Skip to content

Add Dark-Moon (open source autonomous AI DAST) - #442

Open
Dark-Moon-X wants to merge 1 commit into
analysis-tools-dev:masterfrom
Dark-Moon-X:add-darkmoon
Open

Dark-Moon-X wants to merge 1 commit into
analysis-tools-dev:masterfrom
Dark-Moon-X:add-darkmoon

Conversation

@Dark-Moon-X

Copy link
Copy Markdown

Adds Dark-Moon, an open source (GPL-3.0) autonomous AI penetration testing tool for web, Active Directory, Kubernetes and API, with proof of exploitation on every finding and a local Privacy Gateway so the model never sees real IPs, hosts or credentials. Repo https://github.com/ASCIT31/Dark-Moon , site https://dark-moon.org

@github-actions github-actions Bot added the stale label Sep 12, 2026
@github-actions github-actions Bot closed this Sep 19, 2026
@mre mre reopened this Sep 19, 2026
@mre mre removed the stale label Sep 19, 2026
@mre

mre commented Sep 19, 2026

Copy link
Copy Markdown
Member

Reopening this: the stale bot closed it without a review. Thanks for the submission, and sorry it went unanswered. The project now meets our published maturity criteria, and its live-target security testing is a good fit for the catalog.

A few concrete changes are needed in data/tools/dark-moon.yml:

  • Replace categories: [dast] with categories: [linter]. The current schema does not have a dast category; security is already an appropriate tag.
  • Remove the kubernetes tag unless you also add a definition to data/tags.yml. The existing security, api, and web tags are valid.
  • Please narrow the description rather than promising proof of exploitation on every finding or guaranteeing that the model never sees sensitive data. For example:

Self-hosted AI-assisted penetration-testing platform that orchestrates security tools against live web, API, Active Directory and Kubernetes targets. Runs tools in Docker through MCP and collects command output and findings. Supports local or cloud LLMs and configurable local tokenization of sensitive data.

Please keep features exclusive to the Pro edition separate from the description of the open-source core. We have just added CI checks; the renderer should help catch the category and tag issues, while the contribution checker assesses repository maturity separately.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants