Run Sherlock, Maigret, Holehe, GHunt, theHarvester, SpiderFoot and more OSINT tools locally
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
One-click editor setup isnβt available for this listing yet β we donβt have a confirmed install command, and weβd rather show nothing than point your editor at the wrong package or host. Follow the projectβs own setup instructions, linked above.
An MCP server that lets AI agents run classic OSINT tools on your own machine: Sherlock, Maigret, Blackbird, Holehe, GHunt, theHarvester, SpiderFoot, subfinder, dnstwist, dnsrecon, PhoneInfoga and ExifTool, plus built-in WHOIS, DNS, certificate transparency and Wayback Machine lookups. No API keys and no cloud service in between: the tools run locally and query public sources directly.
Ask your assistant "which sites have an account for jane@example.com?" or "what can you find about example.com?", and it picks the tools, runs them and reads the results for you.
| Tool | Give it | You get | Needs |
|---|---|---|---|
sherlock_username_search | username | accounts on 400+ sites | Sherlock |
maigret_username_search | username | accounts on up to 3000+ sites, with the profile data found on them | Maigret |
blackbird_username_search | username | accounts on the 700+ sites of the WhatsMyName list | Blackbird checkout (not in the Docker image) |
holehe_email_search | email address | which of about 120 sites have an account for it | Holehe |
ghunt_google_search | Google account email or Gaia ID | name, profile picture, Maps reviews, calendar and other public data | GHunt, logged in |
theharvester_domain_search | domain or company name | email addresses, subdomains, hosts, IP addresses | theHarvester |
spiderfoot_scan | domain, IP, email, phone, username, person name... | findings grouped by type | SpiderFoot checkout |
phoneinfoga_scan | phone number | country, number formats, carrier (with an API key), search queries | PhoneInfoga |
exiftool_metadata | path to a local file | GPS coordinates, camera, author, software, timestamps | ExifTool |
subfinder_subdomain_search | domain | subdomains from passive sources, with the sources that reported them | subfinder |
dnstwist_lookalike_domains | domain | registered lookalike domains (typos, homoglyphs, other TLDs) with their A, MX and NS records | dnstwist |
dnsrecon_domain_scan | domain | DNS records, zone transfer attempts, DNSSEC zone walking | dnsrecon |
whois_lookup | domain, IP address, network or AS number | registrar, dates, name servers, holder and contacts where public (RDAP, or WHOIS) | built in |
dns_lookup | domain name or IP address | A, AAAA, CNAME, MX, NS, TXT, SOA, CAA records, or the reverse name | built in |
crtsh_certificate_search | domain | host names and email addresses from TLS certificates issued for it (crt.sh) | built in |
wayback_snapshots | URL or domain | archived snapshots in the Wayback Machine, newest first | built in |
osint_toolbox_status | nothing | which tools are installed, and how to install the missing ones | built in |
Only installed tools are offered to the agent. Runs take from seconds to half an hour (a full SpiderFoot scan); requests run in parallel and can be cancelled.
Pick one:
The image is large, so pull it once before adding the server; otherwise the first start can take longer than your client waits:
Add the server to your client:
Files for ExifTool, the GHunt login, API keys and proxies are covered in Docker details.
Install uv, then install the tools. This installs everything that is missing and checks that each tool starts; see Install the tools for what it does:
Add the server to your client:
To run the latest code from main instead of a release, use uvx --from git+https://github.com/renkagod/osint-toolbox-mcp osint-toolbox-mcp.
One-click install:
| Client | Docker (all but Blackbird) | uvx (your tools) |
|---|---|---|
| Cursor | ||
| VS Code | ||
| VS Code Insiders | ||
| LM Studio |
Claude Desktop: download osint-toolbox-mcp-<version>.mcpb from the latest release and open it. Claude Desktop installs it as an extension and asks for the optional SpiderFoot, Blackbird and ExifTool locations; the other tools are found on PATH. You can also paste the JSON above into Settings β Developer β Edit Config.
Claude Code:
Clients that read the mcpServers JSON above (paste it into the file):
| Client | Where the config lives |
|---|---|
| Cursor | ~/.cursor/mcp.json, or .cursor/mcp.json in a project |
| Windsurf | ~/.codeium/windsurf/mcp_config.json |
| Cline | MCP Servers β Configure β cline_mcp_settings.json |
| Roo Code | .roo/mcp.json in a project, or the global MCP settings |
| Gemini CLI | ~/.gemini/settings.json |
| Antigravity | agent panel "β¦" β MCP Servers β Manage MCP Servers β View raw config |
| LM Studio | Program tab β Install β Edit mcp.json |
| Kiro | ~/.kiro/settings/mcp.json, or .kiro/settings/mcp.json in a project |
Clients with their own format (shown with uvx; for Docker, use docker with the arguments run -i --rm ghcr.io/renkagod/osint-toolbox-mcp):
Or in .vscode/mcp.json:
Or in ~/.codex/config.toml, with a longer timeout for slow scans:
In settings.json:
In ~/.config/goose/config.yaml:
In opencode.json:
In .continue/mcpServers/osint-toolbox.yaml:
Skip this if you use Docker, unless you want Blackbird.
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/osint-toolbox)<a href="https://allmcps.com/mcp/osint-toolbox"><img src="https://allmcps.com/api/badge/osint-toolbox?style=directory" alt="OSINT Toolbox on AllMCPs" /></a>