is dated 2026-10-05, with 4 open issues.

Are there alternatives to darkmoon-mcp-server?

+

Yes. On ClaudeWave you can browse similar mcp servers at /categories/mcp, sorted by popularity or recent activity.

Deploy darkmoon-mcp-server to your cloud

Ship this repo to production in minutes. Each platform spins up its own environment with editable env vars.

Maintain this repo? Add a badge to your README

Drop the badge into your GitHub README to show it's tracked on ClaudeWave. Each badge links back to this page and reflects the live Trust Score.

Featured on ClaudeWave: ASCIT31/darkmoon-mcp-server
[![Featured on ClaudeWave](https://claudewave.com/api/badge/ascit31-darkmoon-mcp-server)](https://claudewave.com/repo/ascit31-darkmoon-mcp-server)
<a href="https://claudewave.com/repo/ascit31-darkmoon-mcp-server"><img src="https://claudewave.com/api/badge/ascit31-darkmoon-mcp-server" alt="Featured on ClaudeWave: ASCIT31/darkmoon-mcp-server" width="320" height="64" /></a>

More MCP Servers

darkmoon-mcp-server alternatives