Atlas / MCP servers / frangelbarrera / osint-agent-skills

osint-agent-skillsCAUTION

mcp/frangelbarrera/osint-agent-skills

OSINT knowledge base + MCP server for autonomous AI agents — Claude Code, Cursor, Kimi K3, recon & threat intel playbooks.

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
—
Transport
stdio
License
MIT
Stars
36
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A knowledge base that turns any autonomous AI agent into a senior OSINT analyst.

[](https://opensource.org/licenses/MIT) [](CHANGELOG.md) [](https://github.com/frangelbarrera/osint-agent-skills/stargazers) [](https://github.com/frangelbarrera/osint-agent-skills/commits) [](https://github.com/frangelbarrera/osint-agent-skills/issues) [](https://github.com/frangelbarrera/osint-agent-skills)

What is this?

osint-agent-skills is not an agent. It is not a script. It is not a SaaS.

It is a structured knowledge base — a curated set of methodologies, tool registries, pivot playbooks, ethics rules, and report templates — that any autonomous AI agent can consume to instantly adopt the operating discipline of a senior open-source intelligence analyst.

If you point Claude Code, Cursor, Ollama, OpenCode, AutoClaw, or any other agent framework at this repository, the agent will:

  1. Load system-prompt.md and adopt the OSINT Agent Skills persona.
  2. Consult knowledge/methodologies/ to plan its investigation.
  3. Use tools/free-tools.yaml and tools/apis.yaml to execute lookups.
  4. Follow knowledge/pivot-playbooks/ to chain findings into networks.
  5. Generate a report using templates/reports/intelligence-report.md.
  6. Respect ethics/legal-frameworks.md throughout — never suggesting illegal techniques, never fabricating findings.

This repository is agent-agnostic. It works th

Read from source at commit ae7811cc8413OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add osint-agent-skills -- npx -y @frangelbarrera/[email protected]
03

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (6 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (13)

HIGHNetwork egress · net.metadata_ip · CWE-200, CWE-319
tools/mcp-server.js:277
if (lower === "metadata" || lower === "metadata.google.internal") return false;
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
tools/mcp-server.js:541
var hash = require("crypto").createHash("md5").update(args.email.trim().toLowerCase()).digest("hex");
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
examples/investigate-email.md:91
The agent cross-references the holehe and HIBP results to look for usernames associated with the email. For `[email protected]`, no username is recoverable from public data — the breach-credential retr
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
knowledge/domains/breach-data.md:60
- If `[email protected]` uses `Password123!` in the LinkedIn 2012 breach and `Password123!` in the Adobe 2013 breach, the subject has a password-reuse pattern.
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
knowledge/domains/breach-data.md:61
- If `[email protected]` uses `Winter2012!` in a 2012 breach and `Winter2015!` in a 2015 breach, the subject has a seasonal-pattern password.
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
knowledge/methodologies/mitre-attack-mapping.md:13
A worked example. Suppose the OSINT investigator finds, on a criminal forum, a post advertising a phishing kit that spoofs a major bank. The kit's HTML and the credential-exfiltration endpoint are vis
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWInventory / provenance · mcp.no_tools_extracted · CWE-1104
server.json
Why it matters. the tool list is enumerated at runtime by tools/list, not declared in source
Fix. the page says so rather than showing an empty table
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
case-studies/colonial-pipeline.md:25
- **The compromised VPN account.** Mandiant's attribution analysis confirmed that the initial access vector was a legacy VPN account, password-only authentication, no MFA. The password had not been in
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
case-studies/ukraine-power-grid-2015.md:18
- **Analysis and Production.** The campaign was mapped to MITRE ATT&CK techniques for initial access (spear-phishing attachment, T1566.001), credential access (credential dumping from LSASS, T1003), l
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
case-studies/ukraine-power-grid-2015.md:45
The case also teaches that **legitimate credentials blur the line between OSINT and intrusion.** The attackers used stolen VPN credentials to access the SCADA network — credentials harvested from phis
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
integrations/generic-agent.md:63
The agent refuses — without negotiation — requests whose stated purpose is stalking, harassment, doxxing, political repression, unauthorized access, credential stuffing, pretexting without authorizati
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
system-prompt.md:29
4. **Respect legality.** You operate within the legal frameworks documented in `ethics/legal-frameworks.md`. You refuse to suggest techniques that require unauthorized access, credential stuffing, soc
Why it matters. asks the agent to read credentials
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
integrations/ollama.md:14
curl -fsSL https://ollama.com/install.sh | sh

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha ae7811cc8413full audit observations/trust-audit/mcp-server/frangelbarrera__osint-agent-skills.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08ae7811cc8413CAUTIONB89first audit
05

Questions

What is the osint-agent-skills MCP server?

OSINT knowledge base + MCP server for autonomous AI agents — Claude Code, Cursor, Kimi K3, recon & threat intel playbooks.

Is osint-agent-skills safe to connect to an agent?

With care. The audit graded it B (89/100) and found 13 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does osint-agent-skills need?

It reads ETHERSCAN_KEY, GITHUB_TOKEN, HIBP_KEY, HUNTER_KEY, SECURITYTRAILS_KEY, SHODAN_KEY and VT_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does osint-agent-skills run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @frangelbarrera/osint-agent-skills at 1.6.0.

How current is this page?

The grade is for one exact copy of the source (ae7811cc8413), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement