No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by ASCIT31 · MCP Server · ★ 898
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is Dark-Moon safe to install? View the security audit →
The Open-Source AI-Powered Autonomous Penetration Testing Platform Full Documentation · Contributing · License What is DarkMoon? DarkMoon is an automated penetration testing tool that orchestrates complete security assessments using artificial intelligence security agents. Built as an open-source cybersecurity tool, it enables organizations to run professional-grade vulnerability assessments without manual intervention. Instead of replacing the pentester, DarkMoon acts as an autonomous security testing system — it reasons, plans, and coordinates specialized agents that execute real offensive security operations through a controlled execution layer. Watch DarkMoon in action — Full autonomous penetration test demo Why DarkMoon? Traditional penetration testing is: ⏱️ Time-consuming — manual testing takes weeks 💰 Expensive — expert consultants cost thousands per day 🔄 Inconsistent — results var
| Stars | 898 |
| Forks | 154 |
| Language | Python |
| Category | MCP Server |
| License | GPL-3.0 |
| Quality Score | 71.5080512630968/100 |
| Open Issues | 3 |
| Last Updated | 2026-09-08 |
| Created | 2024-11-26 |
| Platforms | browser, k8s, mcp, python |
| Est. Tokens | ~16k |
These tools work well together with Dark-Moon for enhanced workflows:
Looking for a Dark-Moon alternative? If you're comparing Dark-Moon with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.
Turn Claude Code into your offensive security research assistant. Specialized AI subagents for authorized pene
Open-source AI-augmented offensive security harness. 13+ autonomous agents, 150+ LLM providers, 5,300+ models,
PentestCode - Multi-agent AI penetration testing system with persistent engagement state, strategic coordinati
MCP-native security automation workbench (SDK + CLI + MCP) — authorized testing + static AI/MCP attack-surface
Open-source AI pentester that proves every finding. Machine oracles re-run each exploit; verified bugs ship a
The SmythOS Runtime Environment (SRE) is an open-source, cloud-native runtime for agentic AI. Secure, modular,
Explore other popular mcp server tools:
Dark-Moon is Autonomous AI pentesting engine across web, cloud, identity, CI/CD, IaC, databases, Active Directory, Kubernetes, IoT firmware and AI/LLM endpoints (OWASP LLM Top 10). Real exploits with proof for eve. It is categorized as a MCP Server with 898 GitHub stars.
Dark-Moon is primarily written in Python. It covers topics such as active-directory, ai-agents, ai-red-team.
You can find installation instructions and usage details in the Dark-Moon GitHub repository at github.com/ASCIT31/Dark-Moon. The project has 898 stars and 154 forks, indicating an active community.
Dark-Moon is released under the GPL-3.0 license, making it free to use and modify according to the license terms.
The top alternatives to Dark-Moon on Agent Skills Hub include pentest-ai-agents, CyberStrike, pentestcode. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: