Update — October 2026
What changed since this guide was last revised (6 September 2026), one line per item, re-checked on 8 October 2026:
- 28 Jul 2026 — new spec revision. The current MCP protocol version is
2026-07-28; it removes theinitializehandshake and protocol-level sessions, adds a mandatoryserver/discovercall, and deprecates the Roots, Sampling and Logging features. MCP changelog (2026-07-28) - 9 Dec 2025 — new governance. Anthropic donated MCP to the Agentic AI Foundation, a directed fund under the Linux Foundation co-founded by Anthropic, Block and OpenAI. Anthropic (9 Dec 2025)
- Clients. MCP is now documented in Claude Code, ChatGPT (full MCP in beta for Business, Enterprise and Edu), OpenAI's Responses API and Agents SDK, VS Code, Copilot Studio, Cursor and Gemini CLI — see the client table for sources and caveats.
- Official vendor servers. Have I Been Pwned (registry listing 22 Jul 2026), VirusTotal (
vt-mcp0.9.8, 28 Sep 2026) and Censys (docs updated 1 Sep 2026) now run their own MCP servers — see the verified server table. - OpenOSINT is now v2.31.0 (6 Oct 2026) with 21 tools, up from v2.27 and 20 tools. PyPI (6 Oct 2026)
- OSINT Navigator (Indicator and Buried Signals, launched 13 Apr 2026) lets Indicator members query its 7,500+ tool index from an AI agent over MCP. Indicator (13 Apr 2026)
- Registry ≠ vetting. The official MCP Registry says consumers "should assume minimal-to-no moderation"; a listing proves who published a server, not that it is safe. MCP Registry moderation policy (checked 8 Oct 2026)
- Corrections. We removed two claims we could not verify (an unnamed "~64-tool" OSINT server and a generic "skill catalog" bullet), corrected SpiderFoot from "100+ sources" to its README's "200+ modules", and corrected OpenOSINT's username tool to Sherlock (it does not bundle Maigret).
The biggest OSINT shift of 2026 is agentic investigation: instead of manually running one tool at a time, you hand a target to an AI agent that decides which tools to run, pivots on what it finds, and writes the report. The enabler is the Model Context Protocol (MCP) — an open standard that lets AI assistants call external tools. Open-source frameworks like OpenOSINT (MIT-licensed; AI REPL + CLI + MCP server) wrap proven utilities such as Sherlock, holehe, PhoneInfoga, and Have I Been Pwned so an agent can chain them. Crucially, the credible tools use native tool-calling: the AI reads real tool output and cannot fabricate findings. Alongside this, AI geolocation (e.g., GeoSeer, launched late 2025) now pinpoints photos from visual cues without EXIF. And if you don't want to install Python CLIs, browser-based suites run the same categories of lookups with no setup.
What is AI-agent OSINT, and how is it different?
AI-agent OSINT is open-source intelligence gathering driven by an autonomous AI agent rather than a human clicking through tools one at a time. You give the agent a starting point — an email, username, domain, or IP — and it scopes the task, decides which tools to run, chains them based on what each returns, verifies against real sources, and compiles a structured report. It is the difference between keeping fifteen browser tabs open and asking a competent junior analyst to "look into this and write it up."
The old workflow was passive aggregation: every tool a silo, every pivot manual, and the investigation logic — what to run next, what a finding means — living entirely in your head. The 2026 workflow is active and reasoning-driven. A typical agent loop looks like: generate search dorks for the target → enumerate accounts tied to an email → check breach databases → pivot to a discovered username → search that username across platforms → save the report. Each step is chosen by the model in response to the previous step's real output.
How does an OSINT MCP server work?
The Model Context Protocol (MCP) is an open standard, introduced by Anthropic and now widely adopted, for connecting AI assistants to external tools and data. You implement an MCP server once — defining each tool, its input schema, and its description — and any MCP-compatible client (Claude Code, Claude Desktop, or another agent) can discover and invoke those tools automatically. Before MCP, you either hard-coded investigation logic into a fragile prompt or wrote a custom function-calling wrapper locked to one AI provider.
The design detail that makes this trustworthy is native tool use. When the agent decides to run, say, a breach check, it emits a tool call; your code executes the real underlying binary; and the real output is returned to the model. As the maintainer of OpenOSINT puts it, the model only ever reads real output and never generates it — so if a username tool finds twelve profiles, exactly those twelve go back into context and the model cannot invent a thirteenth. That is the maintainer's design claim, and it holds for the raw tool output; the model's summary of that output can still misread or overstate it, and text inside a tool result can carry instructions (see security), so check the summary against the raw output.
Which spec version applies? MCP versions are dates. The current revision is 2026-07-28, which makes the protocol stateless: each request carries its protocol version and client capabilities, servers must answer a server/discover call, and Roots, Sampling and Logging are deprecated (they keep working for at least twelve months). Clients and servers built for 2025-11-25 and earlier use the older handshake and can still interoperate through version negotiation. MCP versioning (checked 8 Oct 2026) Since 9 December 2025 the protocol is stewarded by the Agentic AI Foundation under the Linux Foundation rather than by Anthropic alone. Anthropic (9 Dec 2025)
Which AI apps support MCP in October 2026?
Every major assistant family now documents MCP support, but the details — which plans, which transports, read-only or read/write — differ. Only clients with a vendor documentation page are listed; each was checked on 8 October 2026.
| Client | What is supported | Caveat | Source |
|---|---|---|---|
| Claude Code | Local (stdio) and remote (HTTP) MCP servers via claude mcp add | Anthropic warns that servers fetching external content can expose you to prompt injection | Claude Code docs |
| ChatGPT | Developer mode; full MCP (including write actions) rolling out in beta to Business, Enterprise and Edu | Pro users get read/fetch only; web only; OpenAI warns untrusted servers raise prompt-injection risk | OpenAI Help Center |
| OpenAI Responses API | mcp tool type for remote servers; Secure MCP Tunnel for private ones | Calls can be auto-approved or require explicit approval — keep approval on | OpenAI API docs |
| OpenAI Agents SDK | stdio, SSE and Streamable HTTP servers | Supports MCP Python SDK v1 and v2 | Agents SDK docs |
| Gemini CLI | stdio, SSE and Streamable HTTP servers | For unpaid-tier and Google One users, Gemini CLI was replaced by Antigravity CLI on 18 Jun 2026 | Gemini CLI docs |
| VS Code (Copilot) | Add and manage MCP servers for agent mode | Microsoft: local MCP servers "can run arbitrary code on your machine"; a project's .vscode/mcp.json can define servers, so review it in shared repos | VS Code docs |
| Copilot Studio | MCP tools and resources in Microsoft agents | Prompts are not listed as supported | Microsoft Learn |
| Cursor | stdio, SSE and Streamable HTTP; OAuth for remote servers | stdio servers run as local shell commands with your user's rights | Cursor docs |
Takeaway: write an OSINT MCP server once and it runs in all of these clients, but the plan you are on decides whether the agent can only read or can also act.
Which AI-agent OSINT tools matter in 2026?
A short, credible shortlist of what's actually shipping:
- OpenOSINT — an MIT-licensed, MCP-native framework offering an interactive AI REPL, a direct CLI, a browser Web UI, and an MCP server. It wraps proven tools (holehe, Sherlock, sublist3r, PhoneInfoga, Have I Been Pwned, plus Shodan, VirusTotal, Censys, AbuseIPDB, DNS and RDAP lookups — 21 tools in v2.31.0, released 6 October 2026) so an agent can chain them, and runs on Anthropic Claude (default), local Ollama, or any OpenAI-compatible endpoint. PyPI (6 Oct 2026)
- Vendor-run MCP servers — Have I Been Pwned, VirusTotal and Censys now host official MCP endpoints, so an agent can query those data sources directly with your own account and quota. Details, auth and caveats are in the verified table below.
- The underlying open-source tools the agents drive — Sherlock and Maigret (username search across hundreds to 3,000+ sites), holehe (email-to-accounts), PhoneInfoga (phone numbers), theHarvester and GHunt (domain/company footprint), and SpiderFoot (automated recon; its README claims 200+ modules).
For a broader, continuously updated catalog, the community lists awesome-osint and the OSINT Framework remain the standard reference points, and Bellingcat's toolkit and methodology guides are the gold standard for verification-first investigation.
