protogrid

Search / com.thetempleofdoom.osint-mcp/osint-terminal

osint-terminal

R0 · no sign-in

454 OSINT recon tools + server-side entity correlation & person sweeps. Keyless.

v1.1.0 · active · descriptor JSON · versions

An agent can connect right now, no human step.Remote endpoint, no authentication, reachable on the last probe.
Quality64needs work
Trust79of 100
Uptime, 30 days93%
Latency p50360 ms

Connect

8 clients · secrets stay placeholders
{
  "mcpServers": {
    "osint-terminal": {
      "type": "http",
      "url": "https://osint-mcp.thetempleofdoom.com/mcp"
    }
  }
}
claude mcp add --transport http osint-terminal https://osint-mcp.thetempleofdoom.com/mcp
[mcp_servers.osint-terminal]
url = "https://osint-mcp.thetempleofdoom.com/mcp"
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "osint-terminal": {
      "type": "remote",
      "url": "https://osint-mcp.thetempleofdoom.com/mcp",
      "enabled": true
    }
  }
}
{
  "mcpServers": {
    "osint-terminal": {
      "type": "http",
      "url": "https://osint-mcp.thetempleofdoom.com/mcp"
    }
  },
  "deeplink": "cursor://anysphere.cursor-deeplink/mcp/install?name=osint-terminal&config=eyJ0eXBlIjoiaHR0cCIsInVybCI6Imh0dHBzOi8vb3NpbnQtbWNwLnRoZXRlbXBsZW9mZG9vbS5jb20vbWNwIn0%3D"
}
{
  "servers": {
    "osint-terminal": {
      "type": "http",
      "url": "https://osint-mcp.thetempleofdoom.com/mcp"
    }
  }
}
{
  "mcpServers": {
    "osint-terminal": {
      "httpUrl": "https://osint-mcp.thetempleofdoom.com/mcp"
    }
  }
}
extensions:
  "osint-terminal":
    enabled: true
    name: "osint-terminal"
    type: streamable_http
    uri: "https://osint-mcp.thetempleofdoom.com/mcp"
    timeout: 300

Quality 64 / 100needs work

protocol88 · weight 25
  • pass
    protocol.modernsupports 2026-07-28 (server/discover)
  • pass
    protocol.statelessanswers without a session
  • pass
    protocol.transportstreamable HTTP
  • warn
    protocol.list_ttltools/list declares ttlMs 0, so clients re-fetch it on every use
authorizationn/a · weight 15
  • n/a
    auth.prm, auth.as_metadata, auth.cimdno remote uses OAuth
  • n/a
    auth.secret_in_urlno templated URL
tool hygiene64 · weight 30
  • pass
    tools.descriptionsevery tool has a description
  • pass
    tools.description_lengthdescriptions are concise
  • pass
    tools.schemasevery tool has an object input schema
  • fail
    tools.annotationsno tool declares readOnlyHint or destructiveHint, so clients cannot tell safe calls from risky ones
  • fail
    tools.directory_hintsno tool declares all four of readOnlyHint, destructiveHint, idempotentHint and openWorldHint; missing: headers (readOnlyHint, destructiveHint, idempotentHint, openWorldHint); asn (readOnlyHint, destructiveHint, idempotentHint, openWorldHint); reverseip (readOnlyHint, destructiveHint, idempotentHint, openWorldHint); …
  • warn
    tools.token_costabout 19,661 tokens to load every tool
  • pass
    tools.api_dumptools are not a one-to-one API dump
stability25 · weight 15
  • warn
    stability.changes21 tool changes in 30 days
  • fail
    stability.rug_pull1 tools kept their name but changed most of their description in 30 days; review before trusting them
dependenciesn/a · weight 15
  • n/a
    deps.known_vulns, deps.mcp_sdk_version, deps.resolvableno npm or PyPI package

474 tools, about 19,661 tokens to load them all · tool set 452e1a9bb500 · tools last changed 2026-10-09 · checked 2026-10-09 23:53 UTC

Tool changes

  • social_deepadded

    SOCIAL DEEP: All-Platform Link Set: 'name | username | phone | email' (pipe-separated, use what you have) -> ready URL sets for FB/IG/TikTok/X/LinkedIn/Reddit/Discord/Snap/Bluesky/WhatsApp/biolinks

  • workupadded

    WORKUP: Full Person Dossier: first+last -> username variants x 16 platforms, name stats, dork surfaces, wiki (30-60s)

  • fbsearchadded

    FB Search URLs (graph replacement): name [| keyword] -> ready facebook search URLs: people/posts/all/keyword-filtered

  • hunter_countadded

    Hunter: Email Count: How many emails findable for a domain (free)

  • hunter_verifyadded

    Hunter: Verify Email: Deliverability verdict: valid/invalid/accept_all + score

  • hunter_findadded

    Hunter: Find Email: name + domain -> most likely email (usage: first last domain)

  • hunter_domainadded

    Hunter: Domain Emails: All findable emails for a domain + names/positions/confidence

  • human_sweepadded

    Human Sweep: Auto-detect target type, run all matching human tools, merge entities

  • bssid_geoadded

    WiFi BSSID Geo: BSSID/cell -> approximate location (Mylnikov free DB)

  • gps_deepadded

    GPS Full Context: Coords/place -> address, sun times, nearby POIs, map links

Showing the latest 10. Full history: list_changes · trend: quality JSON.

Checks run on what our credential-free, read-only probes observe; tools are never called and no code audit is performed. How it is computed.

Trust 79 / 100

no-repository
provenance45
liveness97
freshness100
hygiene80

+dns-namespace +reachable +uptime-93% +updated-16d-ago -no-repository

Derived from observable signals (official registry feed and our own credential-free probes); no code audit performed. How it is computed.

Endpoints

remoteauthreachableuptime 30dp50protocollast ok
https://osint-mcp.thetempleofdoom.com/mcp streamable-httpnoneyes93%360 ms2026-07-282026-10-09

Tools (474)

abusecontactAbuse Contact: Authoritative abuse email (RIPEstat finder)
adstxtads.txt: Ad-tech sellers declared in ads.txt
agent_manifestSelf-describing manifest of all OSINT Terminal agent endpoints.
agifyAge Predictor: Predict age from a first name (agify.io)
airqualityAir Quality: PM2.5/PM10/European AQI at coords (Open-Meteo, no key)
antipodeAntipode: Opposite point on Earth for coords (offline)
api_key_scanAPI Key Exposure: Scan GitHub/Pastebin/Google for exposed API keys/secrets
apileakAPI Leak Search: GitHub dork links for API key/secret exposure
apodNASA APOD: Astronomy Picture of the Day (optional date)
apt_trackAPT Track: Track APT campaigns via MITRE + researchers
archiveorgArchive.org Item: Internet Archive item metadata
arxivarXiv Search: arXiv paper search by title/author/keyword
ascii85Ascii85: Ascii85 encode/decode (offline)
asnASN / BGP: ASN details or prefixes for an IP
asnlookupASN Lookup: ASN org/country/prefixes via RIPEstat
asnprefixesASN Prefixes: All announced prefixes for an ASN (RIPEstat)
asrankAS Rank (CAIDA): Global ASN ranking + customer cone size
atbashAtbash Cipher: Atbash A↔Z mirror cipher (offline, self-inverse)
attack_surfaceAttack Surface: Map attack surface: services + endpoints + API
barcodeBarcode Validate: EAN-13 / UPC-A check digit validation (offline)
base32Base32 Encode/Decode: RFC 4648 Base32 encode or decode
base36Base36 Codec: Encode int <-> base36, autodetecting direction (offline)
base58Base58 Codec: Bitcoin base58 encode/decode: 'hex:..' / 'b58:..' (offline)
base64Base64: Auto decode/encode base64 (offline)
base_convertBase Convert: Binary/octal/decimal/hex number conversion (offline)
bearingBearing: Initial compass bearing between two coord pairs (offline)
bgphistoryBGP History: Routing origin history (RIPE Stat)
bimiBIMI: Brand-indicator (logo) DNS record
binCard BIN: Issuer/scheme/country from card BIN (binlist)
binarytextBinary Text: Text ↔ 8-bit binary (offline)
binlookupBIN Lookup: Card BIN → bank, brand, country, type
blockheightBlock Height: Current Bitcoin + Ethereum block height
blueskyBluesky: AT Protocol public profile
botnet_trackerBotnet Tracker: Botnet C2 + IoT malware tracking
breach_aggregatorBreach Aggregator: Aggregate breach databases (XposedOrNot, LeakCheck, etc)
breachdbBreachDB Search: Aggregated breach collection search
breachdirectoryBreach Directory: ProxyNova COMB dataset search for credential exposure
breachsearchBreach Catalog: Public HIBP breach metadata search
brewHomebrew: Formula/cask version, deps, installs
bssid_geoWiFi BSSID Geo: BSSID/cell -> approximate location (Mylnikov free DB)
btcaddrBTC Address: Bitcoin balance/tx via mempool.space
btcfeesBTC Fees: Recommended Bitcoin fees sat/vB (mempool.space)
c2_infrastructureC2 Infrastructure: Detect C2 infrastructure + hosting
caaCAA Records: Which CAs may issue certs for the domain
caesarCaesar Cipher: ROT-N / Caesar brute force, all 25 shifts (offline)
cameraCamera Exposure: RTSP/ONVIF + camera-port exposure (per-target)
casifyCase Convert: snake/camel/Pascal/kebab/CONSTANT case (offline)
cdnjscdnjs: Hosted JS library version + assets
cdxwaybackWayback CDX: Snapshot count + first/latest capture in Wayback Machine
certhistoryCert History: crt.sh issuer timeline & counts
cfradarCloudflare Radar: Domain rank + categories from Cloudflare Radar
checksumCRC32/Adler32: CRC32 + Adler32 checksum of input text (offline)
chesscomChess.com: Public player profile + ratings
cidrCIDR Calculator: Subnet calc: network, mask, host range, count (offline)
cidrinfoCIDR Calculator: Network/broadcast/host-count (offline)
circlhashHash Lookup: Known-file lookup (CIRCL hashlookup)
cisa_alertsCISA Alerts: CISA alerts + advisories (recent threats)
clickjackingClickjacking: X-Frame-Options + CSP frame-ancestors check
cloudCloud Provider: AWS/GCP/Azure/etc. detection + hosting flag
codebergCodeberg: Codeberg/Gitea public user
codeforcesCodeforces: Codeforces competitive programmer rating & rank
coininfoCoin Info: Coin metadata: categories, algorithm, genesis (CoinGecko)
colorColor Parser: hex/rgb -> rgb/hsl + nearest name (offline)
