Update — October 2026

What changed since this guide was last revised (6 September 2026), one line per item, re-checked on 8 October 2026:

  • 28 Jul 2026 — new spec revision. The current MCP protocol version is 2026-07-28; it removes the initialize handshake and protocol-level sessions, adds a mandatory server/discover call, and deprecates the Roots, Sampling and Logging features. MCP changelog (2026-07-28)
  • 9 Dec 2025 — new governance. Anthropic donated MCP to the Agentic AI Foundation, a directed fund under the Linux Foundation co-founded by Anthropic, Block and OpenAI. Anthropic (9 Dec 2025)
  • Clients. MCP is now documented in Claude Code, ChatGPT (full MCP in beta for Business, Enterprise and Edu), OpenAI's Responses API and Agents SDK, VS Code, Copilot Studio, Cursor and Gemini CLI — see the client table for sources and caveats.
  • Official vendor servers. Have I Been Pwned (registry listing 22 Jul 2026), VirusTotal (vt-mcp 0.9.8, 28 Sep 2026) and Censys (docs updated 1 Sep 2026) now run their own MCP servers — see the verified server table.
  • OpenOSINT is now v2.31.0 (6 Oct 2026) with 21 tools, up from v2.27 and 20 tools. PyPI (6 Oct 2026)
  • OSINT Navigator (Indicator and Buried Signals, launched 13 Apr 2026) lets Indicator members query its 7,500+ tool index from an AI agent over MCP. Indicator (13 Apr 2026)
  • Registry ≠ vetting. The official MCP Registry says consumers "should assume minimal-to-no moderation"; a listing proves who published a server, not that it is safe. MCP Registry moderation policy (checked 8 Oct 2026)
  • Corrections. We removed two claims we could not verify (an unnamed "~64-tool" OSINT server and a generic "skill catalog" bullet), corrected SpiderFoot from "100+ sources" to its README's "200+ modules", and corrected OpenOSINT's username tool to Sherlock (it does not bundle Maigret).

The biggest OSINT shift of 2026 is agentic investigation: instead of manually running one tool at a time, you hand a target to an AI agent that decides which tools to run, pivots on what it finds, and writes the report. The enabler is the Model Context Protocol (MCP) — an open standard that lets AI assistants call external tools. Open-source frameworks like OpenOSINT (MIT-licensed; AI REPL + CLI + MCP server) wrap proven utilities such as Sherlock, holehe, PhoneInfoga, and Have I Been Pwned so an agent can chain them. Crucially, the credible tools use native tool-calling: the AI reads real tool output and cannot fabricate findings. Alongside this, AI geolocation (e.g., GeoSeer, launched late 2025) now pinpoints photos from visual cues without EXIF. And if you don't want to install Python CLIs, browser-based suites run the same categories of lookups with no setup.

2025
The Agentic Turning Point
2026-07-28
Current MCP Spec Revision
Real
Tool Output, Not Model Output (by design)
3,000+
Sites Checked by Maigret
Late 2025
GeoSeer AI Geolocation Launch
MIT
OpenOSINT License

What is AI-agent OSINT, and how is it different?

AI-agent OSINT is open-source intelligence gathering driven by an autonomous AI agent rather than a human clicking through tools one at a time. You give the agent a starting point — an email, username, domain, or IP — and it scopes the task, decides which tools to run, chains them based on what each returns, verifies against real sources, and compiles a structured report. It is the difference between keeping fifteen browser tabs open and asking a competent junior analyst to "look into this and write it up."

The old workflow was passive aggregation: every tool a silo, every pivot manual, and the investigation logic — what to run next, what a finding means — living entirely in your head. The 2026 workflow is active and reasoning-driven. A typical agent loop looks like: generate search dorks for the target → enumerate accounts tied to an email → check breach databases → pivot to a discovered username → search that username across platforms → save the report. Each step is chosen by the model in response to the previous step's real output.

How does an OSINT MCP server work?

The Model Context Protocol (MCP) is an open standard, introduced by Anthropic and now widely adopted, for connecting AI assistants to external tools and data. You implement an MCP server once — defining each tool, its input schema, and its description — and any MCP-compatible client (Claude Code, Claude Desktop, or another agent) can discover and invoke those tools automatically. Before MCP, you either hard-coded investigation logic into a fragile prompt or wrote a custom function-calling wrapper locked to one AI provider.

The design detail that makes this trustworthy is native tool use. When the agent decides to run, say, a breach check, it emits a tool call; your code executes the real underlying binary; and the real output is returned to the model. As the maintainer of OpenOSINT puts it, the model only ever reads real output and never generates it — so if a username tool finds twelve profiles, exactly those twelve go back into context and the model cannot invent a thirteenth. That is the maintainer's design claim, and it holds for the raw tool output; the model's summary of that output can still misread or overstate it, and text inside a tool result can carry instructions (see security), so check the summary against the raw output.

Which spec version applies? MCP versions are dates. The current revision is 2026-07-28, which makes the protocol stateless: each request carries its protocol version and client capabilities, servers must answer a server/discover call, and Roots, Sampling and Logging are deprecated (they keep working for at least twelve months). Clients and servers built for 2025-11-25 and earlier use the older handshake and can still interoperate through version negotiation. MCP versioning (checked 8 Oct 2026) Since 9 December 2025 the protocol is stewarded by the Agentic AI Foundation under the Linux Foundation rather than by Anthropic alone. Anthropic (9 Dec 2025)

Which AI apps support MCP in October 2026?

Every major assistant family now documents MCP support, but the details — which plans, which transports, read-only or read/write — differ. Only clients with a vendor documentation page are listed; each was checked on 8 October 2026.

ClientWhat is supportedCaveatSource
Claude CodeLocal (stdio) and remote (HTTP) MCP servers via claude mcp addAnthropic warns that servers fetching external content can expose you to prompt injectionClaude Code docs
ChatGPTDeveloper mode; full MCP (including write actions) rolling out in beta to Business, Enterprise and EduPro users get read/fetch only; web only; OpenAI warns untrusted servers raise prompt-injection riskOpenAI Help Center
OpenAI Responses APImcp tool type for remote servers; Secure MCP Tunnel for private onesCalls can be auto-approved or require explicit approval — keep approval onOpenAI API docs
OpenAI Agents SDKstdio, SSE and Streamable HTTP serversSupports MCP Python SDK v1 and v2Agents SDK docs
Gemini CLIstdio, SSE and Streamable HTTP serversFor unpaid-tier and Google One users, Gemini CLI was replaced by Antigravity CLI on 18 Jun 2026Gemini CLI docs
VS Code (Copilot)Add and manage MCP servers for agent modeMicrosoft: local MCP servers "can run arbitrary code on your machine"; a project's .vscode/mcp.json can define servers, so review it in shared reposVS Code docs
Copilot StudioMCP tools and resources in Microsoft agentsPrompts are not listed as supportedMicrosoft Learn
Cursorstdio, SSE and Streamable HTTP; OAuth for remote serversstdio servers run as local shell commands with your user's rightsCursor docs

Takeaway: write an OSINT MCP server once and it runs in all of these clients, but the plan you are on decides whether the agent can only read or can also act.

Which AI-agent OSINT tools matter in 2026?

A short, credible shortlist of what's actually shipping:

  • OpenOSINT — an MIT-licensed, MCP-native framework offering an interactive AI REPL, a direct CLI, a browser Web UI, and an MCP server. It wraps proven tools (holehe, Sherlock, sublist3r, PhoneInfoga, Have I Been Pwned, plus Shodan, VirusTotal, Censys, AbuseIPDB, DNS and RDAP lookups — 21 tools in v2.31.0, released 6 October 2026) so an agent can chain them, and runs on Anthropic Claude (default), local Ollama, or any OpenAI-compatible endpoint. PyPI (6 Oct 2026)
  • Vendor-run MCP servers — Have I Been Pwned, VirusTotal and Censys now host official MCP endpoints, so an agent can query those data sources directly with your own account and quota. Details, auth and caveats are in the verified table below.
  • The underlying open-source tools the agents drive — Sherlock and Maigret (username search across hundreds to 3,000+ sites), holehe (email-to-accounts), PhoneInfoga (phone numbers), theHarvester and GHunt (domain/company footprint), and SpiderFoot (automated recon; its README claims 200+ modules).

For a broader, continuously updated catalog, the community lists awesome-osint and the OSINT Framework remain the standard reference points, and Bellingcat's toolkit and methodology guides are the gold standard for verification-first investigation.

OSINT MCP servers that exist (October 2026)

Every server below was checked on 8 October 2026 against its package registry (npm or PyPI), the official MCP Registry or the vendor's own documentation. "Last activity" is the most recent release or documentation update we could confirm, not a GitHub commit date. A row here means "exists and is maintained", not "audited" — treat every server as code that runs with your keys.

ServerWhat it doesMaintainerAuthRepo / pageLast activityCaveats
Fetch (reference)Fetches a URL and converts it to Markdown for the modelMCP project (modelcontextprotocol/servers; PyPI author Anthropic, PBC)NoneGitHub · PyPImcp-server-fetch 2026.8.18 (18 Aug 2026)README: "can access local/internal IP addresses and may represent a security risk"; obeys robots.txt for model-initiated fetches unless disabled; every fetched page is untrusted input
Filesystem (reference)Read/write files inside directories you allowMCP projectNone (directory allow-list)GitHub · npm2026.8.31 (31 Aug 2026)Allow only the case folder; versions before 2025.7.01 had two path-escape CVEs (CVE-2025-53109, CVE-2025-53110)
Playwright MCPDrives a real browser through accessibility snapshots (navigate, click, read pages)MicrosoftNone (uses whatever browser profile you give it)GitHub · npm@playwright/mcp 0.0.83 (28 Sep 2026)README: "not a security boundary"; browser_run_code_unsafe is "RCE-equivalent"; logged-in sessions mean the agent acts as you — use a sock-puppet profile
Have I Been Pwned MCPBreach metadata, data classes, Pwned Passwords; email, domain, paste and stealer-log searchHave I Been Pwned (official, hosted)Public tools: none. Email/domain/stealer-log tools: OAuth (hibp.mcp scope) plus a qualifying HIBP subscriptionHIBP docs (endpoint haveibeenpwned.com/mcp)Registry listing 22 Jul 2026Searching a person's email is processing personal data — have a lawful basis; paid-plan rules still apply
VirusTotal MCPFile, URL, domain and IP reports; file/URL submissionVirusTotal (official)Free VTAI token (file) or OAuthGitHub · setupvt-mcp 0.9.8 (28 Sep 2026)Vendor-stated limits: 60 queries/minute and 1,000 per UTC day; submitting a file or URL hands it to a third party — never submit case material you cannot share
Censys Platform MCPSearch the Censys internet map (hosts, certificates, web properties)Censys (official, hosted)OAuth (recommended) or API token header; account needs the API Access roleCensys docsDocs updated 1 Sep 2026Calls spend Censys credits; a separate Adversary Investigation MCP server needs that paid module
Shodan MCP (community)Host/IP lookup, device search, DNS, CVE/CPE queriesCommunity — published on npm as @burtthecoder/mcp-shodanSHODAN_API_KEYnpm (metadata points to github.com/w0h1v/mcp-shodan)1.0.32 (8 Sep 2026)Not made by Shodan; the package's repository link moved from BurtTheCoder to w0h1v — confirm the publisher before installing
WhoisXML API MCP32 WHOIS, DNS, IP, threat-intel and bulk toolsWhoisXML API (vendor)WHOISXMLAPI_TOKEN (paid API)GitHub · npm1.8.7 (28 Sep 2026)Bulk tools can burn credits fast — cap them
whois-mcp-serverDomain registration, availability, DNS and IP/ASN via RDAP and DNS-over-HTTPSCommunity (cyanheads)None requiredGitHub · npm0.1.6 (30 Sep 2026)Pre-1.0; RDAP redacts most registrant data — cross-check in our RDAP Lookup
OpenOSINT21 OSINT tools (email, username, breach, phone, IP, DNS, Shodan, VirusTotal, Censys…) as one MCP serverTommaso Bertocchi / OpenOSINTPer tool (e.g. HIBP_API_KEY); some tools keylessGitHub · PyPI2.31.0 (6 Oct 2026)Three tools use Bright Data, one described as fetching URLs "bypassing Cloudflare/CAPTCHA" — that can breach site terms; one IP tool is marked sponsored
OSINT NavigatorFinds the right OSINT tool from a 7,500+ tool index (does not run the tools)Indicator with Buried SignalsIndicator membership (MCP and API are members-only)Indicator post (no public repo)Launched 13 Apr 2026Members get 50 queries/day; free web users get 10

Checked and left out: we found no official MCP server from Maltego, Shodan or urlscan.io — only third-party wrappers or paid gateways that proxy your queries through someone else's infrastructure. The SpiderFoot wrapper we inspected had two commits. If you rely on one of these, read its code first and pin the version.

Takeaway: prefer vendor-run servers (HIBP, VirusTotal, Censys) and the reference servers, pin versions, and treat community wrappers as unaudited code holding your API keys.

Is MCP safe for OSINT? Security risks and incidents

MCP is a connection standard, not a sandbox. An OSINT agent is unusually exposed because its whole job is to read attacker-controllable content — web pages, profiles, paste dumps, WHOIS records — and feed it to a model that can call more tools. The documented risks:

  • Prompt injection through tool output. Text in a fetched page or a GitHub issue can instruct the agent. Invariant Labs showed in May 2025 that a malicious public GitHub issue could make an agent using the official GitHub MCP server leak private-repository data. Invariant Labs (26 May 2025) OpenAI's MCP docs likewise warn that malicious servers "may include hidden instructions (prompt injections)". OpenAI (checked 8 Oct 2026)
  • Tool poisoning. Instructions hidden in a tool's description — which the model reads but the user usually does not — can steer the agent; Invariant Labs disclosed this class in April 2025 and reported Cursor and other clients as susceptible. Invariant Labs (1 Apr 2025)
  • Malicious or hijacked packages. The npm package postmark-mcp began silently BCC-ing every email it sent to an outside address from around version 1.0.16 (September 2025). Snyk (Sep 2025)
  • Bugs in MCP plumbing. mcp-remote allowed OS command injection when connecting to an untrusted server (CVE-2025-6514, CVSS 9.6), and MCP Inspector before 0.14.1 allowed unauthenticated remote code execution (CVE-2025-49596, CVSS 9.4). Both are patched — keep tooling updated.
  • Over-broad credentials. A stdio server reads its keys from your environment, so one compromised server can use every key in that shell. Give each server its own low-privilege key, and never let an OSINT agent hold credentials to your real accounts.

What the spec's authorization model does — and doesn't — cover. Authorization is optional in MCP. For HTTP servers it is OAuth 2.1-based: the server is a resource server, clients must request tokens bound to that specific server (RFC 8707 resource indicators), and servers "MUST NOT accept or transit any other tokens", which rules out token passthrough. Stdio servers instead take credentials from the environment. MCP authorization spec (2026-07-28) The tools spec adds that there "SHOULD always be a human in the loop with the ability to deny tool invocations". MCP tools spec None of this stops prompt injection: it governs who may call a server, not what a page tells your model. The project's security best practices cover confused-deputy, SSRF and scope-minimization attacks in detail.

Takeaway: assume anything an OSINT agent reads may try to give it orders, and limit what a hijacked agent could do with the tools and keys you have handed it.

How do you wire a safe OSINT agent?

A short checklist that applies whichever client and servers you choose. The OpSec half follows our OpSec & managed attribution guide; the legal half follows Is OSINT legal?

  1. Plan before you connect anything. Write the question, scope and stop conditions first — the AI Investigation Planner turns a selector into a step-by-step plan you can hand to the agent.
  2. Read-only by default. Connect lookup servers only; leave email-sending, posting and file-writing tools out of an investigation agent, and allow the filesystem server only on the case folder.
  3. Keep human approval on for every tool call that sends data out (submissions, searches on a person's name or email). The MCP spec recommends a human who can deny tool calls, and OpenAI's Responses API lets you require explicit approval per call.
  4. One key per server, least privilege, spend caps. Separate API keys you can revoke; set quota limits on paid sources (Censys credits, WhoisXML, VirusTotal's 1,000/day).
  5. Separate the sock puppet from you. Browser automation must use a dedicated profile, account and egress — never your logged-in personal browser. See sock-puppet accounts and machine isolation.
  6. Treat tool output as data, not instructions. Tell the agent so in its system prompt, and stop the run if it starts doing things you did not ask for.
  7. Respect rate limits, robots.txt and terms. Do not disable the fetch server's robots.txt handling or use CAPTCHA-bypass tools on sites whose terms forbid scraping — automation does not change what the law and the courts say about scraping.
  8. Log everything. Keep the agent's tool-call log and save each finding with a timestamp and hash in the Evidence Logger, so every claim in the report traces back to a captured source.
  9. Pivot with known-good tools. When the agent turns up a selector, check it by hand: dorks for a name or domain in the Dork Generator, URL patterns for a profile or post in the URL Pivot Encyclopedia, and ready-made prompts in the AI dork library (infrastructure, contact details, due diligence, verification).
  10. Verify before you report. Every agent finding is a lead until a human has opened the original source.

Takeaway: a safe OSINT agent is read-only, separated from your identity, approval-gated and fully logged.

AI geolocation: finding where a photo was taken — without EXIF

Most geolocation tools depend on EXIF metadata, which is stripped the moment an image is posted to most social platforms. The 2026 development is visual-inference geolocation. GeoSeer, launched in late 2025, uses a parallel multi-agent architecture to read raw visual cues — landmarks, architecture, terrain, signage, vegetation, lighting — and returns GPS coordinates, city, and country from a single image, no EXIF required. On the face-search side, PimEyes layered AI enhancements in 2026 to match a face across the open web despite changes in angle, age, and background.

These are powerful and correspondingly sensitive. Use them for legitimate verification — confirming the origin of footage, supporting missing-persons work — and never for stalking, doxxing, or surveillance of private individuals. If you want to work from the metadata side first, our in-browser EXIF Viewer maps any embedded GPS coordinates and lets you scrub metadata before sharing.

Browser-based alternatives to the CLI classics (no install)

Here's the catch with almost every tool above: it's a command-line Python program you have to install. That's fine for analysts with a configured environment, but a real barrier if you're on a locked-down machine, new to OSINT, or just need one quick lookup. Browser-based suites run the same categories of lookups against the same public sources, with no install and no signup. This is where Max Intel fits — as the no-setup alternative:

Popular CLI toolWhat it doesBrowser-based alternative (no install)
Sherlock / MaigretFind accounts by username across hundreds of sitesUsername Search
holeheDiscover accounts registered to an emailEmail Lookup
theHarvester / GHuntEmails, subdomains, and company footprintDomain OSINT
PhoneInfogaInvestigate a phone numberPhone Lookup
SpiderFootAutomated domain / IP reconnaissanceDomain + IP Lookup
ExifToolRead and strip photo metadataEXIF Viewer
WHOIS / RDAP CLIsDomain and IP registration dataRDAP Lookup

The trade-off is real: the CLI tools are more configurable and scriptable, and an MCP-driven agent can chain them at speed. The browser tools win on zero setup and instant access. Many investigators use both — a browser suite for the first pass and quick pivots, the CLI/agent stack for depth.

Using AI agents for OSINT responsibly

OSINT works only with publicly available information, but legality depends on how you collect and use it. The reputable AI-OSINT projects state plainly that they are for authorized security research, penetration testing, and investigative journalism, and that users are responsible for compliance with laws such as GDPR, CCPA, and the CFAA. Automation raises the stakes because it makes it trivial to gather a lot, fast:

  • Verify everything. Even tool-grounded agents can misread output; a general chatbot asked to "investigate" someone will confidently invent accounts and connections. Always trace an AI-surfaced finding back to its original source.
  • Respect terms and rate limits. Aggressive automated scraping breaks platform rules and gets you blocked or worse.
  • Never use these tools for stalking, harassment, doxxing, or unauthorized surveillance. The same ethical guardrails that apply to any OSINT work apply here — automation just makes discipline more important.
  • Keep your identity out of the agent's footprint. Run agents from sock-puppet accounts and isolated browsers, as set out in our OpSec & managed attribution guide, and check the jurisdiction-specific rules in Is OSINT legal? before automating collection on people.

The limitations (an honest assessment)

Agentic OSINT is genuinely useful, but it is not magic. Agents can only see what's already public — private profiles, paywalled content, and login-gated data stay invisible. Non-tool-grounded "AI investigation" is prone to hallucination, and even tool-grounded agents can be steered by instructions planted in the pages and records they read. Running many API-backed tools costs money, and platforms actively rate-limit and block automated access. And the broader lesson from 2026 research holds: AI answer systems behave like consensus engines, trusting facts that appear across multiple independent sources — so a single tool's output is a lead to verify, not a conclusion. Treat the agent as a fast, tireless junior analyst whose work you always check.

Sources and further reading

OpenOSINT (github.com/OpenOSINT/OpenOSINT) and openosint.tech; the awesome-osint list; the OSINT Framework; Bellingcat's Online Investigation Toolkit; GeoSeer (geoseeer.com); and the official Model Context Protocol documentation (modelcontextprotocol.io). Statistics and tool capabilities are directional and change monthly — re-verify anything that will drive a decision, and confirm each tool is current and reputable before use.

Added in the October 2026 update (all checked 8 October 2026):