OSINT MCP servers that exist (October 2026)
Every server below was checked on 8 October 2026 against its package registry (npm or PyPI), the official MCP Registry or the vendor's own documentation. "Last activity" is the most recent release or documentation update we could confirm, not a GitHub commit date. A row here means "exists and is maintained", not "audited" — treat every server as code that runs with your keys.
| Server | What it does | Maintainer | Auth | Repo / page | Last activity | Caveats |
|---|---|---|---|---|---|---|
| Fetch (reference) | Fetches a URL and converts it to Markdown for the model | MCP project (modelcontextprotocol/servers; PyPI author Anthropic, PBC) | None | GitHub · PyPI | mcp-server-fetch 2026.8.18 (18 Aug 2026) | README: "can access local/internal IP addresses and may represent a security risk"; obeys robots.txt for model-initiated fetches unless disabled; every fetched page is untrusted input |
| Filesystem (reference) | Read/write files inside directories you allow | MCP project | None (directory allow-list) | GitHub · npm | 2026.8.31 (31 Aug 2026) | Allow only the case folder; versions before 2025.7.01 had two path-escape CVEs (CVE-2025-53109, CVE-2025-53110) |
| Playwright MCP | Drives a real browser through accessibility snapshots (navigate, click, read pages) | Microsoft | None (uses whatever browser profile you give it) | GitHub · npm | @playwright/mcp 0.0.83 (28 Sep 2026) | README: "not a security boundary"; browser_run_code_unsafe is "RCE-equivalent"; logged-in sessions mean the agent acts as you — use a sock-puppet profile |
| Have I Been Pwned MCP | Breach metadata, data classes, Pwned Passwords; email, domain, paste and stealer-log search | Have I Been Pwned (official, hosted) | Public tools: none. Email/domain/stealer-log tools: OAuth (hibp.mcp scope) plus a qualifying HIBP subscription | HIBP docs (endpoint haveibeenpwned.com/mcp) | Registry listing 22 Jul 2026 | Searching a person's email is processing personal data — have a lawful basis; paid-plan rules still apply |
| VirusTotal MCP | File, URL, domain and IP reports; file/URL submission | VirusTotal (official) | Free VTAI token (file) or OAuth | GitHub · setup | vt-mcp 0.9.8 (28 Sep 2026) | Vendor-stated limits: 60 queries/minute and 1,000 per UTC day; submitting a file or URL hands it to a third party — never submit case material you cannot share |
| Censys Platform MCP | Search the Censys internet map (hosts, certificates, web properties) | Censys (official, hosted) | OAuth (recommended) or API token header; account needs the API Access role | Censys docs | Docs updated 1 Sep 2026 | Calls spend Censys credits; a separate Adversary Investigation MCP server needs that paid module |
| Shodan MCP (community) | Host/IP lookup, device search, DNS, CVE/CPE queries | Community — published on npm as @burtthecoder/mcp-shodan | SHODAN_API_KEY | npm (metadata points to github.com/w0h1v/mcp-shodan) | 1.0.32 (8 Sep 2026) | Not made by Shodan; the package's repository link moved from BurtTheCoder to w0h1v — confirm the publisher before installing |
| WhoisXML API MCP | 32 WHOIS, DNS, IP, threat-intel and bulk tools | WhoisXML API (vendor) | WHOISXMLAPI_TOKEN (paid API) | GitHub · npm | 1.8.7 (28 Sep 2026) | Bulk tools can burn credits fast — cap them |
| whois-mcp-server | Domain registration, availability, DNS and IP/ASN via RDAP and DNS-over-HTTPS | Community (cyanheads) | None required | GitHub · npm | 0.1.6 (30 Sep 2026) | Pre-1.0; RDAP redacts most registrant data — cross-check in our RDAP Lookup |
| OpenOSINT | 21 OSINT tools (email, username, breach, phone, IP, DNS, Shodan, VirusTotal, Censys…) as one MCP server | Tommaso Bertocchi / OpenOSINT | Per tool (e.g. HIBP_API_KEY); some tools keyless | GitHub · PyPI | 2.31.0 (6 Oct 2026) | Three tools use Bright Data, one described as fetching URLs "bypassing Cloudflare/CAPTCHA" — that can breach site terms; one IP tool is marked sponsored |
| OSINT Navigator | Finds the right OSINT tool from a 7,500+ tool index (does not run the tools) | Indicator with Buried Signals | Indicator membership (MCP and API are members-only) | Indicator post (no public repo) | Launched 13 Apr 2026 | Members get 50 queries/day; free web users get 10 |
Checked and left out: we found no official MCP server from Maltego, Shodan or urlscan.io — only third-party wrappers or paid gateways that proxy your queries through someone else's infrastructure. The SpiderFoot wrapper we inspected had two commits. If you rely on one of these, read its code first and pin the version.
Takeaway: prefer vendor-run servers (HIBP, VirusTotal, Censys) and the reference servers, pin versions, and treat community wrappers as unaudited code holding your API keys.