comb_searchCOMB Credential Search: Search COMB breach compilation via ProxyNova free API
commoncrawlCommon Crawl: Captures of a domain in Common Crawl index
cookiesCookie Audit: Secure/HttpOnly/SameSite flag review
correlate_sweepRun a 40-tool broad sweep on the query and return the cross-tool entity graph: emails/domains/IPs/handles/phones appearing in >=2 tools, strongest first. This is the connected-pattern signal.
corsCORS Check: Origin-reflection / wildcard misconfig
countryCountry Profile: World Bank country profile by ISO code
cpeCPE → CVEs: NVD: recent CVEs affecting a CPE 2.3 string
cpfcnpjCPF / CNPJ: Brazilian doc checksum (offline)
cratedownloadsCrate Downloads: Download totals for a Rust crate
cratescrates.io: Rust crate stats + downloads
cratestatscrates.io Stats: Rust crate downloads, version, repo (no key)
crc32CRC-32 Checksum: Compute CRC-32 of input
credential_stuffingCredential Stuffing Risk: Check breach + stuffing risk
creditcardCard Brand: Identify card brand + Luhn validity (offline)
creditcardtestCredit Card Validator: Luhn check + brand guess (test only)
cronCron Explain: Explain a 5-field cron expression (offline)
crossrefauthorCrossref Author: Works by author/keyword (Crossref)
cryptoCrypto Address: BTC/ETH balance & tx history
cryptomarketCrypto Market: Global market cap, BTC dominance, 24h volume (CoinGecko)
cryptopriceCrypto Price: Live coin price + 24h change (CoinGecko)
csp_parseCSP Analyzer: Content-Security-Policy header analysis & grade
ctlogsearchCT Logs (Org): crt.sh cert search by organization name
cveCVE Lookup: CVE detail + CVSS (CIRCL, no key)
cvedetailCVE Detail: Full CVE record (CVSS, refs) via CIRCL
cve_poc_checkerCVE POC Check: Check if a CVE has public POC/exploit code
cve_severityCVE Severity: CVSS + EPSS + KEV for a CVE
cve_timelineCVE Timeline: When a CVE was discussed (Twitter/Reddit/News)
darkweb_monitorDarkweb Monitor: Darkweb monitoring: marketplaces, paste sites
dataciteDataCite Search: Research datasets/DOIs by keyword
datauriData URI Parse: Parse or create data: URIs
dblpDBLP: DBLP CS publication search
ddg_instantDDG Instant: DuckDuckGo instant answer + related topics
decodeDecoder: Auto base64/hex/URL-decode + refang
dehashed_domainDeHashed Domain: DeHashed public page scrape for domain breach exposure
depsdevdeps.dev: Open-source insights: versions, default
deviantartDeviantArt Meta: Deviation title + author (oEmbed)
devtodev.to: Forem/dev.to public profile
dirlistingDirectory Listing: Open directory-index exposure (per-target)
disastersDisasters (GDACS): Active worldwide disasters: quakes/cyclones/floods (feeds globe)
disposableDisposable Email: Is the email domain a disposable provider?
disposablecheckDisposable Email: Check if email is temporary/disposable
dnsDNS Records: A/AAAA/MX/NS/TXT/CNAME/SOA/CAA records
dnsblDNS Blocklist: Spamhaus/Barracuda/SORBS/SpamCop check
dnsgraphDNS Graph (HE): Hurricane Electric DNS delegation info
dnsmxMX (DoH): MX records via Google DNS-over-HTTPS
dnspropDNS Propagation: Compare A records across Google/Cloudflare/Quad9
dnsptrrangePTR Range Sweep: Reverse-DNS every host in a /24 (offline)
dnsqueryDNS A Record: DNS A record lookup via Google DoH
dnsreconDNS Recon: Query ALL DNS record types at once
dnssecDNSSEC: Is the zone signed (AD flag + DNSKEY/DS)
dnsverifyTXT Verifications: Which SaaS a domain is enrolled in (TXT tokens)
dockerhubDocker Hub Repo: Docker Hub repo pulls, stars, last update (no key)
dogeaddrDOGE Address: Dogecoin address balance & tx count
dohDoH Records: Uncommon DNS records (HTTPS/SVCB/TLSA/SRV/NAPTR…)
doiDOI Resolver: Crossref publication metadata for a DOI
domainageDomain Age: Days since registration (phishing signal)
dorksSearch Dorks: Builds manual OSINT search links
eanBarcode/EAN: EAN/UPC check digit + GS1 country prefix (offline)
elevationElevation: Ground elevation in metres (Open-Meteo)
emailEmail Intel: Gravatar, MX, disposable detection
email_crosssiteEmail Identity: Gravatar graph, disposable check, breach/paste surfaces (mosint)
email_domain_crossDomain Emails: Subdomain surface + org email-pattern dorks for a domain
emailformatEmail Validator: Basic RFC 5322 email format validation
email_registrationEmail Cross-Site: Which 120+ sites have an account on this email (holehe)
emailrepEmail Reputation: emailrep.io: malicious/spam/breach flags for email (no key, limited)
emailsecEmail Security: SPF / DMARC / DKIM posture
emerging_threatsEmerging Threats: Emerging threats: new CVEs + 0days (24h)
emojiEmoji Lookup: Emoji ↔ Unicode name/codepoint (offline)
ensENS Resolve: ENS name <-> ETH address + avatar
entropyShannon Entropy: Per-char entropy — flags secrets/keys
epochEpoch Time: Unix timestamp <-> UTC datetime
epssEPSS Score: Exploitation probability (FIRST EPSS)
ethaddrETH Address: Ethereum balance/tx + contract flag
ethcontractETH Contract: Contract check + Sourcify verified source
exploit_cveCVE Exploits: Exploit-DB + GitHub POCs for a CVE
faviconFavicon Hash: favicon md5/sha256 for pivoting
fbsearchFB Search URLs (graph replacement): name [| keyword] -> ready facebook search URLs: people/posts/all/keyword-filtered
fccidFCC ID: FCC equipment authorization database
feedsRSS / Atom Feeds: Discover syndication feeds on a site
feodoFeodo C2: abuse.ch botnet C2 blocklist (key-free)
feodoipsFeodo C2 List: Is IP on abuse.ch Feodo botnet C2 list
flightsnearFlights Nearby: Live aircraft within ~1° of coords (OpenSky)
formauditForm Audit: Enumerate forms/inputs (login/upload) — attack surface
fxrateFX Rates: Live exchange rates for a currency code
gdeltGDELT News: Global news/events by keyword (last 24h)
genderizeGender Predictor: Predict gender from a first name (genderize.io)
geocodeGeocode: Place name → coordinates (OSM Nominatim)
geodistGeo Distance: Great-circle distance between two coord pairs (offline)
geohashGeohash: lat,lon -> geohash (offline)
ghadvisoryGitHub Advisories: Security advisories for an ecosystem (pip/npm/…)
ghcommitsGitHub Commits: Recent commits for owner/repo
gh_dorkingGitHub Dork Search: GitHub code search for target string exposure in public repos
gheventsGitHub Activity: Recent public GitHub events for a user (60/hr)
ghgistsGitHub Gists: Public gists for a user
ghkeysgpgGitHub GPG Key: Whether a user publishes a GPG key
ghlanguagesRepo Languages: Language byte-breakdown for owner/repo
ghorgGitHub Org: Public org profile
ghpubkeysGitHub SSH Keys: A user's public SSH keys (.keys)
ghrepoGitHub Repo: Stars/langs/license/activity (owner/repo)
gh_secret_scanGitHub Secret Scan: Scan GitHub user's public repos for leaked secrets/passwords
gitexposedExposed Files: .git/.env/backup exposure (per-target)
githubGitHub Recon: Profile, repos, languages
github_codeGitHub Code Search: GitHub unauthenticated code search (10 results)
githubgistsGitHub Gists: A user's public gists
githubsearchGitHub Repo Search: Search GitHub repos by keyword
github_trendingGitHub Trending: Trending repos (optional language filter)
gitignoregitignore Template: GitHub .gitignore template for a language
gitlabGitLab: Public user profile
gleif_nameGLEIF Name: GLEIF fuzzy legal-entity name → LEI codes
golangpkgGo Module: Latest version of a Go module
gomodGo Module: Go module latest version (module proxy)
goproxyGo Module: Latest version of a Go module via module proxy (no key)
gps_deepGPS Full Context: Coords/place -> address, sun times, nearby POIs, map links
graphqlGraphQL Probe: Find GraphQL endpoint + introspection (per-target)
gravatarfullGravatar Profile: Full public Gravatar profile + linked accounts
greynoiseGreyNoise: Is the IP a known internet scanner — benign/malicious
hackernewsHacker News: Profile: karma, age, activity
hackernews_frontHN Front Page: Current Hacker News front-page stories
hashidHash Identifier: Guess hash algorithm from length/charset
hashnodeHashnode: Blogger profile: followers, posts
hashtextHash Text: md5/sha1/sha256/sha512 of text (offline)
headersHTTP / Security: Headers + security-header scorecard
hexdumpHexdump: Offset/hex/ASCII hexdump of input (offline)
hexpmHex.pm: Elixir/Erlang package downloads
hibpHIBP Password Check: Check if a password appeared in breaches via HIBP k-anonymity (no key)
hibp_breachesHIBP Breaches: Check breach database for email/username exposure
hibp_emailHIBP Email Breaches: Email breach exposure via XposedOrNot (HIBP-compatible, no key)
hnsearchHN Search: Search Hacker News stories/comments
hnuserHacker News User: HN profile: karma, created, submission count
holidaysPublic Holidays: Country public holidays this year (nager.at)
homoglyphHomoglyph: Detect confusable/mixed-script spoofing chars (offline)
hosthuntHost Search: Forward-DNS host/subdomain map (HackerTarget)
hostnameReverse DNS: IP → hostname via reverse DNS
hostsearchHost Search: Forward-DNS host enumeration for a domain
hstspreloadHSTS Preload: Is the domain on the browser HSTS preload list
htmlcommentsHTML Comments: Extract HTML comments — leaked TODOs/paths/software
htmlencodeHTML Encode/Decode: HTML entity encode/decode
httpcodeHTTP Status Code: HTTP status code meaning & family (offline)
httpingHTTP Ping: Reachability + response timing
httpmethodsHTTP Methods: Allowed methods + TRACE/risky-verb check
httpstatusHTTP Status: Explain an HTTP status code (offline)
hudsonrockHudsonRock Stealer: Stealer-log exposure check via HudsonRock Cavalier free API
huggingfaceHuggingFace: HuggingFace user profile or model card
human_sweepHuman Sweep: Auto-detect target type, run all matching human tools, merge entities
hunter_countHunter: Email Count: How many emails findable for a domain (free)
hunter_domainHunter: Domain Emails: All findable emails for a domain + names/positions/confidence
hunter_findHunter: Find Email: name + domain -> most likely email (usage: first last domain)
hunter_verifyHunter: Verify Email: Deliverability verdict: valid/invalid/accept_all + score
ibanIBAN Validate: ISO 13616 checksum + country/length (offline)
imagechunksPNG Chunks: Hidden tEXt/zTXt/iTXt chunks in PNG (steganography)
imagecolorsImage Palette: Dominant color palette extraction
imageexifImage EXIF: Full EXIF: camera, lens, timestamps, software
imagegpsImage GPS: GPS coordinates from EXIF → map links (feeds globe)
imagehashImage Hash: Perceptual aHash + sha256/md5 for dupe matching
imageiccICC Profile: Color profile name — fingerprints editing software
imagelsbLSB Steg Detect: Statistical LSB analysis — detects possible hidden payload
imagemetaImage Metadata: Dimensions, format, mode, size, megapixels
imagephashImage pHash/dHash: dHash + pHash for robust near-duplicate detection
imagerevReverse Image: Google Lens / Yandex / Bing / TinEye search links
imagethumbEXIF Thumbnail: Extract embedded thumbnail — often retains GPS after stripping
imagexmpXMP Metadata: XMP block: creator tool, edit history, software version
imeiIMEI Check: Validate IMEI (Luhn) + split TAC/serial (offline)
infra_fingerprintInfra Fingerprint: Infrastructure fingerprinting + hosting
intelx_emailXposedOrNot Breach: Email breach exposure — breach names, data types, paste hits (XposedOrNot, no key)
internetdbShodan InternetDB: Open ports, CPEs, tags, known CVEs for a host
ioc_reputationIOC Reputation: Cross-check IP/domain/hash across feeds
ip_deepIP Deep Intel: Geo + ASN + VPN/proxy/Tor risk + open ports/vulns + reverse DNS
ipfullIP Full Profile: Rich geo+ASN+proxy/mobile/hosting flags
ipgeoIP Geolocation: Geo, ISP, ASN, proxy/hosting flags
ipintIP ↔ Integer: IPv4 ↔ integer ↔ hex (offline)
ip_mathIP Math: CIDR: network/broadcast/range/host count (offline)
ipv4classifyIP Classify: Classify IP: private/loopback/multicast/global (offline)
ipv6IPv6 Validator: IPv6 parser, expander, classifier
ipwhoisIP WHOIS / RDAP: Network owner, range, abuse contact
isbnISBN Book: Book metadata (OpenLibrary) + checksum
isbnmetaISBN Metadata: Book title/authors/subjects (OpenLibrary)
isexitnodeTor Exit Check: Is this a Tor exit node?
isinISIN Validate: Validate ISIN security identifier check digit (offline)
isotimeTimestamp Convert: Parse/convert a timestamp (offline)
issISS Position: Live International Space Station lat/lon
jarmJARM / InternetDB: Shodan InternetDB: ports, CPEs, vulns, tags (no key)
jslibsJS Libraries: Enumerate <script> sources + detect JS libs/versions
jsonfmtJSON Format: Validate, pretty-print & stat JSON (offline)
jwtJWT Decoder: Header + claims (no signature verify)
jwtdecodeJWT Decode: Decode JWT header+payload (offline, unverified)
kevCISA KEV: Is the CVE actively exploited (KEV catalog)
keybaseKeybase: Crypto identity + linked social proofs
latlonformatLat/Lon Format: DD ↔ DMS ↔ DM coordinate format conversion (offline)
leakcheckLeakCheck: Breach exposure via leakcheck.io public endpoint (no key)
leaklookupHudson Rock Stealers: Infostealer compromise check — stealer logs, credential count (Hudson Rock, no key)
leetLeetspeak: Leetspeak transform (offline)
leetcode_userLeetCode: LeetCode solved problems, ranking, badges
leiLEI Lookup: GLEIF legal-entity record by LEI code
linksLink Extractor: All links + external domains + emails on a page
linktreeLinktree: Extract destination links from a linktr.ee profile
lobstersLobste.rs: Public user profile + karma
ltcaddrLTC Address: Litecoin address balance & tx count
luhnLuhn Check: Validate card/IMEI Luhn checksum (offline)
macMAC Vendor: OUI → hardware vendor
macvalidMAC Validator: MAC address parser (colon/dash/plain)
macvendorMAC Vendor (OUI): MAC vendor + local/multicast bits from local OUI table (offline)
macvendorlookupMAC Vendor: OUI → hardware vendor (macvendors.com)
maidenheadMaidenhead Grid: Coords → ham-radio grid locator (offline)
malware_familyMalware Family: Variants, IOCs, AV detections
manifestPWA Manifest: Web app manifest: name, icons, theme
marineweatherMarine Weather: Wave height/period/direction + sea temp at coords
mastodonMastodon: Resolve user@instance via WebFinger
mavenMaven Central: Java artifact: 'group:artifact' or name
mediumMedium: Author feed: recent post titles
metatagsMeta Tags: OpenGraph / Twitter-card / generator meta tags
mgrsMGRS Grid: Lat/lon → MGRS military grid reference (offline)
mimetypeMIME Type: File extension → MIME type (offline)
mitre_techniqueMITRE Technique: ATT&CK technique → tactics + detection
moonphaseMoon Phase: Current moon phase & illumination (offline)
morseMorse Code: Morse encode/decode, autodetecting direction (offline)
mtastsMTA-STS: Inbound-mail TLS enforcement policy
musicbrainzMusicBrainz: Artist search: type, country, MBID
musicbrainzartistMusicBrainz Artist: Artist type, country, lifespan
nationalizeNationality: Predict nationality from a name (nationalize.io)
natoNATO Phonetic: Spell text in NATO phonetic alphabet (offline)
nearbywikiNearby Places: Wikipedia places near a coordinate
npmnpm Author: Packages published by an author
npmdlnpm Downloads: npm download counts day/week/month
npmdownloadsnpm Downloads: npm package download counts, last week + month (no key)
npmorgnpm Org: npm organization: all published packages
npmpkgnpm Package: npm package version, deps, maintainers
nstraceNS Delegation: Trace NS delegation: TLD → registrar → authoritative
nugetNuGet: .NET package stats + downloads
numlookupNumber Lookup: Validity, region, carrier, line type, timezones (libphonenumber)
numwordsNumber to Words: Integer → English words (offline)
nvdcveNVD CVE Detail: Full NVD record: CVSS, CWE, references
onthisdayOn This Day: Historical events on a date (Wikipedia; MM/DD or today)
openalexauthorOpenAlex Author: Author works count, h-index, institution
openalexworkOpenAlex Work: Scholarly work: citations, concepts, OA
opencorpOpenCorporates: Company registrations worldwide search
openfoodfactsProduct Barcode: EAN/UPC -> product, brand, nutrition
openphishOpenPhish: Community phishing-URL feed membership
orcidORCID: Researcher record (0000-000X-…)
orcidworksORCID Works: Recent publications for an ORCID iD
orgnameCompany → LEI: Fuzzy company-name search → candidate LEIs
osmuserOpenStreetMap User: Contributor: last edit + changeset
osvOSV Vulns: Known package vulns (OSV.dev). 'eco:name'
otxdomainOTX Domain Rep: AlienVault OTX threat pulses for a domain
otxipOTX IP Rep: AlienVault OTX threat pulses for an IP
packagistPackagist: PHP/Composer package stats (vendor/pkg)
pageinfoCommon Crawl Page: Common Crawl capture index lookup
passentropyPassword Entropy: Estimate entropy & offline crack time (offline)
passgenPassword Gen: Generate strong random passwords + passphrase (offline)
passwordcheckPassword Pwned: HIBP k-anonymity breach check (safe)
password_dumpsPassword Dump Search: Search Dehashed for leaked passwords (query-only)
paste_domainPaste Domain Search: Find domain in public pastes via psbdmp.ws (no key)
paste_emailPaste Email Search: Find email in public pastes via Wayback CDX + search links (no key)
peeringdbPeeringDB: Network type, traffic, IX/facility presence
peeringnetPeeringDB Net: Peering policy / traffic / IX presence for ASN
peersASN Peers: Upstream/downstream BGP neighbours
permissions_polPermissions Policy: Permissions-Policy: camera/mic/geo controls
person_identityPerson Identity: Name -> gender/age/nationality probs + Wikipedia/Wikidata + dorks
person_sweepPerson-focused sweep: checks ~30 username/email/social presence tools for one name/handle and returns where it exists plus extracted entities.
pgpPGP Key: Public key published on keys.openpgp.org
phishing_intelPhishing Intel: Phishing kit tracking + URL detection
phonePhone Number: E.164 country/region (offline)
phoneappsMessaging Links: WhatsApp / Telegram / Viber / Signal deep links
phoneccCalling Code: Country, trunk & intl dialing prefixes (offline)
phone_deepPhone Deep-Dive: Validity, carrier, region + WhatsApp/Telegram/Signal pivots, caller-ID surfaces
phonefmtPhone Format: E.164 / national / international / RFC3966 formats (offline)
phone_leakPhone Leak Check: Phone in breaches/pastes via LeakCheck + dork pack
phonenanpNANP Area Code: +1 number → US/Canada region (offline subset)
phonepivotPhone Lookups: Caller-ID / reputation site links (Truecaller, Sync.me…)
phonespamSpam Reports: Robocall / scam report-database links
phonevcardvCard: Generate a .vcf contact card (offline)
pluscodePlus Code: Coords → Open Location Code / Google Plus Code (offline)
portPort Reference: Service + exposure notes for a port number
portlookupPort Lookup: IANA port → service name (offline)
portquickPort Check: Quick TCP port scan (2s timeout)
portscanPort Scan: TCP connect scan: common + camera ports
pubmedPubMed: PubMed biomedical paper search (NCBI)
punycodePunycode/IDN: IDN domain ↔ Punycode (xn--) homograph check (offline)
pwstrengthPassword Strength: Offline entropy/strength estimate
pypiPyPI Package: Python package metadata + links
pypiprojectPyPI Project: PyPI version/license/links
pypistatsPyPI Downloads: PyPI recent download counts
qrcodeQR Code: Generate a QR code for text/URL
quakesEarthquakes: USGS recent quakes — global or near coords (M2.5+)
quoted_printableQuoted-Printable: Quoted-printable encode/decode
railfenceRail Fence: Rail-fence cipher over 3 rails (offline)
random_factRandom Fact: Random trivia fact
randomuserRandom Identity: Synthetic identity for sockpuppet hygiene (randomuser.me)
ransomware_trackerRansomware Groups: Ransomware gang profiles + recent hits
rdapRDAP Registration: Structured domain registration record (RDAP/IANA bootstrap, no key)
rdap_domainRDAP Domain: RDAP structured domain registration data
rdapipRDAP IP: Authoritative RDAP record for an IP
reddit_subReddit Subreddit: Subreddit: subscribers, active users, description
reddit_userReddit User: Reddit user: karma, age, verified status
redirectsRedirect Tracer: Full HTTP redirect chain
referrer_polReferrer Policy: Referrer-Policy header — URL leakage risk
regdomainRegistered Domain: Extract eTLD+1 registered domain from URL (offline)
restcountryCountry Detail: Capital/region/income by name or ISO (World Bank)
reversednsReverse DNS: PTR record / hostname
reverseipReverse IP: Other domains sharing the host
revgeoReverse Geocode: lat,lon -> address (OSM Nominatim)
revgeocodeReverse Geocode: Coordinates → nearest address (OSM)
revimgReverse Image: Reverse-image-search links (Lens/Yandex/TinEye/Bing)
ripewhoisRIPE Network Info: Covering prefix + origin ASN (RIPEstat)
robotsrobots.txt: Disallowed paths + sitemaps
robotsmetaRobots Meta: meta-robots + X-Robots-Tag: noindex/nofollow/noarchive
robotstxt_historyrobots.txt History: Historical robots.txt snapshots from Wayback Machine
romanRoman Numerals: Convert int <-> roman numeral, autodetecting (offline)
rot13ROT-13 Cipher: ROT-13 encode/decode
rot47ROT47: ROT47 ASCII cipher (offline, self-inverse)
rpkiRPKI / ROA: Route-origin validation for the covering prefix
rubygemrevGem Rev-Deps: Reverse dependencies of a RubyGem
rubygemsRubyGems: Ruby gem stats + downloads
s3bucketsCloud Buckets: S3/GCS/Azure buckets named for the domain
sec_edgarSEC EDGAR: Company name + recent SEC filings by ticker/CIK
securitytxtsecurity.txt: RFC 9116 disclosure policy & contacts
semanticscholarSemantic Scholar: Paper TLDR, citations, influence
semverSemantic Version: Parse and validate semantic versioning
sha256lookupSHA-256 Reverse: Crack SHA-256 via online DB
sitemapSitemap: Fetch sitemap.xml + list URLs
slugSlugify: Text → URL-safe slug (offline)
smtpbannerSMTP Banner: SMTP banner & EHLO capabilities (ports 25/587/465)
snowflakeSnowflake ID: Decode Twitter/Discord snowflake → timestamp (offline)
snusbase_hashHash Reverse (Leaks): Reverse MD5/SHA1 hash via breach-sourced hash DB (md5decrypt.net)
socialSocial Links: Direct profile URLs across 20 platforms
social_deepSOCIAL DEEP: All-Platform Link Set: 'name | username | phone | email' (pipe-separated, use what you have) -> ready URL sets for FB/IG/TikTok/X/LinkedIn/Reddit/Discord/Snap/Bluesky/WhatsApp/biolinks
soladdrSOL Account: Solana account balance & owner program
sopostuserStackOverflow User: SO profile + reputation by numeric id
soundcloudSoundCloud Meta: Track/user title + author (oEmbed)
spacepeoplePeople in Space: Who is in space right now (names + craft)
spaceweatherSpace Weather: Planetary Kp index + geomagnetic storm/aurora (NOAA)
spamhauslookupSpamhaus IP Check: Spam/phishing IP blacklist check
spdxlicenseSPDX License: SPDX license id → name + OSI status
sri_checkSRI Check: Subresource Integrity: external scripts without integrity=
srvlookupSRV Records: SIP/XMPP/mail/CalDAV SRV record discovery
sshSSH Banner: Per-target SSH server banner / version
ssn_checkSSN/Identity Leak: Check if SSN/DOB appears in identity theft databases
stackoverflowStack Overflow: SO/SE user search by display name
steam_userSteam Profile: Steam community profile via public XML
stringmetricsString Metrics: Length, entropy, character breakdown
subbruteSubdomain Brute: Resolve a common-subdomain wordlist (per-target)
subdomainsSubdomains: Certificate-transparency subdomain discovery
suntimesSun Times: Sunrise/sunset/twilight for a coordinate (UTC)
supply_chain_riskSupply Chain Risk: Dependency vulns + typosquatting
swaggerSwagger / OpenAPI: Exposed API docs at common paths (per-target)
swiftbicSWIFT/BIC: Parse SWIFT/BIC: bank/country/branch (offline)
takeoverSubdomain Takeover: Dangling-CNAME takeover fingerprint check
teamcymruTeam Cymru ASN: IP → ASN via Team Cymru DNS (fastest ASN lookup)
techTech Fingerprint: CMS/framework/server detection
telegram_channelTelegram Channel: Public channel preview: subscribers, description
tempconvTemperature: Convert °C / °F / K (offline)
tempmailTemp Email: Generate/read a disposable email inbox (1secmail)
threat_actorThreat Actor: Known campaigns, techniques, tools
threatcrowdPassive DNS: OTX passive DNS resolution history
threat_patternThreat Pattern: Find threat patterns across incidents
tiktokTikTok Profile: TikTok user stats (best-effort, keyless)
timezone_infoTimezone Info: Timezone UTC offset & current time (offline, IANA names)
tldinfoTLD Info: TLD registry operator, type, purpose (offline)
tlsTLS Certificate: Live cert: issuer, validity, SANs, cipher
tlsaDANE / TLSA: Certificate-pinning DANE records on :443
tlsscanTLS Versions: Which SSL/TLS protocols the host accepts
torTor Exit Check: Is the IP a known Tor exit node
transformText Transforms: rot13/base32/morse/reverse (offline)
trendingwikiTrending Wikipedia: Most-read Wikipedia articles today
trufflehog_urlSecret Pattern Scan: Scan raw URL content for API keys, tokens, private keys, JWTs
txhashCrypto Tx: BTC/ETH transaction detail (blockchair)
typosquatTyposquat Finder: Look-alike domains that currently resolve
ulidULID Decode: Decode a ULID's embedded timestamp (offline)
unicode_lookupUnicode Lookup: Unicode codepoint: name, category, HTML entity (offline)
unixpermUnix Permissions: Octal permission (755/644) → rwx breakdown (offline)
unpaywallUnpaywall: Is a DOI open-access? Direct PDF link
urbanUrban Dictionary: Slang/term definitions + examples
urlparseURL Parse: Parse URL into components + query params
urlscanurlscan.io: Past scans, verdicts, infra (IP/ASN/server) for a site
urlscansearchurlscan Archive: Public urlscan.io scan history for a domain
useragentUA Parser: Parse a User-Agent into OS/browser (offline)
usernameUsername Hunter: Presence across 16 public sites
username_dossierUsername Dossier: 250-site profile dossier via Maigret with extracted names/emails/phones
utmUTM Coords: Lat/lon → UTM coordinates (WGS84, offline)
uuencodeUUencode: Unix-to-Unix encoding
uuidUUID Parser: Version/variant + v1 timestamp/MAC (offline)
uuid_validateUUID Validator: UUID v1-v5 version and variant detector
vatidEU VAT: Validate EU VAT number country format (offline)
vigenereVigenere Cipher: Vigenere encrypt/decrypt: 'KEY:text[:d]' (offline)
vimeoVimeo Meta: Video title, author, thumbnail (oEmbed)
vinVIN Decoder: NHTSA vPIC vehicle decode (make/model/plant)
vuln_feedVuln Feed: Real-time vuln feeds (NVD, Exploit-DB, PacketStorm)
wafWAF / CDN: Detect WAF/CDN from headers & cookies
waybackWayback Machine: Archive.org snapshot history
wayback_leaksWayback Leak Scan: Search Wayback Machine for historically exposed .env/config/secrets
weatherWeather: Current weather at a coordinate (Open-Meteo)
weatheralertsWeather Alerts: Active US NWS weather alerts near coords
webfingerWebFinger: WebFinger resource discovery (ActivityPub/OIDC)
wellknown.well-known Scan: Which /.well-known/* resources exist
whatsnearbyNearby POIs: OSM amenities within 500m of coords (Overpass)
whoisWHOIS / RDAP: Registration, status, nameservers, DNSSEC
whois_checkWHOIS Check: Domain WHOIS record existence via who.is
whoisserverWHOIS Server: TLD → WHOIS server mapping (offline + IANA fallback)
wikidataWikidata Search: Search Wikidata entities by label (no key)
wikidatasearchWikidata Search: Free-text → Wikidata entities
wikipediaWikipedia Summary: Wikipedia REST summary: extract, type, coords (no key)
wikipvWikipedia Meta: Page length, last edit, editor
wikisummaryWikipedia Summary: Page extract/description for a topic
wordcountWord Count: Text stats: words/chars/lines/reading time (offline)
workupWORKUP: Full Person Dossier: first+last -> username variants x 16 platforms, name stats, dork surfaces, wiki (30-60s)
wppluginWP Plugin Info: WordPress.org plugin version/install stats
wpscanWordPress Scan: WP version + author enum via REST (per-target)
xrpaddrXRP Account: XRP Ledger account balance & sequence
youtubeYouTube Meta: Video/channel title, author, thumbnail (oEmbed)
zenodoZenodo: Zenodo open-research records search
zerodday_timelineZero-Day Timeline: 0day mentions across researchers + CVE
zonetransferZone Transfer: AXFR attempt — is zone transfer misconfigured?

Schemas: list_tools.

Official server.json
{
  "name": "com.thetempleofdoom.osint-mcp/osint-terminal",
  "$schema": "https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json",
  "remotes": [
    {
      "url": "https://osint-mcp.thetempleofdoom.com/mcp",
      "type": "streamable-http"
    }
  ],
  "version": "1.1.0",
  "description": "454 OSINT recon tools + server-side entity correlation & person sweeps. Keyless."
}