Skip to main content
ClaudeWave

MCP server with passive OSINT lookups: RDAP/whois, DNS, crt.sh subdomains, Wayback Machine, HTTP headers, Shodan InternetDB

MCP ServersRegistry oficial0 estrellas0 forks● PythonMITActualizado today
ClaudeWave Trust Score
95/100
✓ Verified
Passed
  • ✓Open-source license (MIT)
  • ✓Actively maintained (<30d)
  • ✓Clear description
  • ✓Topics declared
  • ✓Documented (README)
Last scanned: 10/1/2026
Install in Claude Code / Claude Desktop
Method: UVX (Python) · osint-mcp-server
Claude Code CLI
claude mcp add osint-mcp -- uvx osint-mcp-server
claude_desktop_config.json (Claude Desktop)
{
  "mcpServers": {
    "osint-mcp": {
      "command": "uvx",
      "args": ["osint-mcp-server"]
    }
  }
}
1. Run the command above in your terminal (Claude Code), or paste the JSON config into claude_desktop_config.json (Claude Desktop).
2. Replace any <placeholder> values with your API keys or paths.
3. Restart Claude. The MCP server and its tools appear automatically.
Casos de uso

Resumen de MCP Servers

# osint-mcp

[![tests](https://github.com/robyroro/osint-mcp/actions/workflows/tests.yml/badge.svg)](https://github.com/robyroro/osint-mcp/actions/workflows/tests.yml)
[![PyPI](https://img.shields.io/pypi/v/osint-mcp-server)](https://pypi.org/project/osint-mcp-server/)

MCP server that gives Claude (or any MCP client) a handful of passive recon lookups for domains and IPs. No API keys needed, everything comes from public sources.

I got tired of jumping between whois, crt.sh, the Wayback Machine and Shodan tabs when looking into a domain, so this lets the model do it and put the results together.

## Tools

| tool | what it does | source |
|---|---|---|
| `recon_domain` | all of the below at once + a list of highlights worth a look | everything |
| `domain_whois` | registrar, created/expires, nameservers, abuse contact | RDAP (rdap.org) |
| `ip_whois` | network owner, CIDR, country, abuse contact, PTR | RDAP + reverse DNS |
| `dns_lookup` | A, AAAA, CNAME, MX, NS, TXT, SOA, CAA (or pick your own) | your resolver or a custom one |
| `subdomains` | subdomains found in certificate transparency logs | crt.sh |
| `wayback` | archived snapshots of a URL, supports `example.com/*` | Wayback CDX API |
| `http_headers` | status, redirect chain, headers, missing security headers | direct request |
| `shodan_internetdb` | open ports, hostnames, CPEs, known CVEs | Shodan InternetDB (free) |
| `email_security` | SPF, DMARC, MTA-STS, TLS-RPT, DKIM, graded A-F | DNS |
| `tls_certificate` | issuer, expiry, SANs, TLS version, why a cert is invalid | direct connection |
| `asn_lookup` | which AS announces an IP, who owns it, all its prefixes | RIPEstat |

Everything except `http_headers` and `tls_certificate` is passive, the target never sees your traffic. Those two just open a normal connection, same as visiting the site in a browser.

## Install

Needs Python 3.10+.

```
pip install osint-mcp-server
```

or if you use uv you don't need to install anything, just point the client at `uvx` (see below).

### Claude Desktop

Add this to `claude_desktop_config.json`:

```json
{
  "mcpServers": {
    "osint": {
      "command": "uvx",
      "args": ["osint-mcp-server"]
    }
  }
}
```

If you installed with pip, `"command": "osint-mcp-server"` with no args works too.

### Claude Code

```
claude mcp add osint -- uvx osint-mcp-server
```

Cursor, Windsurf etc. take the same JSON as Claude Desktop.

## Example prompts

- "run recon on example.com and tell me what stands out"
- "can someone spoof email from our domain? what should we fix first?"
- "which of these 20 domains have certificates expiring this month?"
- "what ip ranges does AS13335 announce?"
- "check the security headers on these 5 sites and tell me which are worst"
- "which of the subdomains of example.com resolve to something with open ports?"
- "what did example.com/about look like in 2015?"