Is MCP safe for OSINT? Security risks and incidents
MCP is a connection standard, not a sandbox. An OSINT agent is unusually exposed because its whole job is to read attacker-controllable content — web pages, profiles, paste dumps, WHOIS records — and feed it to a model that can call more tools. The documented risks:
- Prompt injection through tool output. Text in a fetched page or a GitHub issue can instruct the agent. Invariant Labs showed in May 2025 that a malicious public GitHub issue could make an agent using the official GitHub MCP server leak private-repository data. Invariant Labs (26 May 2025) OpenAI's MCP docs likewise warn that malicious servers "may include hidden instructions (prompt injections)". OpenAI (checked 8 Oct 2026)
- Tool poisoning. Instructions hidden in a tool's description — which the model reads but the user usually does not — can steer the agent; Invariant Labs disclosed this class in April 2025 and reported Cursor and other clients as susceptible. Invariant Labs (1 Apr 2025)
- Malicious or hijacked packages. The npm package
postmark-mcpbegan silently BCC-ing every email it sent to an outside address from around version 1.0.16 (September 2025). Snyk (Sep 2025) - Bugs in MCP plumbing.
mcp-remoteallowed OS command injection when connecting to an untrusted server (CVE-2025-6514, CVSS 9.6), and MCP Inspector before 0.14.1 allowed unauthenticated remote code execution (CVE-2025-49596, CVSS 9.4). Both are patched — keep tooling updated. - Over-broad credentials. A stdio server reads its keys from your environment, so one compromised server can use every key in that shell. Give each server its own low-privilege key, and never let an OSINT agent hold credentials to your real accounts.
What the spec's authorization model does — and doesn't — cover. Authorization is optional in MCP. For HTTP servers it is OAuth 2.1-based: the server is a resource server, clients must request tokens bound to that specific server (RFC 8707 resource indicators), and servers "MUST NOT accept or transit any other tokens", which rules out token passthrough. Stdio servers instead take credentials from the environment. MCP authorization spec (2026-07-28) The tools spec adds that there "SHOULD always be a human in the loop with the ability to deny tool invocations". MCP tools spec None of this stops prompt injection: it governs who may call a server, not what a page tells your model. The project's security best practices cover confused-deputy, SSRF and scope-minimization attacks in detail.
Takeaway: assume anything an OSINT agent reads may try to give it orders, and limit what a hijacked agent could do with the tools and keys you have handed it.
How do you wire a safe OSINT agent?
A short checklist that applies whichever client and servers you choose. The OpSec half follows our OpSec & managed attribution guide; the legal half follows Is OSINT legal?
- Plan before you connect anything. Write the question, scope and stop conditions first — the AI Investigation Planner turns a selector into a step-by-step plan you can hand to the agent.
- Read-only by default. Connect lookup servers only; leave email-sending, posting and file-writing tools out of an investigation agent, and allow the filesystem server only on the case folder.
- Keep human approval on for every tool call that sends data out (submissions, searches on a person's name or email). The MCP spec recommends a human who can deny tool calls, and OpenAI's Responses API lets you require explicit approval per call.
- One key per server, least privilege, spend caps. Separate API keys you can revoke; set quota limits on paid sources (Censys credits, WhoisXML, VirusTotal's 1,000/day).
- Separate the sock puppet from you. Browser automation must use a dedicated profile, account and egress — never your logged-in personal browser. See sock-puppet accounts and machine isolation.
- Treat tool output as data, not instructions. Tell the agent so in its system prompt, and stop the run if it starts doing things you did not ask for.
- Respect rate limits, robots.txt and terms. Do not disable the fetch server's robots.txt handling or use CAPTCHA-bypass tools on sites whose terms forbid scraping — automation does not change what the law and the courts say about scraping.
- Log everything. Keep the agent's tool-call log and save each finding with a timestamp and hash in the Evidence Logger, so every claim in the report traces back to a captured source.
- Pivot with known-good tools. When the agent turns up a selector, check it by hand: dorks for a name or domain in the Dork Generator, URL patterns for a profile or post in the URL Pivot Encyclopedia, and ready-made prompts in the AI dork library (infrastructure, contact details, due diligence, verification).
- Verify before you report. Every agent finding is a lead until a human has opened the original source.
Takeaway: a safe OSINT agent is read-only, separated from your identity, approval-gated and fully logged.
AI geolocation: finding where a photo was taken — without EXIF
Most geolocation tools depend on EXIF metadata, which is stripped the moment an image is posted to most social platforms. The 2026 development is visual-inference geolocation. GeoSeer, launched in late 2025, uses a parallel multi-agent architecture to read raw visual cues — landmarks, architecture, terrain, signage, vegetation, lighting — and returns GPS coordinates, city, and country from a single image, no EXIF required. On the face-search side, PimEyes layered AI enhancements in 2026 to match a face across the open web despite changes in angle, age, and background.
