Skip to content

About

Darknode Desktop — cross-platform cybersecurity workstation: native scanners, terminals, VMs, and a multi-engine AI assistant (local Ollama + hosted). Windows, macOS, Linux.

Topics

Resources

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Repository files navigation

Darknode

Darknode (desktop app)

The Darknode security console — a cross-platform Electron app: an AI assistant, a QEMU VM runner that can build Darknode OS, a native port scanner, DNS/WHOIS/TLS recon, a code workbench, live terminals, MCP, and enterprise governance.

Architecture

   Renderer  (renderer/app.js — the UI: dashboard, terminal, recon, VMs, ...)
        |
        |  contextBridge  ->  window.darknode   (preload.js — the only exposed surface)
        v
   Main process  (main.js — IPC handlers)
        |
        +-- AI          streaming: Ollama (local) · Claude · OpenAI-compatible
        +-- VM runner   QEMU + a Darknode OS builder (pick a base, build, boot)
        +-- Recon       scan · dns · whois · tls · subdomains · fuzz
        +-- Dev         git / github · pty terminals · MCP client
        +-- Governance  usage ledger · compliance bundle
        +-- Bridges     Gmail OAuth (config-based) · net:get (SSRF-guarded fetch)
        v
   OS + network  (sandboxed through the main process; the renderer never touches them directly)

Security boundary: the renderer has no Node access. Everything privileged goes through preload.js's contextBridge to typed IPC handlers in main.js, where inputs are validated (e.g. net:get blocks loopback/link-local/private hosts).

Project Structure

darknode-app/
├── main.js                    # Electron main: all IPC handlers (AI, VM, recon, git, pty, MCP)
├── preload.js                 # contextBridge — the window.darknode API surface
├── renderer/
│   └── app.js                 # UI: the section router + all views
├── lib/                       # main-process modules (anthropic, governance, ...)
├── oauth.config.example.json  # template for Gmail OAuth (real oauth.config.json is gitignored)
├── package.json
└── README.md

Configuration

Native Gmail OAuth loads its client id/secret from oauth.config.json (gitignored) or the DARKNODE_GMAIL_CLIENT_ID / DARKNODE_GMAIL_CLIENT_SECRET env vars — no credentials in source. Copy the template to start:

cp oauth.config.example.json oauth.config.json   # then fill in your Desktop client

Installation

git clone https://github.com/Darknode-Official/darknode-app
cd darknode-app && npm install
npm start                      # run in development
npm run build                  # package (.deb / AppImage / .exe)
npm test                       # run the unit/native-path/security test suite

Status

Active. The VM runner can build and boot a customized Darknode OS on a chosen base (Debian / Ubuntu / Kali) directly from the app.

What works offline vs online

The brief and repo metadata have described this app as "offline-first"; to be exact about what that means (measured 2026-10-04):

  • Works with no network: the 73 in-app offline tools (renderer/webtools-native.js — hashing, encoding, ciphers, generators, net math), file forensics, encode/decode, notes, reference libraries, and any locally-installed CLI tool run from the Tools section. Local AI via Ollama runs on-device. There is no sign-in gate, so a network-isolated launch reaches full local capability.
  • Needs network: the hosted AI engines (Claude, OpenAI-compatible, the Darknode proxy), the update check (GitHub Releases), CVE/threat lookups, live recon that contacts real hosts (DNS/WHOIS/TLS/subdomains/scan/fuzz against a remote target), and the "Web tools" grid (which opens the darknode.ai catalog in the system browser).

Tool-count note: the app ships 98 native CLI-tool launchers, 73 offline in-app tools, and mirrors 843 darknode.ai Toolbox tiles (external links). The older "164+ tools" figure is not reproducible against this tree; use the measured numbers above.

Planning documents

EXPANSION-PLAN.md and BUILDLOG.md are planning / historical records, not a description of the current shipped state. Treat the capability matrix (docs/CAPABILITY-PARITY.md) and the per-item docs under docs/ as the current ground truth.

Security

The app runs local tools, VMs, and shells. The renderer is sandboxed from the OS; all privileged actions cross a validated IPC boundary (see docs/SECURITY-ELECTRON-AUDIT.md). Never commit oauth.config.json.

License

See LICENSE.

About

Darknode Desktop — cross-platform cybersecurity workstation: native scanners, terminals, VMs, and a multi-engine AI assistant (local Ollama + hosted). Windows, macOS, Linux.

Topics

Resources

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages