The Darknode security console — a cross-platform Electron app: an AI assistant, a QEMU VM runner that can build Darknode OS, a native port scanner, DNS/WHOIS/TLS recon, a code workbench, live terminals, MCP, and enterprise governance.
Renderer (renderer/app.js — the UI: dashboard, terminal, recon, VMs, ...)
|
| contextBridge -> window.darknode (preload.js — the only exposed surface)
v
Main process (main.js — IPC handlers)
|
+-- AI streaming: Ollama (local) · Claude · OpenAI-compatible
+-- VM runner QEMU + a Darknode OS builder (pick a base, build, boot)
+-- Recon scan · dns · whois · tls · subdomains · fuzz
+-- Dev git / github · pty terminals · MCP client
+-- Governance usage ledger · compliance bundle
+-- Bridges Gmail OAuth (config-based) · net:get (SSRF-guarded fetch)
v
OS + network (sandboxed through the main process; the renderer never touches them directly)
Security boundary: the renderer has no Node access. Everything privileged goes
through preload.js's contextBridge to typed IPC handlers in main.js, where
inputs are validated (e.g. net:get blocks loopback/link-local/private hosts).
darknode-app/
├── main.js # Electron main: all IPC handlers (AI, VM, recon, git, pty, MCP)
├── preload.js # contextBridge — the window.darknode API surface
├── renderer/
│ └── app.js # UI: the section router + all views
├── lib/ # main-process modules (anthropic, governance, ...)
├── oauth.config.example.json # template for Gmail OAuth (real oauth.config.json is gitignored)
├── package.json
└── README.md
Native Gmail OAuth loads its client id/secret from oauth.config.json (gitignored)
or the DARKNODE_GMAIL_CLIENT_ID / DARKNODE_GMAIL_CLIENT_SECRET env vars — no
credentials in source. Copy the template to start:
cp oauth.config.example.json oauth.config.json # then fill in your Desktop client
git clone https://github.com/Darknode-Official/darknode-app
cd darknode-app && npm install
npm start # run in development
npm run build # package (.deb / AppImage / .exe)
npm test # run the unit/native-path/security test suite
Active. The VM runner can build and boot a customized Darknode OS on a chosen base (Debian / Ubuntu / Kali) directly from the app.
The brief and repo metadata have described this app as "offline-first"; to be exact about what that means (measured 2026-10-04):
- Works with no network: the 73 in-app offline tools (
renderer/webtools-native.js— hashing, encoding, ciphers, generators, net math), file forensics, encode/decode, notes, reference libraries, and any locally-installed CLI tool run from the Tools section. Local AI via Ollama runs on-device. There is no sign-in gate, so a network-isolated launch reaches full local capability. - Needs network: the hosted AI engines (Claude, OpenAI-compatible, the Darknode proxy), the update check (GitHub Releases), CVE/threat lookups, live recon that contacts real hosts (DNS/WHOIS/TLS/subdomains/scan/fuzz against a remote target), and the "Web tools" grid (which opens the darknode.ai catalog in the system browser).
Tool-count note: the app ships 98 native CLI-tool launchers, 73 offline in-app tools, and mirrors 843 darknode.ai Toolbox tiles (external links). The older "164+ tools" figure is not reproducible against this tree; use the measured numbers above.
EXPANSION-PLAN.md and BUILDLOG.md are planning / historical records, not a
description of the current shipped state. Treat the capability matrix
(docs/CAPABILITY-PARITY.md) and the per-item docs under docs/ as the current
ground truth.
The app runs local tools, VMs, and shells. The renderer is sandboxed from the OS;
all privileged actions cross a validated IPC boundary (see
docs/SECURITY-ELECTRON-AUDIT.md). Never commit oauth.config.json.
See LICENSE.