OpenOSINT

An OSINT AI agent with an interactive mode, an MCP server and a CLI: about twenty tools to check domains, addresses, hashes and breaches

CLI

Medium risk

We rate an entry medium when the tool runs code, makes network calls or reads project files. Check what exactly it does before installing.

Why this level

  • Gathers data from many external sources
  • Handles potentially personal data
All reasons and checks

openosint/openosint

Install

In your terminal, with SkillFoxx CLI

npx skillfoxx add cli/openosint

Detects the agents on your machine, checks the risk and pins the version.

Other ways to install

Install the tool

pipx install openosint

Without pipx, pip install openosint works too.

You will need: pipx

Checked against the repository on Sep 25, 2026, commit 871ccbe.

Text for your agent

Install: pip install openosint. Run the interactive mode with openosint or single commands such as openosint web and openosint email. Set the keys of the sources you need in environment variables.

Other ways from the author
pip install openosint

After installing, run openosint for the interactive mode.

This is third-party code. Review the repository files before installing.

What it does

OpenOSINT does open-source reconnaissance for authorized security work. It runs as an interactive terminal agent, an MCP server and a plain CLI, and combines about twenty tools. These include domain and IP checks, hash and file lookups, breach and reputation databases and queries to search and profiles. Some sources need their own keys, and results build up into an entity graph.

Who it is for. For security professionals doing authorized open-source reconnaissance.

Good fit when

  • You need to gather open-source data on a domain, address or hash
  • You need breach and reputation checks
  • You need to run an investigation with a relationship graph

Not a fit when

  • The task is not authorized reconnaissance
  • You cannot gather data about people under your rules and law

Example request

Use OpenOSINT to gather data on this domain: records, open ports and breach mentions

Limitations

The tool gathers data from external sources, many of which need their own API keys, and the agent needs a model key or a local model via ollama. Use it only against permitted targets and within data protection law.

How to disable. Remove the openosint package via your Python package manager and remove the MCP setup if you added it.

Security check

  • Gathers data from many external sources
  • Handles potentially personal data

README in short

The README describes OpenOSINT as an OSINT AI agent with an interactive mode, an MCP server and a CLI. Installation is via pip, with commands for web, email and other targets and a live demo with your own model key. It lists sources and their keys: breach checks, Shodan, VirusTotal, IP reputation, GitHub search and search-engine queries. Results build an entity graph, and the tool is stated to be for authorized research only.

FAQ

How do I connect it to an agent?

OpenOSINT works both as an MCP server and a CLI; the interactive mode starts with openosint.

Are source keys required?

Some checks work without keys, but many sources such as breach or reputation checks need their own keys.

Editors’ pick

A code security audit skill by Cloudflare: the agent runs recon, coverage-led hunting and independent verification of findings, then produces a structured repor

SkillMedium riskNo VPN needed22.6KRepository stars
Editors’ pick

NVIDIA's open stack for running OpenClaw, Hermes and LangChain Deep Agents in OpenShell sandboxes with network policy and managed inference

CLIHigh risk22.6KRepository stars
Editors’ pick

Security scanner for agent skills and MCP servers: finds prompt injection, data exfiltration and supply chain risks before install

CLIMedium riskNo VPN needed18.5KRepository stars
Official

Static code analysis with rules that look like source code, plus a built-in MCP server for AI agents

CLIMedium risk16.8KRepository stars
Foxx AIOpenOSINT

I am Foxx AI and I have already vetted this tool. Ask about install, setup or anything else, and I will keep it simple.