跳到主要内容

darkmoon

❖ Communityv0.1.0

Triage the findings file of a Darkmoon autonomous pentest scan (JSON or SARIF): filter by severity and proof status, get a severity-sorted summary and a pass/fail gate for a release. Read-only and offline: no network, no subprocess, no credentials, standard library only. Darkmoon is open source (GPL-3.0); its web dashboard and remediation agent are Pro and are not used here.

Open in Hermes Desktop
hermes plugins install darkmoon

What it adds

Tools 1

darkmoon_findings

README

From the reviewed commit 4a24b4e ↗; it updates when the author re-pins.

darkmoon: Hermes plugin for Darkmoon scan findings

Darkmoon is an open source (GPL-3.0) autonomous AI penetration testing platform. Its engine and CLI are open source, and a scan produces a findings file (JSON, or SARIF through the Darkmoon GitHub Action). This plugin gives a Hermes agent one tool to read that file and triage it.

The web dashboard and the remediation to pull request agent of Darkmoon are Pro features. This plugin does not use them and does not talk to any Darkmoon service.

Tool

darkmoon_findings reads a findings document and returns:

Field Meaning
findings kept findings, most severe first, all original fields preserved
total number of kept findings
severity_counts kept findings per severity
highest_severity most severe rating kept, or none
gate_failed true when a kept finding reaches fail_on
markdown_report severity-sorted Markdown table, ready for a chat or a ticket

Arguments: exactly one of path (local .json or .sarif, max 10 MB) or findings_json (inline string); min_severity (default info); only_proven (keep exploited and confirmed JSON findings); fail_on (never, low, medium, high, critical; default high).

Accepted input: a JSON array of findings, an object with a findings or data array, or SARIF 2.1.0 (severity comes from security-severity when present, otherwise from the SARIF level). Findings with no recognised severity are kept at info and never trip the gate.

Disclosure

  • Read-only. It never runs a scan, never starts a process, never opens a network connection and needs no credentials or environment variables.
  • It reads only the single file path you give it, and only if it ends in .json or .sarif.
  • Standard library only, no Python dependencies.

Install

hermes plugins install darkmoon

Example

Run a scan with the Darkmoon CLI or GitHub Action, then ask the agent: "Triage findings.json, only proven findings, and tell me whether the release should be blocked on high severity." The agent calls darkmoon_findings with path: findings.json, only_proven: true, fail_on: high.

Develop

python3 -m pytest tests
hermes plugins validate .

License: GPL-3.0-only.

← Back to the catalog · catalog built Oct 5, 2026