@darkmoon_ai/mcp-server
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| DARKMOON_TOKEN | No | Alternative to username/password: a pre-issued JWT | |
| DARKMOON_BASE_URL | Yes | Base URL of your Darkmoon Pro Dashboard API (required) | |
| DARKMOON_PASSWORD | No | Dashboard password | |
| DARKMOON_USERNAME | No | Dashboard username | |
| DARKMOON_TIMEOUT_MS | No | Optional per-request timeout, default 60000 | 60000 |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": true
} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| run_pentestA | Start an autonomous Darkmoon penetration test against one authorized target. The run executes in the background and can take a long time. Returns the run_id; poll it with get_run_status and read results with get_findings once a campaign exists (list_campaigns). Only use against systems the user owns or has explicit written authorization to test. Findings can include false positives and must be reviewed by a qualified human. |
| get_run_statusA | Report whether a Darkmoon run is 'running', 'completed', 'error' or 'unknown' (run log not found), with the event count and the 5 most recent events. |
| list_campaignsA | List the Darkmoon campaigns visible to the dashboard user, with ids and status. Use a campaign id with get_findings. |
| get_findingsA | Return the vulnerabilities and aggregated severity statistics for a Darkmoon campaign (read only). Each finding carries title, severity, CVSS score, category, status (exploited, confirmed or unconfirmed), endpoint and remediation guidance. Findings may contain false positives and require human review. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 4 tools
Each tool targets a distinct action (start, status, list campaigns, get findings), but the relationship between a 'run' and a 'campaign' is not fully clear, which could cause slight misselection between get_run_status and list_campaigns when checking progress.
All names follow a consistent snake_case verb_noun pattern (run_pentest, get_run_status, list_campaigns, get_findings), with clear verb prefixes that are easy to predict.
Four tools is well-scoped for a focused pentest service; each tool (start, monitor, list campaigns, read findings) earns its place without redundancy or bloat.
Core start-monitor-results workflow is covered, but notable gaps exist: no cancel/stop for long-running runs, and no explicit way to map a run_id to its resulting campaign, forcing agents to guess from list_campaigns.