Fusion Center MCP Server and AI Agent for OSINT and Geopolitical Intelligence. Provides tools for news search (GDELT), satellite thermal anomaly detection (NASA FIRMS), internet infrastructure monitoring (IODA), threat intelligence (AlienVault OTX), Telegram channel search, and cyber threat analysis.
Project Overwatch demonstrates moderate quality with significant gaps in consistency and error handling. All 14 tools have descriptions and most have input schemas with reasonable parameter definitions, but descriptions vary widely in quality (ranging from 40 to 1000+ chars), parameter constraints are often missing or inconsistent, and output schemas are entirely undocumented. Error handling guidance is absent across all tools. The codebase shows evidence of tool composition effort (search_news, fetch_rss_news, detect_thermal_anomalies, etc.) but lacks the rigor expected for production-grade OSINT/geopolitical intelligence infrastructure.
Check for internet outages and connectivity issues at COUNTRY level. IMPORTANT: IODA only provides country-level data, NOT city/region data. Uses IODA (Internet Outage Detection and Analysis) data to detect: Government-imposed internet shutdowns; Infrastructure damage from conflicts or disasters; Cyber attacks on network infrastructure; Cable cuts or major routing anomalies.
Look up indicators of compromise in AlienVault OTX (Open Threat Exchange) threat intelligence database.
Query Cloudflare Radar for internet traffic and security metrics. Provides insights into: Traffic volume changes that might indicate outages; DDoS attacks and threat activity.
Detect thermal anomalies (fires, explosions) using NASA satellite data. NASA FIRMS provides near real-time active fire data from satellite observations. Thermal anomalies can indicate: Active fires or wildfires; Industrial explosions or accidents; Military strikes or bombardments; Large-scale burning events. Note: Requires NASA_FIRMS_API_KEY environment variable to be set.
Fetch latest articles from independent news RSS feeds. Supported sources: meduza (independent Russian news), theinsider (Russian investigative journalism), thecradle (geopolitical news covering West Asia). Use this tool to: Get latest breaking news from independent sources; Monitor coverage of conflicts and geopolitical events; Track investigative journalism from Russian independent media; Follow developments in West Asia and Middle East.
Output schemas completely undocumented. Tools like search_news, check_connectivity, detect_thermal_anomalies, and search_telegram return structured data but provide no schema documentation to agents. Agents must guess what fields to expect and cannot plan downstream tool calls reliably.
Minimal/missing descriptions for 6 tools. get_outages (35 chars: 'Get IODA outage events.'), get_threat_pulse (23 chars: 'Get threat pulse details from AlienVault OTX.'), get_channel_info (35 chars: 'Get information about a Telegram channel.'), list_osint_channels (35 chars: 'List curated OSINT channels on Telegram.'), search_web (no visible description), search_ddos_secrets_db (no visible description in provided code). Descriptions under 50 chars lack context for when/why to call these tools.
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | C | 65 | <=2025-11-25 | v2 |
| 2026-03-09 | F | 0 | 1.0.0+ | v1 |
Get information about a Telegram channel.
Get IODA outage events.
Get threat pulse details from AlienVault OTX.
List curated OSINT channels on Telegram.
Search the DDoS Secrets database for leaked data.
Search for news articles and events using the GDELT database. GDELT monitors news from around the world in 100+ languages. Use this tool to: Find breaking news about conflicts, protests, or political events; Track media coverage of specific countries or regions; Monitor news about military activities or humanitarian crises; Research geopolitical developments and international relations.
Search Telegram channels for messages containing specific keywords or in specific channels.
Search threat intelligence pulses in AlienVault OTX.
Search the web using DuckDuckGo.
No error handling guidance. Tools lack recovery instructions. Examples: detect_thermal_anomalies requires NASA_FIRMS_API_KEY but does not document fallback behavior if the key is missing. check_connectivity warns IODA only provides country-level data but does not return an error when a city/region is requested, silently succeeds or fails? Agents have no guidance on next steps after errors.
Inconsistent parameter constraint documentation. search_news documents boolean operator syntax in detail ('MUST be inside parentheses'), but check_traffic_metrics does not document that metric values are constrained ('traffic', 'attacks', 'routing'). get_outages accepts entity_type but does not enforce via enum. Agents cannot know which values are valid without trial-and-error.
Missing or incomplete input schemas. search_web and search_ddos_secrets_db lack visible input schema definitions in the provided code (File: src/mcp_server/tools/search.py not shown). If schemas are truly absent, these tools cannot be safely called by LLMs.
Missing pagination and result limits documentation. Tools like search_news (default max_records=50, supports up to 250), search_threats (default limit=20, max 50), search_telegram (max_messages default 50) return potentially large result sets. Output schemas do not specify whether results include a total_count, next_cursor, or other pagination metadata. Agents cannot know if results are truncated or how to fetch the next page.
Parameter type inconsistencies. Some tools mix nullable and non-nullable parameters inconsistently. search_telegram has keywords: str|None, channels: list[str]|None, category: str|None, but does not clarify which are truly optional vs. required at the MCP schema layer. Agents cannot know if omitting a parameter is safe without documentation.
OSINT-specific tool coordination gaps. search_news (GDELT) and fetch_rss_news (RSS) both retrieve news but operate on different data sources. Response schemas are not documented, making it unclear to agents which tool to call for what type of coverage (breaking vs. investigative vs. geopolitical). No guidance on when to use both vs. choosing one.
Geopolitical domain context underspecified. Tools like detect_thermal_anomalies, check_connectivity, and search_telegram operate on conflict-sensitive data (Ukraine, Russia, Iran, Syria). No security considerations, rate-limiting guidance, or ethical guardrails documented. Tools accept specific countries but do not document special handling or warnings for contested/sensitive regions.