These are powerful and correspondingly sensitive. Use them for legitimate verification — confirming the origin of footage, supporting missing-persons work — and never for stalking, doxxing, or surveillance of private individuals. If you want to work from the metadata side first, our in-browser EXIF Viewer maps any embedded GPS coordinates and lets you scrub metadata before sharing.
Browser-based alternatives to the CLI classics (no install)
Here's the catch with almost every tool above: it's a command-line Python program you have to install. That's fine for analysts with a configured environment, but a real barrier if you're on a locked-down machine, new to OSINT, or just need one quick lookup. Browser-based suites run the same categories of lookups against the same public sources, with no install and no signup. This is where Max Intel fits — as the no-setup alternative:
| Popular CLI tool | What it does | Browser-based alternative (no install) |
|---|---|---|
| Sherlock / Maigret | Find accounts by username across hundreds of sites | Username Search |
| holehe | Discover accounts registered to an email | Email Lookup |
| theHarvester / GHunt | Emails, subdomains, and company footprint | Domain OSINT |
| PhoneInfoga | Investigate a phone number | Phone Lookup |
| SpiderFoot | Automated domain / IP reconnaissance | Domain + IP Lookup |
| ExifTool | Read and strip photo metadata | EXIF Viewer |
| WHOIS / RDAP CLIs | Domain and IP registration data | RDAP Lookup |
The trade-off is real: the CLI tools are more configurable and scriptable, and an MCP-driven agent can chain them at speed. The browser tools win on zero setup and instant access. Many investigators use both — a browser suite for the first pass and quick pivots, the CLI/agent stack for depth.
Using AI agents for OSINT responsibly
OSINT works only with publicly available information, but legality depends on how you collect and use it. The reputable AI-OSINT projects state plainly that they are for authorized security research, penetration testing, and investigative journalism, and that users are responsible for compliance with laws such as GDPR, CCPA, and the CFAA. Automation raises the stakes because it makes it trivial to gather a lot, fast:
- Verify everything. Even tool-grounded agents can misread output; a general chatbot asked to "investigate" someone will confidently invent accounts and connections. Always trace an AI-surfaced finding back to its original source.
- Respect terms and rate limits. Aggressive automated scraping breaks platform rules and gets you blocked or worse.
- Never use these tools for stalking, harassment, doxxing, or unauthorized surveillance. The same ethical guardrails that apply to any OSINT work apply here — automation just makes discipline more important.
- Keep your identity out of the agent's footprint. Run agents from sock-puppet accounts and isolated browsers, as set out in our OpSec & managed attribution guide, and check the jurisdiction-specific rules in Is OSINT legal? before automating collection on people.
The limitations (an honest assessment)
Agentic OSINT is genuinely useful, but it is not magic. Agents can only see what's already public — private profiles, paywalled content, and login-gated data stay invisible. Non-tool-grounded "AI investigation" is prone to hallucination, and even tool-grounded agents can be steered by instructions planted in the pages and records they read. Running many API-backed tools costs money, and platforms actively rate-limit and block automated access. And the broader lesson from 2026 research holds: AI answer systems behave like consensus engines, trusting facts that appear across multiple independent sources — so a single tool's output is a lead to verify, not a conclusion. Treat the agent as a fast, tireless junior analyst whose work you always check.
Sources and further reading
OpenOSINT (github.com/OpenOSINT/OpenOSINT) and openosint.tech; the awesome-osint list; the OSINT Framework; Bellingcat's Online Investigation Toolkit; GeoSeer (geoseeer.com); and the official Model Context Protocol documentation (modelcontextprotocol.io). Statistics and tool capabilities are directional and change monthly — re-verify anything that will drive a decision, and confirm each tool is current and reputable before use.
Added in the October 2026 update (all checked 8 October 2026):
- MCP specification: versioning, 2026-07-28 changelog, authorization, tools, security best practices, registry and its moderation policy.
- Governance and history: Anthropic, Introducing the Model Context Protocol (25 Nov 2024) and Donating MCP and establishing the Agentic AI Foundation (9 Dec 2025).
- Client documentation: linked in the client table.
- Server data: npm and PyPI release metadata, the MCP Registry API, and the vendor pages linked in the server table.
- Incidents: Invariant Labs (tool poisoning, GitHub MCP), Snyk on postmark-mcp, and NVD entries for CVE-2025-6514, CVE-2025-49596, CVE-2025-53109 and CVE-2025-53110.