Top AI Repos — open-source AI, indexed and scored
Top AI Repos tracks AI repositories on GitHub and answers two different questions about each one: is it moving right now, and would you bet a product on it.
Top AI Repos tracks AI repositories on GitHub and answers two different questions about each one: is it moving right now, and would you bet a product on it.
Autonomous AI pentesting engine, continuous offensive security across web, cloud, identity, CI/CD, IaC, databases, Active Directory, Kubernetes and IoT firmware. Agentic reasoning plus real exploit execution deliver proof-based vulnerabilities. Privacy gateway: the LLM never sees your real IPs, hosts or creds, nothing leaves your perimeter.
| Date | Stars |
|---|---|
| 2026-07-31 | 793 |
| 2026-08-06 | 809 |
Today
+16 stars today
This week
— stars this week
This month
— stars this month
Momentum
124.0
growth rate 0.00%/day
<div align="center">

**The Open-Source AI-Powered Autonomous Penetration Testing Platform**
*The only autonomous AI pentester where the model never sees your real IPs, hostnames or credentials.*
[](https://www.gnu.org/licenses/gpl-3.0)
[](https://github.com/ASCIT31/Dark-Moon)
[](https://github.com/ASCIT31/Darkmoon-Benchmarks)
**As featured in** [Help Net Security](https://www.helpnetsecurity.com/2026/06/29/darkmoon-open-source-ai-pentesting-platform/) · [Cyber Security News](https://cybersecuritynews.com/darkmoon-penetration-testing-platform/) · [SecurityBrief](https://securitybrief.co.uk/story/asc-it-launches-darkmoon-for-private-ai-pentesting) · [LinuxLinks](https://www.linuxlinks.com/darkmoon-ai-powered-autonomous-penetration-testing-platform/) · [IT Brief](https://itbrief.co.uk/story/asc-it-launches-darkmoon-for-private-ai-pentesting) · [ChannelLife](https://channellife.co.uk/story/asc-it-launches-darkmoon-for-private-ai-pentesting)
[Full Documentation](docs/full.md) · [Contributing](CONTRIBUTING.md) · [License](LICENSE)
</div>
---
## What is DarkMoon?
DarkMoon is an **automated penetration testing tool** that orchestrates complete security assessments using **artificial intelligence security** agents. Built as an open-source **cybersecurity tool**, it enables organizations to run professional-grade **vulnerability assessments** without manual intervention.
Instead of replacing the pentester, DarkMoon acts as an **autonomous security testing system**, it reasons, plans, and coordinates specialized agents that execute real offensive security operations through a controlled execution layer.
<div>
<a href="https://youtu.be/1bFRVuMkZzY?si=peKxwuxzbXBnb2zO">
<img src="docs/pics/darkmoon-youtube.png" />
</a>
<p><strong>Watch DarkMoon in action, Full autonomous penetration test demo</strong></p>
</div>
---
## Why DarkMoon?
Traditional **penetration testing** is:
- ⏱️ **Time-consuming**, manual testing takes weeks
- 💰 **Expensive**, expert consultants cost thousands per day
- 🔄 **Inconsistent**, results vary by tester expertise
- 📊 **Hard to scale**, limited by human resources
DarkMoon solves this with **AI penetration testing**:
- 🤖 **AI-powered pentesting**, autonomous agents conduct full security assessments end-to-end
- 🛡️ **Security by design**, the AI never directly executes tools; all actions flow through a controlled MCP interface
- 🕶️ **Privacy gateway (reversible local tokenization)**, the AI **never sees your real sensitive values**. IPs, hostnames, domains, URLs, emails, credentials and internal paths are replaced by deterministic placeholders (`IP_PRIVATE_001`, …); real values are injected **locally, right before a tool runs**, and masked back out of every result. **No sensitive data ever leaves your perimeter to the LLM provider**, use Claude's power under strict data-sovereignty constraints. Exfiltration attempts are blocked.
- ♾️ **Pentesting automation for CI/CD**, run **automated security testing** post-build to catch critical vulnerabilities before production
- 🔧 **50+ integrated tools**, a comprehensive **penetration testing tools suite** (Nuclei, NetExec, BloodHound, sqlmap, Naabu, httpx, ffuf, and more)
- 📈 **Adaptive multi-agent methodology**, specialized agents for Web, Active Directory, Kubernetes, Network, CMS, and more
- 📝 **Vulnerability reporting automation**, structured, evidence-based reports generated automatically
Perfect for **security teams**, **DevSecOps engineers**, **ethical hacking** professionals, and organizations of all sizes.
---
## 📊 Benchmark: 57 real vulnerabilities on OWASP Juice Shop
Real, reproducible **black-bExcerpt of 15,050 characters
Read on GitHub19
12
3
1
1
1
1
1
Would you bet a product on this? Bounded 0–100 and slow moving.
matched fp:6c8dad3e7a7b2137, topic:ai-agents, topic:autonomous-agents, topic:multi-agent-systems