osint-agent-skillsCAUTION
OSINT knowledge base + MCP server for autonomous AI agents — Claude Code, Cursor, Kimi K3, recon & threat intel playbooks.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A knowledge base that turns any autonomous AI agent into a senior OSINT analyst.
[](https://opensource.org/licenses/MIT) [](CHANGELOG.md) [](https://github.com/frangelbarrera/osint-agent-skills/stargazers) [](https://github.com/frangelbarrera/osint-agent-skills/commits) [](https://github.com/frangelbarrera/osint-agent-skills/issues) [](https://github.com/frangelbarrera/osint-agent-skills)
What is this?
osint-agent-skills is not an agent. It is not a script. It is not a SaaS.
It is a structured knowledge base — a curated set of methodologies, tool registries, pivot playbooks, ethics rules, and report templates — that any autonomous AI agent can consume to instantly adopt the operating discipline of a senior open-source intelligence analyst.
If you point Claude Code, Cursor, Ollama, OpenCode, AutoClaw, or any other agent framework at this repository, the agent will:
- Load
system-prompt.mdand adopt the OSINT Agent Skills persona. - Consult
knowledge/methodologies/to plan its investigation. - Use
tools/free-tools.yamlandtools/apis.yamlto execute lookups. - Follow
knowledge/pivot-playbooks/to chain findings into networks. - Generate a report using
templates/reports/intelligence-report.md. - Respect
ethics/legal-frameworks.mdthroughout — never suggesting illegal techniques, never fabricating findings.
This repository is agent-agnostic. It works th
ae7811cc8413OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add osint-agent-skills -- npx -y @frangelbarrera/[email protected]
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (6 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (13)
if (lower === "metadata" || lower === "metadata.google.internal") return false;
var hash = require("crypto").createHash("md5").update(args.email.trim().toLowerCase()).digest("hex");The agent cross-references the holehe and HIBP results to look for usernames associated with the email. For `[email protected]`, no username is recoverable from public data — the breach-credential retr
- If `[email protected]` uses `Password123!` in the LinkedIn 2012 breach and `Password123!` in the Adobe 2013 breach, the subject has a password-reuse pattern.
- If `[email protected]` uses `Winter2012!` in a 2012 breach and `Winter2015!` in a 2015 breach, the subject has a seasonal-pattern password.
A worked example. Suppose the OSINT investigator finds, on a criminal forum, a post advertising a phishing kit that spoofs a major bank. The kit's HTML and the credential-exfiltration endpoint are vis
- **The compromised VPN account.** Mandiant's attribution analysis confirmed that the initial access vector was a legacy VPN account, password-only authentication, no MFA. The password had not been in
- **Analysis and Production.** The campaign was mapped to MITRE ATT&CK techniques for initial access (spear-phishing attachment, T1566.001), credential access (credential dumping from LSASS, T1003), l
The case also teaches that **legitimate credentials blur the line between OSINT and intrusion.** The attackers used stolen VPN credentials to access the SCADA network — credentials harvested from phis
The agent refuses — without negotiation — requests whose stated purpose is stalking, harassment, doxxing, political repression, unauthorized access, credential stuffing, pretexting without authorizati
4. **Respect legality.** You operate within the legal frameworks documented in `ethics/legal-frameworks.md`. You refuse to suggest techniques that require unauthorized access, credential stuffing, soc
curl -fsSL https://ollama.com/install.sh | sh
Gates applied: no_behavioural_pass.
ae7811cc8413full audit observations/trust-audit/mcp-server/frangelbarrera__osint-agent-skills.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | ae7811cc8413 | CAUTION | B | 89 | first audit |
Questions
What is the osint-agent-skills MCP server?
OSINT knowledge base + MCP server for autonomous AI agents — Claude Code, Cursor, Kimi K3, recon & threat intel playbooks.
Is osint-agent-skills safe to connect to an agent?
With care. The audit graded it B (89/100) and found 13 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does osint-agent-skills need?
It reads ETHERSCAN_KEY, GITHUB_TOKEN, HIBP_KEY, HUNTER_KEY, SECURITYTRAILS_KEY, SHODAN_KEY and VT_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does osint-agent-skills run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @frangelbarrera/osint-agent-skills at 1.6.0.
How current is this page?
The grade is for one exact copy of the source (ae7811cc8413), read on 2026-10-08. The repository is watched and re-audited when it changes.