AI-powered OSINT agent, MCP server, and CLI. Interactive REPL + 19 tools. Anthropic Claude or local Ollama. For authorized security research use only.
OpenOSINT provides 23 OSINT reconnaissance tools with basic but incomplete definition quality. Strengths: all tools have names following verb_noun pattern (search_*, scrape_*), all have descriptions (10-200 chars typical), and input schemas are present with type definitions. Critical weaknesses: (1) parameter descriptions are almost entirely missing, 22 of 23 tools have input parameters like 'target', 'query', 'ip', 'domain' with NO descriptions explaining what they control or accept; (2) output schemas are completely undocumented, no tool declares what it returns, forcing LLMs to guess at response structure; (3) no error handling guidance, tools return success/failure with no recovery hints; (4) missing security details, many tools require API keys (HIBP_API_KEY, SHODAN_API_KEY, VIRUSTOTAL_API_KEY, CENSYS_API_ID/SECRET, IP2LOCATION_API_KEY, ABUSEIPDB_API_KEY) injected via environment variables (correct pattern) but no tool description mentions this or guides the user; (5) one tool (graph_review_candidates) is a WRITE operation but has minimal description of what 'decide' does or what side effects occur. The server lands at the lower end of 'fair', definitions exist but lack the rigor production systems require.
Generate targeted Google dork URLs for any target (name, email, username, domain).
Export the graph store as newline-delimited FtM entity JSON, one entity per line.
Traverse the graph from entity_id out to depth hops, with per-edge provenance.
action='list' shows the pending human-review queue; action='decide' records a verdict.
Scrape content and metadata from a web page. Returns page title, description, all visible text, links, images, and embedded media.
Check an IP address against the AbuseIPDB v2 API for abuse reputation. Returns abuse confidence score (0–100%), total reports, country, ISP, domain, and last reported timestamp. Shows a warning when score exceeds 50%. Uses ABUSEIPDB_API_KEY env var.
Missing parameter descriptions on 22 of 23 tools. Parameters like 'target', 'query', 'ip', 'domain', 'email' have NO description text explaining what values are valid, what format is expected, or how the tool uses them. This violates pattern:tool-description which requires every parameter to have a non-empty description so LLMs can infer intent.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | C | 61 | 2026-07-28+ | v2 |
Check if an email appears in data breaches via HaveIBeenPwned. Uses HIBP_API_KEY env var.
Search Censys for internet-facing infrastructure data. IP address → open ports, services, ASN, country. Domain → certificate history, SANs, issuer, first/last seen. Uses CENSYS_API_ID and CENSYS_SECRET env vars.
Query DNS records for a domain and analyze email security posture (SPF, DMARC, DKIM).
Enumerate subdomains of a target domain using sublist3r.
Live Google search using Dorks Search API. Auto-generates and executes a dork query for maximum search coverage.
Enumerate accounts linked to an email using holehe.
Passive online footprint investigation. Combines email, domain, IP, DNS, and WHOIS data into a unified report.
Search GDELT GEO 2.0 for geolocated news mentions of a query within a geographic boundary (GeoJSON fence). Returns news articles with coordinates, sources, and tone.
Search GitHub for leaks, code patterns, or API keys by username, email, or keyword. Returns user profiles, repositories, commits, and file matches.
Retrieve geolocation and ASN data for an IP address via ipinfo.io.
Enhanced IP intelligence using IP2Location Security Plan. Returns geolocation, ISP, ASN, and detects VPN, proxy, Tor exit nodes, and datacenter hosting. Sponsored integration. Uses IP2LOCATION_API_KEY env var.
Search Pastebin dumps for an email or username via psbdmp.ws.
Gather carrier and geolocation data for a phone number using phoneinfoga. Use E.164 format.
Query Shodan for host intelligence or banner search. IP address → host lookup (open ports, org, CVEs). Any other string → keyword/service search. Uses SHODAN_API_KEY env var.
Enumerate platforms where a username is registered using sherlock.
Check IP, domain, URL, or file hash against VirusTotal's 70+ antivirus engines and threat intelligence. Auto-detects input type. Uses VIRUSTOTAL_API_KEY env var.
Retrieve WHOIS registration data for a domain.
No output schemas documented for any tool. Tools like search_email, search_breach, search_shodan return unspecified results. LLMs cannot plan downstream chaining, extract the right fields, or know what to expect without a documented output schema. Violates pattern:tool and mxe:strip-api-responses.
graph_review_candidates is a WRITE operation (accepts 'decide' action to record verdicts) but has a minimal description and no guidance on what side effects occur, what permissions are required, or what the valid values for 'decision' field are. Violates pattern:command-tool which requires state-modifying tools to explicitly declare they modify state.
API keys are correctly injected via environment variables (HIBP_API_KEY, SHODAN_API_KEY, VIRUSTOTAL_API_KEY, etc.), following pattern:secret-injection. However, tool descriptions do NOT mention that these tools require API key setup or guide users on which environment variables to set. This creates a silent failure when users run tools without proper configuration.
No error handling guidance. Tools do not document what errors they may return, whether they are retryable, or what the LLM should do if a call fails. Violates pattern:recovery-guide and pattern:error-classification.
search_gdelt_geo has a required parameter 'geofence_geojson' (a complex GeoJSON string) with no description or format guidance. LLMs will not know how to construct valid GeoJSON without explicit format hints. Violates pattern:constrained-input.
graph_review_candidates has multiple required and optional parameters ('action', 'schema', 'entity_id', 'canonical_id', 'decision', etc.) with NO descriptions and unclear interdependencies. The 'action' enum ('list' vs 'decide') determines which other parameters apply, but this dependency is not documented. Violates review:param-relationships.