█

AI/TLDR

OpenOSINT

An AI agent that chains 20 OSINT lookups from one plain-language prompt

Security AgentsOpen source
Language
Python
License
MIT
$pip install openosint

Overview

OpenOSINT is an open-source intelligence (OSINT) agent for security researchers and analysts. You describe a target in plain language — an email address, a username, a domain, an IP — and an LLM decides which of its 20 investigation tools to run, then chains follow-up lookups on whatever it finds, for example pivoting from an email's linked accounts to a username search across other platforms. Every investigation ends in a saved Markdown report, with PDF export available.

OpenOSINT web UI investigating demo@example.com: tool cards for search_email and search_breach list linked accounts and two breaches, followed by an AI-written summary
The web UI streams each tool call as a card, then writes a summary of what the lookups found.OpenOSINT README ↗

The design point is that the model only issues tool calls; the project's own Python code executes the real lookup — holehe for email accounts, sherlock for usernames, HaveIBeenPwned for breaches, python-whois, sublist3r, phoneinfoga, dnspython, and the Shodan, VirusTotal, Censys, AbuseIPDB, IP2Location, GitHub and GDELT APIs. The agent cannot browse freely or run arbitrary code, so every finding traces back to a real tool call, though its choice of tools can still be wrong or incomplete.

It ships as a pip package with four interfaces over the same toolset: an interactive REPL, a browser web UI, direct CLI subcommands that skip the AI entirely, and an MCP server that exposes all 20 tools to Claude Code, Claude Desktop or any MCP client. The agent runs on Anthropic Claude by default, a local Ollama model, or any OpenAI-compatible endpoint. The project states it is for legal, authorised security research only.

What it does

  • AI tool chaining: the agent picks tools from the findings so far and pivots across email, username, domain and IP leads
  • 20 lookup tools covering email accounts, usernames across 400+ platforms, breach exposure, WHOIS, subdomains, DNS with SPF/DMARC/DKIM analysis, phone numbers, pastes, Google dorks and threat-intel APIs
  • Three model backends: Anthropic Claude, local Ollama, or any OpenAI-compatible endpoint such as LiteLLM, vLLM or LM Studio
  • Native MCP server exposing all 20 tools to Claude Code, Claude Desktop and other MCP clients
OpenOSINT entity graph explorer showing two Organization nodes linked by a dashed same_as candidate edge scored 0.83, with a Review button for human confirmation
The optional entity graph keeps deduplication as a scored candidate until a reviewer accepts it (synthetic demo data).OpenOSINT README ↗
  • Optional FollowTheMoney entity graph with statement-level provenance and a human review queue for same_as deduplication candidates
  • Markdown and PDF reports after each investigation, saved session history, parallel tool execution with --parallel and JSON output with --json

Getting started

OpenOSINT installs from PyPI. Several key-less tools work with zero configuration; the AI agent needs an Anthropic key, a local Ollama model or an OpenAI-compatible endpoint, and some lookups need their provider's API key.

Install the package

The email, username, subdomain and phone tools shell out to holehe, sherlock, sublist3r and phoneinfoga, which must be on your PATH; if one is missing only that tool returns an error.

bashbash
pip install openosint

# optional external binaries
pip install holehe sherlock-project sublist3r

Add your keys to a .env file

Copy .env.example to .env in the directory you run openosint from. ANTHROPIC_API_KEY powers the default agent; tool keys such as HIBP_API_KEY, SHODAN_API_KEY or VIRUSTOTAL_API_KEY are only needed for those tools.

texttext
ANTHROPIC_API_KEY=...
HIBP_API_KEY=...
Terminal running openosint dns example.com and returning DNS records
A direct DNS lookup from the CLI, no AI involved.OpenOSINT README ↗

Run a single tool without the AI

Each lookup is also a plain CLI subcommand, useful for scripting or a quick check.

bashbash
openosint email target@example.com
openosint dns example.com

Start the AI REPL and investigate a target

With no arguments openosint opens the interactive agent. Type a target and it chains tools on the findings, then saves a report under reports/.

bashbash
openosint
openosint > investigate target@example.com
Terminal demo of OpenOSINT listing a username found on 12 platforms, then an email scan showing which services the address is registered with
Username and email scans in the terminal.OpenOSINT README ↗

Or use the web UI, fully local if you like

The web extra opens a browser chat on localhost:8080. Pick Ollama (local) in Settings to run without an API key.

bashbash
pip install "openosint[web]"
ollama pull llama3.2
openosint web

Expose the tools to Claude Code over MCP

bashbash
claude mcp add openosint python /absolute/path/to/OpenOSINT/openosint/mcp_server.py
claude mcp list

Commands and code are distilled from the project's own documentation — always check the official repo for the latest.

When to use it

  • Reach for it when you want to map a person's or organisation's public footprint from a single email or username during an authorised investigation
  • Reach for it for attack-surface reconnaissance on a domain you own: subdomains, DNS and email-security records, exposed services via Shodan or Censys
  • Reach for it when you want OSINT lookups available as tools inside Claude Code or another MCP client rather than in a separate app
  • Reach for it for quick IP or file-hash triage against VirusTotal and AbuseIPDB from the command line

How OpenOSINT compares

OpenOSINT alongside other open-source security agents tools AI/TLDR tracks, ranked by GitHub stars.

ToolStarsWhat it does
PentAGI★ 25.2kPentAGI is a self-hosted AI security platform that plans and runs penetration tests autonomously using a team of agents and 20+ built-in pentesting tools.
PentestGPT★ 15.7kAn open-source agent that uses large language models to run penetration tests and solve security challenges, either fully autonomously or with a human in the loop.
IDA Pro MCP★ 12.4kAn MCP server and IDA Pro plugin that exposes decompilation, cross-references, renaming and type editing to an LLM client, letting an agent read and annotate a binary inside your IDA database.
HexStrike AI★ 12.3kAn MCP server that gives an AI agent a single interface to 150+ installed security tools — Nmap, Nuclei, SQLMap, Ghidra, Hashcat and more — so it can drive reconnaissance, scanning and binary analysis itself.
CAI★ 9.8kCAI (Cybersecurity AI) is an open-source Python framework for building AI agents that automate offensive and defensive security tasks like recon, vulnerability discovery, and exploitation.
AI-Infra-Guard★ 6.7kTencent Zhuque Lab's AI red teaming platform: scans agents, Agent Skills and MCP servers, checks AI infra against a CVE library, fingerprints API relays and runs jailbreak evaluations.
T3MP3ST★ 6.3kA multi-agent offensive-security harness for authorised testing that drives an already-installed coding agent, or a local OpenAI-compatible model, through recon, exploitation and reporting from a localhost War Room or the CLI.
OpenOSINT★ 1.7kAn AI agent that chains 20 OSINT lookups from one plain-language prompt