Skip to main content
Glama
CloudWaddie

OSINT MCP Server

by CloudWaddie

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault
HOSTNoThe host the server will bind to (default is 0.0.0.0).
PORTNoThe port the server will listen on (default is 3000).
EXA_API_KEYNoAPI key for Exa Web Search.
HIBP_API_KEYNoAPI key for HaveIBeenPwned (used for breach checking).
HUNTER_API_KEYNoAPI key for Hunter.io (used for domain email searches).
IMAGGA_API_KEYNoAPI key for Imagga image tagging.
SHODAN_API_KEYNoAPI key for Shodan (used for host details and WHOIS lookup).
ZOOMEYE_API_KEYNoAPI key for ZoomEye (used for host searches).
SAUCENAO_API_KEYNoAPI key for SauceNAO (used for reverse image search).
GREYNOISE_API_KEYNoAPI key for GreyNoise (used for IP context).
IMAGGA_API_SECRETNoAPI secret for Imagga image tagging.
ALIENVAULT_API_KEYNoAPI key for AlienVault OTX (used for threat intel).
VIRUSTOTAL_API_KEYNoAPI key for VirusTotal (used for URL reputation).
GOOGLE_CLOUD_API_KEYNoAPI key for Google Cloud Vision analysis.
SECURITYTRAILS_API_KEYNoAPI key for SecurityTrails (used for subdomain discovery).

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Features and capabilities supported by this server

Protocol revision2025-11-25

CapabilityDetails
tools
{
  "listChanged": true
}

Tools

Functions exposed to the LLM to take actions

NameDescription
ip_geolocationD–
whois_lookupD–
whois_historyD–
dns_lookup_passiveD–
dns_lookup_directD–
reverse_dnsD–
check_breachesD–
shodan_hostD–
shodan_whoisD–
ssl_certsD–
url_reputationD–
dns_enumerationD–
subdomain_enumD–
hunter_domain_searchD–
greynoise_ip_contextD–
otx_indicator_detailsD–
securitytrails_subdomainsD–
zoomeye_host_searchD–
reverse_image_search_animeD–
image_taggingD–
google_vision_analyzeD–
github_user_infoD–
github_user_reposD–
github_commit_emailsD–
github_repo_commitsD–
username_searchD–
fandom_user_infoD–
fandom_user_contributionsD–
archive_org_snapshotD–
mac_lookupD–
keybase_lookupD–
reddit_user_detailsD–
reddit_user_postsD–
url_metadataD–
url_tech_stackD–
email_permutatorD–
domain_email_searchD–
email_social_checkD–
btc_lookupD–
eth_lookupD–
phone_lookupD–
exif_metadataD–
discord_lookupD–
steam_lookupD–
xbox_lookupD–
hash_lookupD–
tor_checkD–
paste_searchD–
asn_lookupD–
unshorten_urlD–
quick_port_scanD–
opencorporates_searchD–
pgp_searchD–
twitter_user_searchD–
instagram_user_lookupD–
web_searchD–

Prompts

Interactive templates invoked by user choice

NameDescription

No prompts

Resources

Contextual data attached and managed by the client

NameDescription

No resources

TDQS

D1.7/5.0

Scored across 56 tools

Disambiguation3/5

Most tools target distinct OSINT data sources or techniques, but there are clear overlaps like dns_lookup_direct/dns_lookup_passive/dns_enumeration and whois_lookup/whois_history that could cause confusion. The lack of descriptions exacerbates ambiguity, though many tools are clearly scoped to specific platforms or data types.

Naming Consistency4/5

Naming follows a consistent snake_case pattern with mostly clear verb_noun or noun_verb structures. Minor inconsistencies exist like 'subdomain_enum' vs 'dns_enumeration' and 'quick_port_scan' vs 'shodan_host', but overall the convention is predictable and readable.

Tool Count2/5

56 tools is excessive for a single server, creating cognitive overload and likely overlapping functionality. While OSINT is a broad domain, this count suggests poor scoping with many specialized tools that could have been consolidated into more general operations.

Completeness4/5

The toolset provides remarkably comprehensive coverage of OSINT techniques across domains, networks, social media, cryptocurrencies, and more. There are no obvious major gaps for an OSINT server, though the lack of descriptions makes it hard to confirm if all expected operations are truly covered.

Maintenance

ActivityInactive
ResponsivenessNo issues