DarkMoon is an open-source AI penetration testing platform for security teams and DevSecOps engineers. Instead of a score-based scanner, it runs a full assessment on its own: 50 specialist agents chain real exploits through a controlled MCP layer and return the exact command and raw output behind every finding.
DarkMoon funnels LLM configuration through one seam, .opencode.env, written by install.sh for a cloud provider, local Ollama/llama.cpp, or an OpenAI-compatible base URL. Its Privacy Gateway tokenizes real IPs and credentials into placeholders, so a cloud model never sees the live perimeter; the docs warn model quality decides whether the autonomous loop survives. For continuous-scanning teams, OrcaRouter adds a real option there: one OpenAI-compatible endpoint over many chat and reasoning models, with failover so a campaign doesn't die on a provider outage.
Proposal
OrcaRouter exposes many chat and reasoning models through one OpenAI-compatible API with standard API-key authentication. I propose adding it as an optional LLM provider for DarkMoon; it would not replace or modify any existing provider (Anthropic, OpenRouter, OpenAI, Ollama and llama.cpp all stay as they are).
DarkMoon already centralizes LLM settings in .opencode.env, so the expected integration point is that same seam: a base URL, an API key and a model name, matching how DarkMoon's documented OpenAI-compatible endpoint option is configured. Nothing here is implemented or tested yet; this is a proposal for your feedback first.
Why it could matter for DarkMoon users
- Automatic routing and provider failover. An autonomous campaign makes many sequential model calls; when one provider rate-limits or fails, traffic continues on another model instead of losing the run.
- Prompt caching. Long multi-agent sessions repeat a lot of context, and caching can cut cost on exactly that workload.
- Usage tracking and budgets. Useful for teams driving continuous scans from CI/CD who need per-team or per-campaign cost visibility.
Ecosystem fit
OpenAI-compatible routing is an established pattern in the tooling around DarkMoon: OrcaRouter is used with goose, promptfoo, and models.dev / OpenCode, the agent runtime DarkMoon uses as its AI brain.
Transparency
OrcaRouter runs an optional open-source partner program: approved OSS projects can receive a 5% revenue share from OrcaRouter usage attributed to their integration. Participation is not a condition for integration, and I'm happy to follow any disclosure or governance requirements DarkMoon has.
Ask
If this seems like a good fit, I'd value your opinion on the integration point and on how OrcaRouter should appear in the install.sh provider options. You can see how other open-source projects present the integration at https://www.orcarouter.ai/built-with. With your go-ahead, I'd be glad to submit an implementation PR.
I'm an engineer on the OrcaRouter team.
DarkMoon is an open-source AI penetration testing platform for security teams and DevSecOps engineers. Instead of a score-based scanner, it runs a full assessment on its own: 50 specialist agents chain real exploits through a controlled MCP layer and return the exact command and raw output behind every finding.
DarkMoon funnels LLM configuration through one seam,
.opencode.env, written byinstall.shfor a cloud provider, local Ollama/llama.cpp, or an OpenAI-compatible base URL. Its Privacy Gateway tokenizes real IPs and credentials into placeholders, so a cloud model never sees the live perimeter; the docs warn model quality decides whether the autonomous loop survives. For continuous-scanning teams, OrcaRouter adds a real option there: one OpenAI-compatible endpoint over many chat and reasoning models, with failover so a campaign doesn't die on a provider outage.Proposal
OrcaRouter exposes many chat and reasoning models through one OpenAI-compatible API with standard API-key authentication. I propose adding it as an optional LLM provider for DarkMoon; it would not replace or modify any existing provider (Anthropic, OpenRouter, OpenAI, Ollama and llama.cpp all stay as they are).
DarkMoon already centralizes LLM settings in
.opencode.env, so the expected integration point is that same seam: a base URL, an API key and a model name, matching how DarkMoon's documented OpenAI-compatible endpoint option is configured. Nothing here is implemented or tested yet; this is a proposal for your feedback first.Why it could matter for DarkMoon users
Ecosystem fit
OpenAI-compatible routing is an established pattern in the tooling around DarkMoon: OrcaRouter is used with goose, promptfoo, and models.dev / OpenCode, the agent runtime DarkMoon uses as its AI brain.
Transparency
OrcaRouter runs an optional open-source partner program: approved OSS projects can receive a 5% revenue share from OrcaRouter usage attributed to their integration. Participation is not a condition for integration, and I'm happy to follow any disclosure or governance requirements DarkMoon has.
Ask
If this seems like a good fit, I'd value your opinion on the integration point and on how OrcaRouter should appear in the
install.shprovider options. You can see how other open-source projects present the integration at https://www.orcarouter.ai/built-with. With your go-ahead, I'd be glad to submit an implementation PR.I'm an engineer on the OrcaRouter team.