OSINT MCP Server
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| HOST | No | The host the server will bind to (default is 0.0.0.0). | |
| PORT | No | The port the server will listen on (default is 3000). | |
| EXA_API_KEY | No | API key for Exa Web Search. | |
| HIBP_API_KEY | No | API key for HaveIBeenPwned (used for breach checking). | |
| HUNTER_API_KEY | No | API key for Hunter.io (used for domain email searches). | |
| IMAGGA_API_KEY | No | API key for Imagga image tagging. | |
| SHODAN_API_KEY | No | API key for Shodan (used for host details and WHOIS lookup). | |
| ZOOMEYE_API_KEY | No | API key for ZoomEye (used for host searches). | |
| SAUCENAO_API_KEY | No | API key for SauceNAO (used for reverse image search). | |
| GREYNOISE_API_KEY | No | API key for GreyNoise (used for IP context). | |
| IMAGGA_API_SECRET | No | API secret for Imagga image tagging. | |
| ALIENVAULT_API_KEY | No | API key for AlienVault OTX (used for threat intel). | |
| VIRUSTOTAL_API_KEY | No | API key for VirusTotal (used for URL reputation). | |
| GOOGLE_CLOUD_API_KEY | No | API key for Google Cloud Vision analysis. | |
| SECURITYTRAILS_API_KEY | No | API key for SecurityTrails (used for subdomain discovery). |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": true
} |
Tools
Functions exposed to the LLM to take actions
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 56 tools
Most tools target distinct OSINT data sources or techniques, but there are clear overlaps like dns_lookup_direct/dns_lookup_passive/dns_enumeration and whois_lookup/whois_history that could cause confusion. The lack of descriptions exacerbates ambiguity, though many tools are clearly scoped to specific platforms or data types.
Naming follows a consistent snake_case pattern with mostly clear verb_noun or noun_verb structures. Minor inconsistencies exist like 'subdomain_enum' vs 'dns_enumeration' and 'quick_port_scan' vs 'shodan_host', but overall the convention is predictable and readable.
56 tools is excessive for a single server, creating cognitive overload and likely overlapping functionality. While OSINT is a broad domain, this count suggests poor scoping with many specialized tools that could have been consolidated into more general operations.
The toolset provides remarkably comprehensive coverage of OSINT techniques across domains, networks, social media, cryptocurrencies, and more. There are no obvious major gaps for an OSINT server, though the lack of descriptions makes it hard to confirm if all expected operations are truly covered.