MCP server for authoring Maltego graph files and running primitive OSINT lookups.
maltego-mcp has 13 tools with complete input schemas and basic descriptions. Naming follows verb_noun convention (create_, add_, expand_, etc.), which is good. However, descriptions are terse (10-50 chars on average), falling short of the 50-200 char LLM-optimized baseline. Parameters have type annotations and brief descriptions, but lack actionable guidance (constraints, format specs, valid ranges). No parameter descriptions explain WHEN to use a tool vs. a similar one, or dependencies between parameters. Error handling is minimal, tools return success/failure but lack recovery guidance. Output schemas are not documented in tool definitions; the MCP SDK schema stripping (mcp-server.ts) suggests internal inconsistency. Security is reasonable (no secrets in params), but there is no documented permission model or audit trail. Composition is sound, tools are modular and chain-friendly (e.g., create_graph → add_entity → save_graph). Overall: serviceable for simple OSINT workflows, but lacks the rigor expected for production agent tooling.
Add an entity to a Maltego graph.
Add a link between two entities in a Maltego graph.
Perform ASN lookup on an IP address via Team Cymru.
Build a comprehensive .mtgx graph from multiple IOCs (domains, IPs, hashes).
Create a new Maltego graph with an optional initial name.
Query certificate transparency via crt.sh for a domain.
Perform DNS lookups (A, AAAA, MX, NS, TXT) on a domain.
Build a .mtgx graph around a domain (whois + DNS + ASN per A record).
Tool descriptions are terse (10 - 50 characters). LLM-optimized descriptions should be 50 - 200 characters and explain WHAT, WHEN, and WHAT depends on the tool. Agents cannot distinguish between similar tools (e.g., expand_domain vs. expand_hash vs. build_ioc_graph) without richer guidance.
Parameter descriptions lack actionable constraints and format guidance. E.g., 'domain' param in maltego_dns has no specification of valid format (FQDN), length limits, or handling of wildcards. 'graphId' in maltego_add_entity has no guidance on format or how to obtain one.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | F | 48 | 2025-06-18+ | v2 |
Build a .mtgx graph around a file hash via VirusTotal and other threat intelligence sources.
Build a .mtgx graph around an IP address (reverse DNS + ASN + WHOIS netblock).
Load a Maltego graph from a .mtgx file.
Save a Maltego graph to a .mtgx file.
Perform a WHOIS lookup on a domain.
No output schema documentation. While input schemas are visible in tool registration (mcp-server.ts), output schemas are not documented. Agents cannot infer what fields to expect from e.g. maltego_dns or maltego_whois, forcing trial-and-error usage and wasting tokens on failed parsing.
No error recovery guidance. Tools return success or failure but do not guide agents on what to do next. E.g., if maltego_expand_domain fails on 'example.xyz', the agent does not know whether to retry, ask the user, or try a different domain. Error responses should include recovery paths.
No tool annotations (readOnlyHint, destructiveHint, idempotentHint). Agents cannot determine which tools are safe to retry, which are read-only, and which modify state. All tools should carry explicit annotations to enable agent reasoning.
No permission model or scope declaration. Tools like maltego_save_graph and maltego_expand_* write files to the filesystem but declare no permissions. Agents cannot reason about least-privilege configuration, and auditing is absent.
Parameter 'properties' in maltego_add_entity and maltego_add_link is defined as type 'object' with no schema. Agents cannot determine valid property keys or values, forcing them to guess or rely on Maltego internals.
Tool 'maltego_crtsh' name is opaque to LLMs. 'crtsh' is an acronym for crt.sh (a CT log query service) but agents cannot infer this from the name alone. Rename to 'maltego_query_certificate_transparency' or 'maltego_search_certificates' for clarity.
No guidance on when to use expand_* tools vs. build_ioc_graph. All four tools build graphs from OSINT. Descriptions do not explain the trade-offs (single indicator vs. batch, speed vs. comprehensiveness) or when to choose one over the other.