Trigger a Darkmoon AI penetration test against a target you are authorised to assess, pull back the findings, and review the fix pull requests it prepares. Talks to your self-hosted Darkmoon Dashboard API.
A Dify tool plugin for Darkmoon, the local, privacy first autonomous AI penetration testing engine. It lets a Dify agent or workflow trigger a Darkmoon pentest against a target you are authorised to assess, pull back the findings, and review the fix pull requests Darkmoon prepares, so security testing fits into your Dify apps like any other tool.
Darkmoon runs and validates security tests. It does not, and this plugin does not, guarantee that a system is secure. Findings can include false positives and must be reviewed by a qualified human. Only run assessments against systems you own or have explicit written authorisation to test. This plugin never merges a pull request; every fix is left for a person to review and merge.
The plugin talks to the Darkmoon Dashboard API, the FastAPI service shipped with Darkmoon (typically on port ). Darkmoon is self hosted, so there is no public endpoint; you point the plugin at your own instance. Darkmoon issues a short lived JWT from , so the plugin logs in at run time using the stored credentials.
Configure the provider with:
Credential validation performs a real login, so a wrong URL or bad credentials fail fast.
Remediation is optional and is a paid Darkmoon Pro feature. The open source Darkmoon focuses on finding, proving and reporting findings locally; the remediation feature that prepares fix pull requests is Pro. When enabled it needs a credential reference, an opaque id of a credential stored in Darkmoon's encrypted vault (created in the dashboard), not a raw token. Raw source control secrets never travel through this plugin, and the remediation agent only ever prepares a pull request for human review; it never merges. This plugin can read the prepared pull requests through the API regardless of edition.
Darkmoon keeps assessment work on your own infrastructure and applies a privacy gateway so the language model works over placeholders rather than your real hosts, IPs and credentials. This plugin sends data only to the base URL you configure and stores nothing of its own. See PRIVACY.md.
The API client () is dependency free and transport injected, so its logic is unit tested without a network. A full end to end run additionally requires a running Darkmoon instance pointed at an authorised target.
Source repository: https://github.com/ASCIT31/dify-plugin-darkmoon
Darkmoon: https://github.com/ASCIT31/Dark-Moon
MIT, see LICENSE. Not affiliated with Dify; "Dify" is a trademark of its respective owner.
Some outbound calls build their address at runtime, so the list may be incomplete.
Last checked 09/30/2026 01:36 PM · version 0.1.0