OpenOSINT
An OSINT AI agent with an interactive mode, an MCP server and a CLI: about twenty tools to check domains, addresses, hashes and breaches
Medium risk
We rate an entry medium when the tool runs code, makes network calls or reads project files. Check what exactly it does before installing.
Why this level
- Gathers data from many external sources
- Handles potentially personal data
Install
In your terminal, with SkillFoxx CLI
npx skillfoxx add cli/openosintDetects the agents on your machine, checks the risk and pins the version.
Other ways to install
Install the tool
pipx install openosintWithout pipx, pip install openosint works too.
Install: pip install openosint. Run the interactive mode with openosint or single commands such as openosint web and openosint email. Set the keys of the sources you need in environment variables.
Other ways from the author
pip install openosintAfter installing, run openosint for the interactive mode.
This is third-party code. Review the repository files before installing.
What it does
OpenOSINT does open-source reconnaissance for authorized security work. It runs as an interactive terminal agent, an MCP server and a plain CLI, and combines about twenty tools. These include domain and IP checks, hash and file lookups, breach and reputation databases and queries to search and profiles. Some sources need their own keys, and results build up into an entity graph.
Who it is for. For security professionals doing authorized open-source reconnaissance.
Good fit when
- You need to gather open-source data on a domain, address or hash
- You need breach and reputation checks
- You need to run an investigation with a relationship graph
Not a fit when
- The task is not authorized reconnaissance
- You cannot gather data about people under your rules and law
Example request
Use OpenOSINT to gather data on this domain: records, open ports and breach mentionsLimitations
The tool gathers data from external sources, many of which need their own API keys, and the agent needs a model key or a local model via ollama. Use it only against permitted targets and within data protection law.
How to disable. Remove the openosint package via your Python package manager and remove the MCP setup if you added it.
Security check
- Gathers data from many external sources
- Handles potentially personal data
README in short
The README describes OpenOSINT as an OSINT AI agent with an interactive mode, an MCP server and a CLI. Installation is via pip, with commands for web, email and other targets and a live demo with your own model key. It lists sources and their keys: breach checks, Shodan, VirusTotal, IP reputation, GitHub search and search-engine queries. Results build an entity graph, and the tool is stated to be for authorized research only.
FAQ
How do I connect it to an agent?
OpenOSINT works both as an MCP server and a CLI; the interactive mode starts with openosint.
Are source keys required?
Some checks work without keys, but many sources such as breach or reputation checks need their own keys.
Related
A code security audit skill by Cloudflare: the agent runs recon, coverage-led hunting and independent verification of findings, then produces a structured repor
NVIDIA's open stack for running OpenClaw, Hermes and LangChain Deep Agents in OpenShell sandboxes with network policy and managed inference
Security scanner for agent skills and MCP servers: finds prompt injection, data exfiltration and supply chain risks before install
Static code analysis with rules that look like source code, plus a built-in MCP server for AI agents