# com.thetempleofdoom.osint-mcp/osint-terminal

> 454 OSINT recon tools + server-side entity correlation & person sweeps. Keyless.

- name: com.thetempleofdoom.osint-mcp/osint-terminal
- version: 1.1.0
- connection class: R0 (autonomous)
- trust: 79/100 flags: no-repository
- quality: 64/100 (needs work)
- owner: not claimed
- descriptor: https://api.protogrid.dev/v1/servers/com.thetempleofdoom.osint-mcp%2Fosint-terminal
- tools: https://api.protogrid.dev/v1/servers/com.thetempleofdoom.osint-mcp%2Fosint-terminal/tools

**An agent can connect right now, no human step.** Remote endpoint, no authentication, reachable on the last probe.

## Connection (mcpServers)

```json
{
  "mcpServers": {
    "osint-terminal": {
      "type": "http",
      "url": "https://osint-mcp.thetempleofdoom.com/mcp"
    }
  }
}
```


## Trust

- hygiene: 80
- liveness: 97
- freshness: 100
- provenance: 45
- drivers: +dns-namespace +reachable +uptime-93% +updated-16d-ago -no-repository
- Derived from observable signals (official registry feed and our own credential-free probes); no code audit performed.

## Quality 64/100 (needs work)

### protocol: 88 (weight 25)

- pass `protocol.modern`: supports 2026-07-28 (server/discover)
- pass `protocol.stateless`: answers without a session
- pass `protocol.transport`: streamable HTTP
- warn `protocol.list_ttl`: tools/list declares ttlMs 0, so clients re-fetch it on every use

### authorization: n/a (weight 15)

- n/a `auth.prm`, `auth.as_metadata`, `auth.cimd`: no remote uses OAuth
- n/a `auth.secret_in_url`: no templated URL

### tool hygiene: 64 (weight 30)

- pass `tools.descriptions`: every tool has a description
- pass `tools.description_length`: descriptions are concise
- pass `tools.schemas`: every tool has an object input schema
- fail `tools.annotations`: no tool declares readOnlyHint or destructiveHint, so clients cannot tell safe calls from risky ones
- fail `tools.directory_hints`: no tool declares all four of readOnlyHint, destructiveHint, idempotentHint and openWorldHint; missing: headers (readOnlyHint, destructiveHint, idempotentHint, openWorldHint); asn (readOnlyHint, destructiveHint, idempotentHint, openWorldHint); reverseip (readOnlyHint, destructiveHint, idempotentHint, openWorldHint); …
- warn `tools.token_cost`: about 19,661 tokens to load every tool
- pass `tools.api_dump`: tools are not a one-to-one API dump

### stability: 25 (weight 15)

- warn `stability.changes`: 21 tool changes in 30 days
- fail `stability.rug_pull`: 1 tools kept their name but changed most of their description in 30 days; review before trusting them

### dependencies: n/a (weight 15)

- n/a `deps.known_vulns`, `deps.mcp_sdk_version`, `deps.resolvable`: no npm or PyPI package

- tools: 474, about 19,661 tokens to load them all
- tool set hash: 452e1a9bb5005e5b4b6ef92e1d67d9c3
- tools last changed: 2026-10-09T12:00:24.316Z
- badge: [![protogrid quality](https://protogrid.dev/badge/com.thetempleofdoom.osint-mcp/osint-terminal.svg)](https://protogrid.dev/servers/com.thetempleofdoom.osint-mcp/osint-terminal)
- Checks run on what our credential-free, read-only probes observe; tools are never called and no code audit is performed.

### Tool changes

- 2026-10-09 `social_deep` added
  - SOCIAL DEEP: All-Platform Link Set: 'name | username | phone | email' (pipe-separated, use what you have) -> ready URL sets for FB/IG/TikTok/X/LinkedIn/Reddit/Discord/Snap/Bluesky/WhatsApp/biolinks
- 2026-10-09 `workup` added
  - WORKUP: Full Person Dossier: first+last -> username variants x 16 platforms, name stats, dork surfaces, wiki (30-60s)
- 2026-10-09 `fbsearch` added
  - FB Search URLs (graph replacement): name [| keyword] -> ready facebook search URLs: people/posts/all/keyword-filtered
- 2026-10-08 `hunter_count` added
  - Hunter: Email Count: How many emails findable for a domain (free)
- 2026-10-08 `hunter_verify` added
  - Hunter: Verify Email: Deliverability verdict: valid/invalid/accept_all + score
- 2026-10-08 `hunter_find` added
  - Hunter: Find Email: name + domain -> most likely email (usage: first last domain)
- 2026-10-08 `hunter_domain` added
  - Hunter: Domain Emails: All findable emails for a domain + names/positions/confidence
- 2026-10-07 `human_sweep` added
  - Human Sweep: Auto-detect target type, run all matching human tools, merge entities
- 2026-10-07 `bssid_geo` added
  - WiFi BSSID Geo: BSSID/cell -> approximate location (Mylnikov free DB)
- 2026-10-07 `gps_deep` added
  - GPS Full Context: Coords/place -> address, sun times, nearby POIs, map links

Full history: https://api.protogrid.dev/v1/servers/com.thetempleofdoom.osint-mcp%2Fosint-terminal/changes

## Remotes

- https://osint-mcp.thetempleofdoom.com/mcp (streamable-http, auth none, reachable true, uptime30d 0.9298246)

## Packages

_none_

## Tools (474)

- `abusecontact`: Abuse Contact: Authoritative abuse email (RIPEstat finder)
- `adstxt`: ads.txt: Ad-tech sellers declared in ads.txt
- `agent_manifest`: Self-describing manifest of all OSINT Terminal agent endpoints.
- `agify`: Age Predictor: Predict age from a first name (agify.io)
- `airquality`: Air Quality: PM2.5/PM10/European AQI at coords (Open-Meteo, no key)
- `antipode`: Antipode: Opposite point on Earth for coords (offline)
- `api_key_scan`: API Key Exposure: Scan GitHub/Pastebin/Google for exposed API keys/secrets
- `apileak`: API Leak Search: GitHub dork links for API key/secret exposure
- `apod`: NASA APOD: Astronomy Picture of the Day (optional date)
- `apt_track`: APT Track: Track APT campaigns via MITRE + researchers
- `archiveorg`: Archive.org Item: Internet Archive item metadata
- `arxiv`: arXiv Search: arXiv paper search by title/author/keyword
- `ascii85`: Ascii85: Ascii85 encode/decode (offline)
- `asn`: ASN / BGP: ASN details or prefixes for an IP
- `asnlookup`: ASN Lookup: ASN org/country/prefixes via RIPEstat
- `asnprefixes`: ASN Prefixes: All announced prefixes for an ASN (RIPEstat)
- `asrank`: AS Rank (CAIDA): Global ASN ranking + customer cone size
- `atbash`: Atbash Cipher: Atbash A↔Z mirror cipher (offline, self-inverse)
- `attack_surface`: Attack Surface: Map attack surface: services + endpoints + API
- `barcode`: Barcode Validate: EAN-13 / UPC-A check digit validation (offline)
- `base32`: Base32 Encode/Decode: RFC 4648 Base32 encode or decode
- `base36`: Base36 Codec: Encode int <-> base36, autodetecting direction (offline)
- `base58`: Base58 Codec: Bitcoin base58 encode/decode: 'hex:..' / 'b58:..' (offline)
- `base64`: Base64: Auto decode/encode base64 (offline)
- `base_convert`: Base Convert: Binary/octal/decimal/hex number conversion (offline)
- `bearing`: Bearing: Initial compass bearing between two coord pairs (offline)
- `bgphistory`: BGP History: Routing origin history (RIPE Stat)
- `bimi`: BIMI: Brand-indicator (logo) DNS record
- `bin`: Card BIN: Issuer/scheme/country from card BIN (binlist)
- `binarytext`: Binary Text: Text ↔ 8-bit binary (offline)
- `binlookup`: BIN Lookup: Card BIN → bank, brand, country, type
- `blockheight`: Block Height: Current Bitcoin + Ethereum block height
- `bluesky`: Bluesky: AT Protocol public profile
- `botnet_tracker`: Botnet Tracker: Botnet C2 + IoT malware tracking
- `breach_aggregator`: Breach Aggregator: Aggregate breach databases (XposedOrNot, LeakCheck, etc)
- `breachdb`: BreachDB Search: Aggregated breach collection search
- `breachdirectory`: Breach Directory: ProxyNova COMB dataset search for credential exposure
- `breachsearch`: Breach Catalog: Public HIBP breach metadata search
- `brew`: Homebrew: Formula/cask version, deps, installs
- `bssid_geo`: WiFi BSSID Geo: BSSID/cell -> approximate location (Mylnikov free DB)
- `btcaddr`: BTC Address: Bitcoin balance/tx via mempool.space
- `btcfees`: BTC Fees: Recommended Bitcoin fees sat/vB (mempool.space)
- `c2_infrastructure`: C2 Infrastructure: Detect C2 infrastructure + hosting
- `caa`: CAA Records: Which CAs may issue certs for the domain
- `caesar`: Caesar Cipher: ROT-N / Caesar brute force, all 25 shifts (offline)
- `camera`: Camera Exposure: RTSP/ONVIF + camera-port exposure (per-target)
- `casify`: Case Convert: snake/camel/Pascal/kebab/CONSTANT case (offline)
- `cdnjs`: cdnjs: Hosted JS library version + assets
- `cdxwayback`: Wayback CDX: Snapshot count + first/latest capture in Wayback Machine
- `certhistory`: Cert History: crt.sh issuer timeline & counts
- `cfradar`: Cloudflare Radar: Domain rank + categories from Cloudflare Radar
- `checksum`: CRC32/Adler32: CRC32 + Adler32 checksum of input text (offline)
- `chesscom`: Chess.com: Public player profile + ratings
- `cidr`: CIDR Calculator: Subnet calc: network, mask, host range, count (offline)
- `cidrinfo`: CIDR Calculator: Network/broadcast/host-count (offline)
- `circlhash`: Hash Lookup: Known-file lookup (CIRCL hashlookup)
- `cisa_alerts`: CISA Alerts: CISA alerts + advisories (recent threats)
- `clickjacking`: Clickjacking: X-Frame-Options + CSP frame-ancestors check
- `cloud`: Cloud Provider: AWS/GCP/Azure/etc. detection + hosting flag
- `codeberg`: Codeberg: Codeberg/Gitea public user
- `codeforces`: Codeforces: Codeforces competitive programmer rating & rank
- `coininfo`: Coin Info: Coin metadata: categories, algorithm, genesis (CoinGecko)
- `color`: Color Parser: hex/rgb -> rgb/hsl + nearest name (offline)
- `comb_search`: COMB Credential Search: Search COMB breach compilation via ProxyNova free API
- `commoncrawl`: Common Crawl: Captures of a domain in Common Crawl index
- `cookies`: Cookie Audit: Secure/HttpOnly/SameSite flag review
- `correlate_sweep`: Run a 40-tool broad sweep on the query and return the cross-tool entity
graph: emails/domains/IPs/handles/phones appearing in >=2 tools, strongest
first. This is the connected-pattern signal.
- `cors`: CORS Check: Origin-reflection / wildcard misconfig
- `country`: Country Profile: World Bank country profile by ISO code
- `cpe`: CPE → CVEs: NVD: recent CVEs affecting a CPE 2.3 string
- `cpfcnpj`: CPF / CNPJ: Brazilian doc checksum (offline)
- `cratedownloads`: Crate Downloads: Download totals for a Rust crate
- `crates`: crates.io: Rust crate stats + downloads
- `cratestats`: crates.io Stats: Rust crate downloads, version, repo (no key)
- `crc32`: CRC-32 Checksum: Compute CRC-32 of input
- `credential_stuffing`: Credential Stuffing Risk: Check breach + stuffing risk
- `creditcard`: Card Brand: Identify card brand + Luhn validity (offline)
- `creditcardtest`: Credit Card Validator: Luhn check + brand guess (test only)
- `cron`: Cron Explain: Explain a 5-field cron expression (offline)
- `crossrefauthor`: Crossref Author: Works by author/keyword (Crossref)
- `crypto`: Crypto Address: BTC/ETH balance & tx history
- `cryptomarket`: Crypto Market: Global market cap, BTC dominance, 24h volume (CoinGecko)
- `cryptoprice`: Crypto Price: Live coin price + 24h change (CoinGecko)
- `csp_parse`: CSP Analyzer: Content-Security-Policy header analysis & grade
- `ctlogsearch`: CT Logs (Org): crt.sh cert search by organization name
- `cve`: CVE Lookup: CVE detail + CVSS (CIRCL, no key)
- `cvedetail`: CVE Detail: Full CVE record (CVSS, refs) via CIRCL
- `cve_poc_checker`: CVE POC Check: Check if a CVE has public POC/exploit code
- `cve_severity`: CVE Severity: CVSS + EPSS + KEV for a CVE
- `cve_timeline`: CVE Timeline: When a CVE was discussed (Twitter/Reddit/News)
- `darkweb_monitor`: Darkweb Monitor: Darkweb monitoring: marketplaces, paste sites
- `datacite`: DataCite Search: Research datasets/DOIs by keyword
- `datauri`: Data URI Parse: Parse or create data: URIs
- `dblp`: DBLP: DBLP CS publication search
- `ddg_instant`: DDG Instant: DuckDuckGo instant answer + related topics
- `decode`: Decoder: Auto base64/hex/URL-decode + refang
- `dehashed_domain`: DeHashed Domain: DeHashed public page scrape for domain breach exposure
- `depsdev`: deps.dev: Open-source insights: versions, default
- `deviantart`: DeviantArt Meta: Deviation title + author (oEmbed)
- `devto`: dev.to: Forem/dev.to public profile
- `dirlisting`: Directory Listing: Open directory-index exposure (per-target)
- `disasters`: Disasters (GDACS): Active worldwide disasters: quakes/cyclones/floods (feeds globe)
- `disposable`: Disposable Email: Is the email domain a disposable provider?
- `disposablecheck`: Disposable Email: Check if email is temporary/disposable
- `dns`: DNS Records: A/AAAA/MX/NS/TXT/CNAME/SOA/CAA records
- `dnsbl`: DNS Blocklist: Spamhaus/Barracuda/SORBS/SpamCop check
- `dnsgraph`: DNS Graph (HE): Hurricane Electric DNS delegation info
- `dnsmx`: MX (DoH): MX records via Google DNS-over-HTTPS
- `dnsprop`: DNS Propagation: Compare A records across Google/Cloudflare/Quad9
- `dnsptrrange`: PTR Range Sweep: Reverse-DNS every host in a /24 (offline)
- `dnsquery`: DNS A Record: DNS A record lookup via Google DoH
- `dnsrecon`: DNS Recon: Query ALL DNS record types at once
- `dnssec`: DNSSEC: Is the zone signed (AD flag + DNSKEY/DS)
- `dnsverify`: TXT Verifications: Which SaaS a domain is enrolled in (TXT tokens)
- `dockerhub`: Docker Hub Repo: Docker Hub repo pulls, stars, last update (no key)
- `dogeaddr`: DOGE Address: Dogecoin address balance & tx count
- `doh`: DoH Records: Uncommon DNS records (HTTPS/SVCB/TLSA/SRV/NAPTR…)
- `doi`: DOI Resolver: Crossref publication metadata for a DOI
- `domainage`: Domain Age: Days since registration (phishing signal)
- `dorks`: Search Dorks: Builds manual OSINT search links
- `ean`: Barcode/EAN: EAN/UPC check digit + GS1 country prefix (offline)
- `elevation`: Elevation: Ground elevation in metres (Open-Meteo)
- `email`: Email Intel: Gravatar, MX, disposable detection
- `email_crosssite`: Email Identity: Gravatar graph, disposable check, breach/paste surfaces (mosint)
- `email_domain_cross`: Domain Emails: Subdomain surface + org email-pattern dorks for a domain
- `emailformat`: Email Validator: Basic RFC 5322 email format validation
- `email_registration`: Email Cross-Site: Which 120+ sites have an account on this email (holehe)
- `emailrep`: Email Reputation: emailrep.io: malicious/spam/breach flags for email (no key, limited)
- `emailsec`: Email Security: SPF / DMARC / DKIM posture
- `emerging_threats`: Emerging Threats: Emerging threats: new CVEs + 0days (24h)
- `emoji`: Emoji Lookup: Emoji ↔ Unicode name/codepoint (offline)
- `ens`: ENS Resolve: ENS name <-> ETH address + avatar
- `entropy`: Shannon Entropy: Per-char entropy — flags secrets/keys
- `epoch`: Epoch Time: Unix timestamp <-> UTC datetime
- `epss`: EPSS Score: Exploitation probability (FIRST EPSS)
- `ethaddr`: ETH Address: Ethereum balance/tx + contract flag
- `ethcontract`: ETH Contract: Contract check + Sourcify verified source
- `exploit_cve`: CVE Exploits: Exploit-DB + GitHub POCs for a CVE
- `favicon`: Favicon Hash: favicon md5/sha256 for pivoting
- `fbsearch`: FB Search URLs (graph replacement): name [| keyword] -> ready facebook search URLs: people/posts/all/keyword-filtered
- `fccid`: FCC ID: FCC equipment authorization database
- `feeds`: RSS / Atom Feeds: Discover syndication feeds on a site
- `feodo`: Feodo C2: abuse.ch botnet C2 blocklist (key-free)
- `feodoips`: Feodo C2 List: Is IP on abuse.ch Feodo botnet C2 list
- `flightsnear`: Flights Nearby: Live aircraft within ~1° of coords (OpenSky)
- `formaudit`: Form Audit: Enumerate forms/inputs (login/upload) — attack surface
- `fxrate`: FX Rates: Live exchange rates for a currency code
- `gdelt`: GDELT News: Global news/events by keyword (last 24h)
- `genderize`: Gender Predictor: Predict gender from a first name (genderize.io)
- `geocode`: Geocode: Place name → coordinates (OSM Nominatim)
- `geodist`: Geo Distance: Great-circle distance between two coord pairs (offline)
- `geohash`: Geohash: lat,lon -> geohash (offline)
- `ghadvisory`: GitHub Advisories: Security advisories for an ecosystem (pip/npm/…)
- `ghcommits`: GitHub Commits: Recent commits for owner/repo
- `gh_dorking`: GitHub Dork Search: GitHub code search for target string exposure in public repos
- `ghevents`: GitHub Activity: Recent public GitHub events for a user (60/hr)
- `ghgists`: GitHub Gists: Public gists for a user
- `ghkeysgpg`: GitHub GPG Key: Whether a user publishes a GPG key
- `ghlanguages`: Repo Languages: Language byte-breakdown for owner/repo
- `ghorg`: GitHub Org: Public org profile
- `ghpubkeys`: GitHub SSH Keys: A user's public SSH keys (.keys)
- `ghrepo`: GitHub Repo: Stars/langs/license/activity (owner/repo)
- `gh_secret_scan`: GitHub Secret Scan: Scan GitHub user's public repos for leaked secrets/passwords
- `gitexposed`: Exposed Files: .git/.env/backup exposure (per-target)
- `github`: GitHub Recon: Profile, repos, languages
- `github_code`: GitHub Code Search: GitHub unauthenticated code search (10 results)
- `githubgists`: GitHub Gists: A user's public gists
- `githubsearch`: GitHub Repo Search: Search GitHub repos by keyword
- `github_trending`: GitHub Trending: Trending repos (optional language filter)
- `gitignore`: gitignore Template: GitHub .gitignore template for a language
- `gitlab`: GitLab: Public user profile
- `gleif_name`: GLEIF Name: GLEIF fuzzy legal-entity name → LEI codes
- `golangpkg`: Go Module: Latest version of a Go module
- `gomod`: Go Module: Go module latest version (module proxy)
- `goproxy`: Go Module: Latest version of a Go module via module proxy (no key)
- `gps_deep`: GPS Full Context: Coords/place -> address, sun times, nearby POIs, map links
- `graphql`: GraphQL Probe: Find GraphQL endpoint + introspection (per-target)
- `gravatarfull`: Gravatar Profile: Full public Gravatar profile + linked accounts
- `greynoise`: GreyNoise: Is the IP a known internet scanner — benign/malicious
- `hackernews`: Hacker News: Profile: karma, age, activity
- `hackernews_front`: HN Front Page: Current Hacker News front-page stories
- `hashid`: Hash Identifier: Guess hash algorithm from length/charset
- `hashnode`: Hashnode: Blogger profile: followers, posts
- `hashtext`: Hash Text: md5/sha1/sha256/sha512 of text (offline)
- `headers`: HTTP / Security: Headers + security-header scorecard
- `hexdump`: Hexdump: Offset/hex/ASCII hexdump of input (offline)
- `hexpm`: Hex.pm: Elixir/Erlang package downloads
- `hibp`: HIBP Password Check: Check if a password appeared in breaches via HIBP k-anonymity (no key)
- `hibp_breaches`: HIBP Breaches: Check breach database for email/username exposure
- `hibp_email`: HIBP Email Breaches: Email breach exposure via XposedOrNot (HIBP-compatible, no key)
- `hnsearch`: HN Search: Search Hacker News stories/comments
- `hnuser`: Hacker News User: HN profile: karma, created, submission count
- `holidays`: Public Holidays: Country public holidays this year (nager.at)
- `homoglyph`: Homoglyph: Detect confusable/mixed-script spoofing chars (offline)
- `hosthunt`: Host Search: Forward-DNS host/subdomain map (HackerTarget)
- `hostname`: Reverse DNS: IP → hostname via reverse DNS
- `hostsearch`: Host Search: Forward-DNS host enumeration for a domain
- `hstspreload`: HSTS Preload: Is the domain on the browser HSTS preload list
- `htmlcomments`: HTML Comments: Extract HTML comments — leaked TODOs/paths/software
- `htmlencode`: HTML Encode/Decode: HTML entity encode/decode
- `httpcode`: HTTP Status Code: HTTP status code meaning & family (offline)
- `httping`: HTTP Ping: Reachability + response timing
- `httpmethods`: HTTP Methods: Allowed methods + TRACE/risky-verb check
- `httpstatus`: HTTP Status: Explain an HTTP status code (offline)
- `hudsonrock`: HudsonRock Stealer: Stealer-log exposure check via HudsonRock Cavalier free API
- `huggingface`: HuggingFace: HuggingFace user profile or model card
- `human_sweep`: Human Sweep: Auto-detect target type, run all matching human tools, merge entities
- `hunter_count`: Hunter: Email Count: How many emails findable for a domain (free)
- `hunter_domain`: Hunter: Domain Emails: All findable emails for a domain + names/positions/confidence
- `hunter_find`: Hunter: Find Email: name + domain -> most likely email (usage: first last domain)
- `hunter_verify`: Hunter: Verify Email: Deliverability verdict: valid/invalid/accept_all + score
- `iban`: IBAN Validate: ISO 13616 checksum + country/length (offline)
- `imagechunks`: PNG Chunks: Hidden tEXt/zTXt/iTXt chunks in PNG (steganography)
- `imagecolors`: Image Palette: Dominant color palette extraction
- `imageexif`: Image EXIF: Full EXIF: camera, lens, timestamps, software
- `imagegps`: Image GPS: GPS coordinates from EXIF → map links (feeds globe)
- `imagehash`: Image Hash: Perceptual aHash + sha256/md5 for dupe matching
- `imageicc`: ICC Profile: Color profile name — fingerprints editing software
- `imagelsb`: LSB Steg Detect: Statistical LSB analysis — detects possible hidden payload
- `imagemeta`: Image Metadata: Dimensions, format, mode, size, megapixels
- `imagephash`: Image pHash/dHash: dHash + pHash for robust near-duplicate detection
- `imagerev`: Reverse Image: Google Lens / Yandex / Bing / TinEye search links
- `imagethumb`: EXIF Thumbnail: Extract embedded thumbnail — often retains GPS after stripping
- `imagexmp`: XMP Metadata: XMP block: creator tool, edit history, software version
- `imei`: IMEI Check: Validate IMEI (Luhn) + split TAC/serial (offline)
- `infra_fingerprint`: Infra Fingerprint: Infrastructure fingerprinting + hosting
- `intelx_email`: XposedOrNot Breach: Email breach exposure — breach names, data types, paste hits (XposedOrNot, no key)
- `internetdb`: Shodan InternetDB: Open ports, CPEs, tags, known CVEs for a host
- `ioc_reputation`: IOC Reputation: Cross-check IP/domain/hash across feeds
- `ip_deep`: IP Deep Intel: Geo + ASN + VPN/proxy/Tor risk + open ports/vulns + reverse DNS
- `ipfull`: IP Full Profile: Rich geo+ASN+proxy/mobile/hosting flags
- `ipgeo`: IP Geolocation: Geo, ISP, ASN, proxy/hosting flags
- `ipint`: IP ↔ Integer: IPv4 ↔ integer ↔ hex (offline)
- `ip_math`: IP Math: CIDR: network/broadcast/range/host count (offline)
- `ipv4classify`: IP Classify: Classify IP: private/loopback/multicast/global (offline)
- `ipv6`: IPv6 Validator: IPv6 parser, expander, classifier
- `ipwhois`: IP WHOIS / RDAP: Network owner, range, abuse contact
- `isbn`: ISBN Book: Book metadata (OpenLibrary) + checksum
- `isbnmeta`: ISBN Metadata: Book title/authors/subjects (OpenLibrary)
- `isexitnode`: Tor Exit Check: Is this a Tor exit node?
- `isin`: ISIN Validate: Validate ISIN security identifier check digit (offline)
- `isotime`: Timestamp Convert: Parse/convert a timestamp (offline)
- `iss`: ISS Position: Live International Space Station lat/lon
- `jarm`: JARM / InternetDB: Shodan InternetDB: ports, CPEs, vulns, tags (no key)
- `jslibs`: JS Libraries: Enumerate <script> sources + detect JS libs/versions
- `jsonfmt`: JSON Format: Validate, pretty-print & stat JSON (offline)
- `jwt`: JWT Decoder: Header + claims (no signature verify)
- `jwtdecode`: JWT Decode: Decode JWT header+payload (offline, unverified)
- `kev`: CISA KEV: Is the CVE actively exploited (KEV catalog)
- `keybase`: Keybase: Crypto identity + linked social proofs
- `latlonformat`: Lat/Lon Format: DD ↔ DMS ↔ DM coordinate format conversion (offline)
- `leakcheck`: LeakCheck: Breach exposure via leakcheck.io public endpoint (no key)
- `leaklookup`: Hudson Rock Stealers: Infostealer compromise check — stealer logs, credential count (Hudson Rock, no key)
- `leet`: Leetspeak: Leetspeak transform (offline)
- `leetcode_user`: LeetCode: LeetCode solved problems, ranking, badges
- `lei`: LEI Lookup: GLEIF legal-entity record by LEI code
- `links`: Link Extractor: All links + external domains + emails on a page
- `linktree`: Linktree: Extract destination links from a linktr.ee profile
- `lobsters`: Lobste.rs: Public user profile + karma
- `ltcaddr`: LTC Address: Litecoin address balance & tx count
- `luhn`: Luhn Check: Validate card/IMEI Luhn checksum (offline)
- `mac`: MAC Vendor: OUI → hardware vendor
- `macvalid`: MAC Validator: MAC address parser (colon/dash/plain)
- `macvendor`: MAC Vendor (OUI): MAC vendor + local/multicast bits from local OUI table (offline)
- `macvendorlookup`: MAC Vendor: OUI → hardware vendor (macvendors.com)
- `maidenhead`: Maidenhead Grid: Coords → ham-radio grid locator (offline)
- `malware_family`: Malware Family: Variants, IOCs, AV detections
- `manifest`: PWA Manifest: Web app manifest: name, icons, theme
- `marineweather`: Marine Weather: Wave height/period/direction + sea temp at coords
- `mastodon`: Mastodon: Resolve user@instance via WebFinger
- `maven`: Maven Central: Java artifact: 'group:artifact' or name
- `medium`: Medium: Author feed: recent post titles
- `metatags`: Meta Tags: OpenGraph / Twitter-card / generator meta tags
- `mgrs`: MGRS Grid: Lat/lon → MGRS military grid reference (offline)
- `mimetype`: MIME Type: File extension → MIME type (offline)
- `mitre_technique`: MITRE Technique: ATT&CK technique → tactics + detection
- `moonphase`: Moon Phase: Current moon phase & illumination (offline)
- `morse`: Morse Code: Morse encode/decode, autodetecting direction (offline)
- `mtasts`: MTA-STS: Inbound-mail TLS enforcement policy
- `musicbrainz`: MusicBrainz: Artist search: type, country, MBID
- `musicbrainzartist`: MusicBrainz Artist: Artist type, country, lifespan
- `nationalize`: Nationality: Predict nationality from a name (nationalize.io)
- `nato`: NATO Phonetic: Spell text in NATO phonetic alphabet (offline)
- `nearbywiki`: Nearby Places: Wikipedia places near a coordinate
- `npm`: npm Author: Packages published by an author
- `npmdl`: npm Downloads: npm download counts day/week/month
- `npmdownloads`: npm Downloads: npm package download counts, last week + month (no key)
- `npmorg`: npm Org: npm organization: all published packages
- `npmpkg`: npm Package: npm package version, deps, maintainers
- `nstrace`: NS Delegation: Trace NS delegation: TLD → registrar → authoritative
- `nuget`: NuGet: .NET package stats + downloads
- `numlookup`: Number Lookup: Validity, region, carrier, line type, timezones (libphonenumber)
- `numwords`: Number to Words: Integer → English words (offline)
- `nvdcve`: NVD CVE Detail: Full NVD record: CVSS, CWE, references
- `onthisday`: On This Day: Historical events on a date (Wikipedia; MM/DD or today)
- `openalexauthor`: OpenAlex Author: Author works count, h-index, institution
- `openalexwork`: OpenAlex Work: Scholarly work: citations, concepts, OA
- `opencorp`: OpenCorporates: Company registrations worldwide search
- `openfoodfacts`: Product Barcode: EAN/UPC -> product, brand, nutrition
- `openphish`: OpenPhish: Community phishing-URL feed membership
- `orcid`: ORCID: Researcher record (0000-000X-…)
- `orcidworks`: ORCID Works: Recent publications for an ORCID iD
- `orgname`: Company → LEI: Fuzzy company-name search → candidate LEIs
- `osmuser`: OpenStreetMap User: Contributor: last edit + changeset
- `osv`: OSV Vulns: Known package vulns (OSV.dev). 'eco:name'
- `otxdomain`: OTX Domain Rep: AlienVault OTX threat pulses for a domain
- `otxip`: OTX IP Rep: AlienVault OTX threat pulses for an IP
- `packagist`: Packagist: PHP/Composer package stats (vendor/pkg)
- `pageinfo`: Common Crawl Page: Common Crawl capture index lookup
- `passentropy`: Password Entropy: Estimate entropy & offline crack time (offline)
- `passgen`: Password Gen: Generate strong random passwords + passphrase (offline)
- `passwordcheck`: Password Pwned: HIBP k-anonymity breach check (safe)
- `password_dumps`: Password Dump Search: Search Dehashed for leaked passwords (query-only)
- `paste_domain`: Paste Domain Search: Find domain in public pastes via psbdmp.ws (no key)
- `paste_email`: Paste Email Search: Find email in public pastes via Wayback CDX + search links (no key)
- `peeringdb`: PeeringDB: Network type, traffic, IX/facility presence
- `peeringnet`: PeeringDB Net: Peering policy / traffic / IX presence for ASN
- `peers`: ASN Peers: Upstream/downstream BGP neighbours
- `permissions_pol`: Permissions Policy: Permissions-Policy: camera/mic/geo controls
- `person_identity`: Person Identity: Name -> gender/age/nationality probs + Wikipedia/Wikidata + dorks
- `person_sweep`: Person-focused sweep: checks ~30 username/email/social presence tools for
one name/handle and returns where it exists plus extracted entities.
- `pgp`: PGP Key: Public key published on keys.openpgp.org
- `phishing_intel`: Phishing Intel: Phishing kit tracking + URL detection
- `phone`: Phone Number: E.164 country/region (offline)
- `phoneapps`: Messaging Links: WhatsApp / Telegram / Viber / Signal deep links
- `phonecc`: Calling Code: Country, trunk & intl dialing prefixes (offline)
- `phone_deep`: Phone Deep-Dive: Validity, carrier, region + WhatsApp/Telegram/Signal pivots, caller-ID surfaces
- `phonefmt`: Phone Format: E.164 / national / international / RFC3966 formats (offline)
- `phone_leak`: Phone Leak Check: Phone in breaches/pastes via LeakCheck + dork pack
- `phonenanp`: NANP Area Code: +1 number → US/Canada region (offline subset)
- `phonepivot`: Phone Lookups: Caller-ID / reputation site links (Truecaller, Sync.me…)
- `phonespam`: Spam Reports: Robocall / scam report-database links
- `phonevcard`: vCard: Generate a .vcf contact card (offline)
- `pluscode`: Plus Code: Coords → Open Location Code / Google Plus Code (offline)
- `port`: Port Reference: Service + exposure notes for a port number
- `portlookup`: Port Lookup: IANA port → service name (offline)
- `portquick`: Port Check: Quick TCP port scan (2s timeout)
- `portscan`: Port Scan: TCP connect scan: common + camera ports
- `pubmed`: PubMed: PubMed biomedical paper search (NCBI)
- `punycode`: Punycode/IDN: IDN domain ↔ Punycode (xn--) homograph check (offline)
- `pwstrength`: Password Strength: Offline entropy/strength estimate
- `pypi`: PyPI Package: Python package metadata + links
- `pypiproject`: PyPI Project: PyPI version/license/links
- `pypistats`: PyPI Downloads: PyPI recent download counts
- `qrcode`: QR Code: Generate a QR code for text/URL
- `quakes`: Earthquakes: USGS recent quakes — global or near coords (M2.5+)
- `quoted_printable`: Quoted-Printable: Quoted-printable encode/decode
- `railfence`: Rail Fence: Rail-fence cipher over 3 rails (offline)
- `random_fact`: Random Fact: Random trivia fact
- `randomuser`: Random Identity: Synthetic identity for sockpuppet hygiene (randomuser.me)
- `ransomware_tracker`: Ransomware Groups: Ransomware gang profiles + recent hits
- `rdap`: RDAP Registration: Structured domain registration record (RDAP/IANA bootstrap, no key)
- `rdap_domain`: RDAP Domain: RDAP structured domain registration data
- `rdapip`: RDAP IP: Authoritative RDAP record for an IP
- `reddit_sub`: Reddit Subreddit: Subreddit: subscribers, active users, description
- `reddit_user`: Reddit User: Reddit user: karma, age, verified status
- `redirects`: Redirect Tracer: Full HTTP redirect chain
- `referrer_pol`: Referrer Policy: Referrer-Policy header — URL leakage risk
- `regdomain`: Registered Domain: Extract eTLD+1 registered domain from URL (offline)
- `restcountry`: Country Detail: Capital/region/income by name or ISO (World Bank)
- `reversedns`: Reverse DNS: PTR record / hostname
- `reverseip`: Reverse IP: Other domains sharing the host
- `revgeo`: Reverse Geocode: lat,lon -> address (OSM Nominatim)
- `revgeocode`: Reverse Geocode: Coordinates → nearest address (OSM)
- `revimg`: Reverse Image: Reverse-image-search links (Lens/Yandex/TinEye/Bing)
- `ripewhois`: RIPE Network Info: Covering prefix + origin ASN (RIPEstat)
- `robots`: robots.txt: Disallowed paths + sitemaps
- `robotsmeta`: Robots Meta: meta-robots + X-Robots-Tag: noindex/nofollow/noarchive
- `robotstxt_history`: robots.txt History: Historical robots.txt snapshots from Wayback Machine
- `roman`: Roman Numerals: Convert int <-> roman numeral, autodetecting (offline)
- `rot13`: ROT-13 Cipher: ROT-13 encode/decode
- `rot47`: ROT47: ROT47 ASCII cipher (offline, self-inverse)
- `rpki`: RPKI / ROA: Route-origin validation for the covering prefix
- `rubygemrev`: Gem Rev-Deps: Reverse dependencies of a RubyGem
- `rubygems`: RubyGems: Ruby gem stats + downloads
- `s3buckets`: Cloud Buckets: S3/GCS/Azure buckets named for the domain
- `sec_edgar`: SEC EDGAR: Company name + recent SEC filings by ticker/CIK
- `securitytxt`: security.txt: RFC 9116 disclosure policy & contacts
- `semanticscholar`: Semantic Scholar: Paper TLDR, citations, influence
- `semver`: Semantic Version: Parse and validate semantic versioning
- `sha256lookup`: SHA-256 Reverse: Crack SHA-256 via online DB
- `sitemap`: Sitemap: Fetch sitemap.xml + list URLs
- `slug`: Slugify: Text → URL-safe slug (offline)
- `smtpbanner`: SMTP Banner: SMTP banner & EHLO capabilities (ports 25/587/465)
- `snowflake`: Snowflake ID: Decode Twitter/Discord snowflake → timestamp (offline)
- `snusbase_hash`: Hash Reverse (Leaks): Reverse MD5/SHA1 hash via breach-sourced hash DB (md5decrypt.net)
- `social`: Social Links: Direct profile URLs across 20 platforms
- `social_deep`: SOCIAL DEEP: All-Platform Link Set: 'name | username | phone | email' (pipe-separated, use what you have) -> ready URL sets for FB/IG/TikTok/X/LinkedIn/Reddit/Discord/Snap/Bluesky/WhatsApp/biolinks
- `soladdr`: SOL Account: Solana account balance & owner program
- `sopostuser`: StackOverflow User: SO profile + reputation by numeric id
- `soundcloud`: SoundCloud Meta: Track/user title + author (oEmbed)
- `spacepeople`: People in Space: Who is in space right now (names + craft)
- `spaceweather`: Space Weather: Planetary Kp index + geomagnetic storm/aurora (NOAA)
- `spamhauslookup`: Spamhaus IP Check: Spam/phishing IP blacklist check
- `spdxlicense`: SPDX License: SPDX license id → name + OSI status
- `sri_check`: SRI Check: Subresource Integrity: external scripts without integrity=
- `srvlookup`: SRV Records: SIP/XMPP/mail/CalDAV SRV record discovery
- `ssh`: SSH Banner: Per-target SSH server banner / version
- `ssn_check`: SSN/Identity Leak: Check if SSN/DOB appears in identity theft databases
- `stackoverflow`: Stack Overflow: SO/SE user search by display name
- `steam_user`: Steam Profile: Steam community profile via public XML
- `stringmetrics`: String Metrics: Length, entropy, character breakdown
- `subbrute`: Subdomain Brute: Resolve a common-subdomain wordlist (per-target)
- `subdomains`: Subdomains: Certificate-transparency subdomain discovery
- `suntimes`: Sun Times: Sunrise/sunset/twilight for a coordinate (UTC)
- `supply_chain_risk`: Supply Chain Risk: Dependency vulns + typosquatting
- `swagger`: Swagger / OpenAPI: Exposed API docs at common paths (per-target)
- `swiftbic`: SWIFT/BIC: Parse SWIFT/BIC: bank/country/branch (offline)
- `takeover`: Subdomain Takeover: Dangling-CNAME takeover fingerprint check
- `teamcymru`: Team Cymru ASN: IP → ASN via Team Cymru DNS (fastest ASN lookup)
- `tech`: Tech Fingerprint: CMS/framework/server detection
- `telegram_channel`: Telegram Channel: Public channel preview: subscribers, description
- `tempconv`: Temperature: Convert °C / °F / K (offline)
- `tempmail`: Temp Email: Generate/read a disposable email inbox (1secmail)
- `threat_actor`: Threat Actor: Known campaigns, techniques, tools
- `threatcrowd`: Passive DNS: OTX passive DNS resolution history
- `threat_pattern`: Threat Pattern: Find threat patterns across incidents
- `tiktok`: TikTok Profile: TikTok user stats (best-effort, keyless)
- `timezone_info`: Timezone Info: Timezone UTC offset & current time (offline, IANA names)
- `tldinfo`: TLD Info: TLD registry operator, type, purpose (offline)
- `tls`: TLS Certificate: Live cert: issuer, validity, SANs, cipher
- `tlsa`: DANE / TLSA: Certificate-pinning DANE records on :443
- `tlsscan`: TLS Versions: Which SSL/TLS protocols the host accepts
- `tor`: Tor Exit Check: Is the IP a known Tor exit node
- `transform`: Text Transforms: rot13/base32/morse/reverse (offline)
- `trendingwiki`: Trending Wikipedia: Most-read Wikipedia articles today
- `trufflehog_url`: Secret Pattern Scan: Scan raw URL content for API keys, tokens, private keys, JWTs
- `txhash`: Crypto Tx: BTC/ETH transaction detail (blockchair)
- `typosquat`: Typosquat Finder: Look-alike domains that currently resolve
- `ulid`: ULID Decode: Decode a ULID's embedded timestamp (offline)
- `unicode_lookup`: Unicode Lookup: Unicode codepoint: name, category, HTML entity (offline)
- `unixperm`: Unix Permissions: Octal permission (755/644) → rwx breakdown (offline)
- `unpaywall`: Unpaywall: Is a DOI open-access? Direct PDF link
- `urban`: Urban Dictionary: Slang/term definitions + examples
- `urlparse`: URL Parse: Parse URL into components + query params
- `urlscan`: urlscan.io: Past scans, verdicts, infra (IP/ASN/server) for a site
- `urlscansearch`: urlscan Archive: Public urlscan.io scan history for a domain
- `useragent`: UA Parser: Parse a User-Agent into OS/browser (offline)
- `username`: Username Hunter: Presence across 16 public sites
- `username_dossier`: Username Dossier: 250-site profile dossier via Maigret with extracted names/emails/phones
- `utm`: UTM Coords: Lat/lon → UTM coordinates (WGS84, offline)
- `uuencode`: UUencode: Unix-to-Unix encoding
- `uuid`: UUID Parser: Version/variant + v1 timestamp/MAC (offline)
- `uuid_validate`: UUID Validator: UUID v1-v5 version and variant detector
- `vatid`: EU VAT: Validate EU VAT number country format (offline)
- `vigenere`: Vigenere Cipher: Vigenere encrypt/decrypt: 'KEY:text[:d]' (offline)
- `vimeo`: Vimeo Meta: Video title, author, thumbnail (oEmbed)
- `vin`: VIN Decoder: NHTSA vPIC vehicle decode (make/model/plant)
- `vuln_feed`: Vuln Feed: Real-time vuln feeds (NVD, Exploit-DB, PacketStorm)
- `waf`: WAF / CDN: Detect WAF/CDN from headers & cookies
- `wayback`: Wayback Machine: Archive.org snapshot history
- `wayback_leaks`: Wayback Leak Scan: Search Wayback Machine for historically exposed .env/config/secrets
- `weather`: Weather: Current weather at a coordinate (Open-Meteo)
- `weatheralerts`: Weather Alerts: Active US NWS weather alerts near coords
- `webfinger`: WebFinger: WebFinger resource discovery (ActivityPub/OIDC)
- `wellknown`: .well-known Scan: Which /.well-known/* resources exist
- `whatsnearby`: Nearby POIs: OSM amenities within 500m of coords (Overpass)
- `whois`: WHOIS / RDAP: Registration, status, nameservers, DNSSEC
- `whois_check`: WHOIS Check: Domain WHOIS record existence via who.is
- `whoisserver`: WHOIS Server: TLD → WHOIS server mapping (offline + IANA fallback)
- `wikidata`: Wikidata Search: Search Wikidata entities by label (no key)
- `wikidatasearch`: Wikidata Search: Free-text → Wikidata entities
- `wikipedia`: Wikipedia Summary: Wikipedia REST summary: extract, type, coords (no key)
- `wikipv`: Wikipedia Meta: Page length, last edit, editor
- `wikisummary`: Wikipedia Summary: Page extract/description for a topic
- `wordcount`: Word Count: Text stats: words/chars/lines/reading time (offline)
- `workup`: WORKUP: Full Person Dossier: first+last -> username variants x 16 platforms, name stats, dork surfaces, wiki (30-60s)
- `wpplugin`: WP Plugin Info: WordPress.org plugin version/install stats
- `wpscan`: WordPress Scan: WP version + author enum via REST (per-target)
- `xrpaddr`: XRP Account: XRP Ledger account balance & sequence
- `youtube`: YouTube Meta: Video/channel title, author, thumbnail (oEmbed)
- `zenodo`: Zenodo: Zenodo open-research records search
- `zerodday_timeline`: Zero-Day Timeline: 0day mentions across researchers + CVE
- `zonetransfer`: Zone Transfer: AXFR attempt — is zone transfer misconfigured?
