Devil's Eye: OSINT with a Russian layer
glaz-dyavola
An OSINT tool for passive reconnaissance: EGRUL, FSSP, VK, Telegram and Yandex alongside secret scanning and a 15-tool MCP server
Medium risk
We rate an entry medium when the tool runs code, makes network calls or reads project files. Check what exactly it does before installing.
Why this level
- Reads personal and corporate data from open Russian registries
- Checks whether found secrets are live by calling external services
Install
Manual install
git clone https://github.com/vladimir120307-droid/glaz-dyavola.git && cd glaz-dyavola && pip install -e ".[mcp]"The README's install method with the mcp extras.
This is third-party code. Review the repository files before installing.
What it does
The project is a modular Python (Typer) CLI and MCP server for OSINT reconnaissance and read-only validation in authorized engagements: bug bounty, attack surface inventory, due diligence, threat intel, investigative journalism. Universal modules cover DNS and subdomains, SPF/DMARC/DKIM auditing, secret scanning with over 65 regex patterns filtered by Shannon entropy, identity provider fingerprinting, web attack-surface recon (Swagger, GraphQL), an AI service secrets catalog, and 9 read-only validators that check whether a found key is still live via a call like AWS GetCallerIdentity or GitHub /user, without taking any other action. A separate Russian-language layer looks up legal entities and sole proprietors by INN or OGRN through DaData or egrul.nalog.ru, FSSP enforcement proceedings with a token, resolves VK and Telegram pages, fingerprints a Yandex digital footprint (Metrika ID, Yandex Cloud, Yandex-hosted mail) and recognizes bank BIC codes and card types. Results export to JSON, JSONL, SARIF or HTML. The tool's scope is explicitly limited to passive reconnaissance: no active exploitation, brute-force or evasion.
Who it is for. For security professionals and OSINT researchers who need reconnaissance across Russian registries and social networks alongside general-purpose modules.
Good fit when
- You need to inventory your own attack surface: subdomains, DNS, secrets in public code
- You need to check whether an accidentally committed key is still live, without taking any other action with it
- You need reconnaissance across Russian registries: EGRUL, FSSP, a Yandex digital footprint, VK or Telegram, within an authorized engagement
Not a fit when
- You need active exploitation, brute-force or evasion, the tool explicitly excludes this
- You do not have authorization for the asset you plan to investigate: the README requires ownership or written permission
Example request
Check my domain for leaked secrets in public code, and map my company's digital footprint by INN in EGRULLimitations
The project is under active development; some RU modules (SPARK, Kontur via API keys) are on the roadmap but not yet implemented. The FSSP module needs a separate FSSP_TOKEN. The read-only validators call external services like GitHub, GitLab, Anthropic and OpenAI, so part of the functionality depends on their availability from Russia. Installation is only by cloning the repository; there is no packaged PyPI release per the README.
How to disable. Remove the glaz server from your MCP client configuration and delete the local repository copy.
MCP
- Transport
- stdio
- Authentication
- not required
| Environment variables | |
|---|---|
| FSSP_TOKEN secret | A token for the FSSP module, needed only for enforcement-proceeding lookups. |
Security check
- Reads personal and corporate data from open Russian registries
- Checks whether found secrets are live by calling external services
README in short
The bilingual README lists universal modules in detail (DNS, email security, subdomains, secrets, identity, web attack surface, an AI secrets catalog, read-only validators, WHOIS/RDAP) and separately calls out the RU layer as the main advantage: EGRUL, FSSP, VK, Telegram, Yandex, banks and government domains. It shows CLI command examples, running the MCP server over stdio with a Claude Code connection, the repository structure, and an explicit scope and authorization statement in SECURITY.md. A roadmap separately names unfinished parts: expanded people-OSINT, breach correlation and deeper SPARK and Kontur coverage.
FAQ
Can the tool use a found secret to access data?
No, the validators only check liveness with a harmless call like AWS GetCallerIdentity or GitHub /user; the README explicitly limits the scope to passive reconnaissance.
Do I need authorization for the target?
Yes, the README requires using the tool only on assets you own or have written permission for: RoE, in-scope bug bounty, an ASM contract, or open legal-entity registries.
Related
A code security audit skill by Cloudflare: the agent runs recon, coverage-led hunting and independent verification of findings, then produces a structured repor
NVIDIA's open stack for running OpenClaw, Hermes and LangChain Deep Agents in OpenShell sandboxes with network policy and managed inference
Security scanner for agent skills and MCP servers: finds prompt injection, data exfiltration and supply chain risks before install
Static code analysis with rules that look like source code, plus a built-in MCP server for AI agents