An intelligent Open Source Intelligence investigation system with multiple MCP-based tools for username, email, web, and profile investigations
The server provides 9 OSINT tools with visible schemas and descriptions. However, several critical quality issues prevent a higher score: (1) Naming is weak, tools like 'analyze_link', 'investigate_email', and 'investigate_username' use generic verbs that don't clearly indicate the specific action (analyze what? investigate how?). Per the rubric baseline, 90% of A+ tools start with action verbs; these do, but they're vague. (2) Descriptions are present but brief (avg ~100-150 chars), lacking context for when to use each tool vs. alternatives. The rubric baseline is 194 chars avg for tool descriptions. (3) Parameter descriptions are sparse or absent in some cases, e.g., 'region' and 'safesearch' parameters in web_search have descriptions, but the rationale for these options is not explained. (4) Output schemas are NOT documented, tools return JSON responses, but no schema is provided for what fields clients should expect. Per the rubric, 100% of A+ tools document return types. (5) Error handling is basic, errors are returned as JSON strings but lack recovery guidance (e.g., 'If query is empty, provide a search term' instead of bare 'Query is required'). (6) No tool annotations (readOnlyHint, destructiveHint, idempotentHint) despite all being READ_ONLY. (7) One tool (check_*_status tools) has no meaningful input parameters and adds little value, they're discovery helpers, not core OSINT functionality. Overall, the server is functional but lacks polish and LLM-optimization.
Analyze a URL for GitHub profiles, social media, and generic web content with deep intelligence extraction
Check if DuckDuckGo search tool is available
Check if Mosint tool is available and working
Check if Sherlock tool is available and working
Investigate email address for breaches, social accounts, and intelligence using Mosint
Search for username across 400+ social media platforms using Sherlock
Search for news articles using DuckDuckGo
No output schemas documented. Tools return JSON responses but clients cannot know what fields to expect.
Weak tool naming conventions. 'analyze_link', 'investigate_email', 'investigate_username' use vague verbs that don't clearly convey the action. Prefer more specific verbs: 'scrape_link_profile', 'query_email_breaches', 'search_username_across_platforms'.
Minimal error recovery guidance. Errors are returned as JSON strings (e.g., 'Query is required') but lack actionable next steps.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 46 | 2026-07-28+ | v2 |
| 2026-03-09 | D | 50 | - | v1 |
Scrape profile pages found by Sherlock for additional OSINT intelligence
Search the web using DuckDuckGo for OSINT intelligence gathering
No tool annotations (readOnlyHint, destructiveHint, idempotentHint). All tools are marked as READ_ONLY risk, but the schema does not include tool annotations. This omission prevents clients from optimizing caching and scheduling.
Status check tools add minimal value. 'check_duckduckgo_status', 'check_mosint_status', 'check_sherlock_status' are discovery helpers that should be integrated into main tools or removed. They clutter the tool namespace.
Sparse parameter descriptions. Parameters like 'region', 'safesearch', 'verbose', 'max_profiles', 'timeout' have descriptions but lack constraint details. Rubric requires 'minimum and maximum for numeric parameters' and 'expected format, range, allowed values' in descriptions.
Incomplete tool descriptions. Descriptions average ~100-150 chars; rubric baseline is 194 chars. Many descriptions do not explain WHEN to use the tool vs. alternatives or WHAT the tool returns.