Awesome OSINT MCP Servers
A curated list of ~60 MCP servers for OSINT work, maintained by soxoj. MIT, 411★ / 86 forks / 76 commits. Ten categories: SOCMINT, network scanning, web scraping, company intelligence, public records & compliance, threat intelligence, research intelligence, meta/discovery, blockchain intelligence, and market & trading. Named entries include Shodan, VirusTotal, Maigret, FilingFirehose (SEC filings) and Voidly (internet censorship tracking).
T3, not T4 — the grade the spoke gave awesome-osint-list does not apply here. This list marks every entry for open-source status, free/freemium/paid tier, and whether it needs an API key, and it says plainly that most do, while some are keyless or trial-only. That is inclusion metadata: three facts per row a reader can act on before installing anything. It is still a link list with no testing and no dates.
What it is actually a list of
Every entry is a server the model calls, not a tool a person runs. That is the whole point of the MCP packaging: the analyst stops driving each instrument and instead gives one LLM the ability to call sixty of them, in whatever order the investigation suggests. The list’s own framing — connect tools to LLMs “enabling flexible intelligence gathering and reporting” — puts the flexibility in the model’s choice of tool.
So the corpus now holds the automation story at three levels. llm-osint is one LLM with a hand-built loop. kallisto-osinter is a multi-agent system with its tools wired in. This is the tool layer standardized underneath both — an interface any agent can consume, which means the capability no longer has to be built into the OSINT tool at all. The ai-osint page has been describing agents that include their instruments; MCP inverts that, and the instruments are now published separately for whichever agent shows up.
Against the census
Read next to awesome-osint-list, routed the same day, this makes an awkward pair.
That list is ~1,730 links, and its finding was that the field’s real toolkit is mostly hosted web services a human opens in a browser, with AI appearing mainly as something to attack rather than something to investigate with. This list is 60 links and every one of them is machine-callable. Both are community catalogs by active maintainers; neither is a survey. The honest reading is that they are counting different things at different stages — the census of what practitioners use, and an early inventory of what has been wrapped for agents — and the gap between 1,730 and 60 is roughly the size of the conversion still outstanding.
The category list has the same reach the census had. Blockchain intelligence and market & trading sit alongside SOCMINT and network scanning, and public records & compliance covers sanctions and filings. The field keeps defining itself by what can be found, not by a technique.
Dual-use note
The gating detail is that MCP servers make capability composition cheap. Username enumeration, breach data, network scanning and public records are individually defensible and were always available; putting all of them behind one model that decides which to call is what changes the effort of building a dossier on a person, which is exactly the concern the spoke’s ai-osint and social-engineering pages already carry. The list itself carries no ethics disclaimer — awesome-social-engineering remains the only catalog here that scopes its own use.
Related
soxoj · osint · ai-osint · awesome-osint-list · username-reconnaissance · ip-reconnaissance · kallisto-osinter · llm-osint · model-context-protocol · social-engineering