MCP ConfigsMay 12, 2026·3 min read

Awesome OSINT MCP Servers — Security Tools Directory

Curated OSINT MCP server directory (threat intel, recon, censorship). Discover endpoints and install via npx or remote HTTP transports.

Agent ready

This asset can be read and installed directly by agents

TokRepo exposes a universal CLI command, install contract, metadata JSON, adapter-aware plan, and raw content links so agents can judge fit, risk, and next actions.

Needs Confirmation · 62/100Policy: confirm
Agent surface
Any MCP/CLI agent
Kind
Mcp
Install
Manual
Trust
Trust: Established
Entrypoint
Pick a server and run: claude mcp add --transport http <name> <url>
Universal CLI install command
npx tokrepo install 9f1c7c7c-1bfa-522b-be2a-cc42b5c94806
Intro

Awesome OSINT MCP Servers is a practical directory for security-minded agent builders: it collects MCP servers and tools you can wire into Claude Code/Cursor to fetch OSINT signals. Use it as a shortlist for building a controlled, auditable security toolbelt.

Best for: security teams and builders who want MCP-based OSINT tooling without hand-rolling every integration

Works with: Claude Code/Cursor MCP clients, npx-based MCP servers, remote HTTP MCP endpoints

Setup time: 5–20 minutes (depends on server)

Key facts (verified)

  • Entries include concrete install commands like npx ... for some servers.
  • README includes quantitative claims for at least one entry (e.g., tool counts, country counts) as part of the directory.
  • GitHub: 228 stars · 38 forks; pushed 2026-05-11 (GitHub API verified).

Main

Use this list as a selection pipeline:

  • Start with read-only / evidence-oriented tools.
  • Prefer servers with clear licenses and transparent data sources.
  • Pin versions for npx installs when rolling into production.

For each chosen MCP, record: data source, rate limits, auth requirements, and what gets logged.

README excerpt (verbatim)

Awesome OSINT MCP Servers

Awesome

A curated list of MCP servers for OSINT (Open Source Intelligence).

An MCP server connects tools and services to LLM systems like Claude, Cursor, Windsurf, etc.
MCP servers simplify execution of OSINT tools by combining them with the ease of LLM querying
and the ability to create flexible reports.


Legend: 📦 Open Source  ·  🆓 Free / Has Free Tier  ·  💰 Paid / Requires Paid API

Contents

SOCMINT

  • 💰 Expose Team — AI-powered OSINT at lightspeed. Credit-based plans from $8/month.
  • 📦🆓 Maigret — Collect user account information from various public sources by username.
  • 📦💰 Xquik — X (Twitter) data extraction and automation with 40+ REST API endpoints, real-time account monitoring, and trending topics. MCP server with API key auth.

Network Scanning

  • 📦🆓💰 Shodan — Query the Shodan API and CVEDB for IP reconnaissance, DNS operations, vulnerability tracking, and device discovery. Free tier available with limited queries, requires Shodan API key.
  • 📦🆓💰 ZoomEye — Obtain network asset information by querying ZoomEye using dorks and other search parameters. 7-day free trial available, requires ZoomEye API key.
  • 📦🆓 DNSTwist — DNS fuzzing tool that helps detect typosquatting, phishing, and corporate espionage.
  • 📦🆓 OSINT Toolkit — Unified interface for network reconnaissance with parallel execution of WHOIS, Nmap, DNS lookups, and typosquatting detection.

FAQ

Q: Is this a single MCP server? A: No—this repo is a directory of many OSINT MCP servers and tools; you choose entries to install.

Q: How do I install an entry? A: Follow each entry’s hint (often npx ... or a remote HTTP URL) and add it to your MCP client.

Q: What should I audit? A: Data sources, permissions, logging, and any credentials required by the selected server.

🙏

Source & Thanks

Source: https://github.com/soxoj/awesome-osint-mcp-servers > License: MIT > GitHub stars: 228 · forks: 38

Discussion

Sign in to join the discussion.
No comments yet. Be the first to share your thoughts.

Related Assets