## Caching

API responses (RDAP, crt.sh, Wayback, RIPEstat, InternetDB) are cached in sqlite for 6 hours at `~/.cache/osint-mcp/cache.sqlite3`, mostly so crt.sh doesn't get hammered. DNS, TLS and HTTP checks are always live.

```
OSINT_MCP_CACHE=off           # disable
OSINT_MCP_CACHE_TTL=3600      # seconds
OSINT_MCP_CACHE_PATH=/tmp/x.db
```

## Notes

- crt.sh and the Wayback CDX API are slow and return 502/503 pretty often. The server retries a couple of times but sometimes you just have to try again later.
- InternetDB isn't real-time and only has IPs Shodan has actually scanned.
- DKIM selectors can't be listed, `email_security` tries the common ones. Pass `dkim_selectors` if you know yours.
- `.ro`, `.de` and some other ccTLDs don't have public RDAP, so `domain_whois` can't do much for them.

## Development

```
git clone https://github.com/robyroro/osint-mcp
cd osint-mcp
pip install -e . pytest
pytest
```

Tests don't hit the network, HTTP calls are mocked.

To poke at it with the MCP inspector:

```
npx @modelcontextprotocol/inspector osint-mcp
```

## Be reasonable

This only pulls public data, but still: use it on your own stuff, bug bounty targets that are in scope, or for research. Don't use it to go after people.

## License

MIT © [Robert Vind-Gardoș](https://stratagency.ro/en/robert-vind-gardos) ([@robyroro](https://github.com/robyroro))

<!-- mcp-name: io.github.robyroro/osint-mcp -->
claudemcpmcp-serverosintpythonrecon

Lo que la gente pregunta sobre osint-mcp

¿Qué es robyroro/osint-mcp?

+

robyroro/osint-mcp es mcp servers para el ecosistema de Claude AI. MCP server with passive OSINT lookups: RDAP/whois, DNS, crt.sh subdomains, Wayback Machine, HTTP headers, Shodan InternetDB Tiene 0 estrellas en GitHub y su última actualización registrada es del 2026-10-01.

¿Cómo se instala osint-mcp?

+

Puedes instalar osint-mcp clonando el repositorio (https://github.com/robyroro/osint-mcp) o siguiendo las instrucciones del README en GitHub. ClaudeWave también te ofrece bloques de instalación rápida en esta misma página.

¿Es seguro usar robyroro/osint-mcp?

+

Nuestro agente de seguridad ha analizado robyroro/osint-mcp y le ha asignado un Trust Score de 95/100 (tier: Verified). Revisa el desglose completo de comprobaciones superadas y flags en esta página.

¿Quién mantiene robyroro/osint-mcp?

+

robyroro/osint-mcp es mantenido por robyroro. La última actividad registrada en GitHub es del 2026-10-01, con 0 issues abiertos.

¿Hay alternativas a osint-mcp?

+

Sí. En ClaudeWave puedes explorar mcp servers similares en /categories/mcp, ordenados por popularidad o actividad reciente.

Despliega osint-mcp en tu cloud

Lleva este repo a producción en minutos. Cada plataforma genera su propio entorno con variables de entorno editables.

¿Mantienes este repo? Añade un badge a tu README

Pega el badge en tu README de GitHub para mostrar que está auditado por ClaudeWave. Cada badge enlaza de vuelta a esta página y muestra el Trust Score actual.

Featured on ClaudeWave: robyroro/osint-mcp
[![Featured on ClaudeWave](https://claudewave.com/api/badge/robyroro-osint-mcp)](https://claudewave.com/repo/robyroro-osint-mcp)
<a href="https://claudewave.com/repo/robyroro-osint-mcp"><img src="https://claudewave.com/api/badge/robyroro-osint-mcp" alt="Featured on ClaudeWave: robyroro/osint-mcp" width="320" height="64" /></a>

Más MCP Servers

Alternativas a osint-mcp