Skip to content

feat(toolkits): add DarkmoonToolkit for autonomous pentest campaigns - #4387

Open
MBK-fr wants to merge 4 commits into
camel-ai:masterfrom
MBK-fr:darkmoon-contrib
Open

MBK-fr wants to merge 4 commits into
camel-ai:masterfrom
MBK-fr:darkmoon-contrib

Conversation

@MBK-fr

@MBK-fr MBK-fr commented Oct 2, 2026

Copy link
Copy Markdown

Adds DarkmoonToolkit, so a CAMEL agent can drive a self-hosted Darkmoon (GPL-3.0 autonomous AI pentest platform): darkmoon_run_pentest (start a campaign, optionally wait and return findings plus severity stats), darkmoon_get_findings, darkmoon_list_campaigns.

Shape mirrors recent merged vendor toolkits such as PlivoToolkit (#4194): camel/toolkits/darkmoon_toolkit.py, export in camel/toolkits/__init__.py, test/toolkits/test_darkmoon_toolkit.py, examples/toolkits/darkmoon_toolkit.py.

Design notes

  • Calls the Darkmoon Dashboard API of an instance the user operates (DARKMOON_BASE_URL / DARKMOON_USERNAME / DARKMOON_PASSWORD, via api_keys_required; JWT login cached). There is no public hosted endpoint.
  • Open source vs Pro is stated in the class docstring: the Darkmoon engine and CLI are open source, the Dashboard API used here is Pro, and Darkmoon's Pro remediation-to-PR feature is deliberately not exposed.
  • Uses httpx, already a core dependency, so no new dependency and no pyproject change.
  • Follows the CONTRIBUTING naming rule (darkmoon_ prefix) and returns an error string on failure like other toolkits. darkmoon_run_pentest is marked @manual_timeout because a run is long and manages its own max_wait_seconds; it only reports a campaign created by that run (never a pre-existing one) and reports timed_out rather than looping forever.
  • Error messages surface the API detail only, never credentials.

Testing: 14 unit tests with an in-memory fake API over httpx.MockTransport (login caching, bearer header, missing credentials, no password leak, network error, no-wait, wait/poll, log-not-yet-created 404, timeout, stale-campaign guard). pytest test/toolkits/test_darkmoon_toolkit.py passes locally, ruff format --check, ruff check and mypy clean on the new files. Tool schemas generate correctly through FunctionTool.get_openai_tool_schema(). No live Darkmoon instance is required to run the tests.

Findings can include false positives and require human review; only test systems you are authorised to test.

馃 Generated with Claude Code

https://claude.ai/code/session_014HBQNzAf5C2E3MiJC48HQw

@coderabbitai

coderabbitai Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

鈿欙笍 Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Advanced

Run ID: a6822745-a772-4875-a0e9-104ba69ff301

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 馃攳 Trigger review
  • Autopilot 路 Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

鉂わ笍 Share

Comment @coderabbitai help to get the list of available commands.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant