Is OpenOSINT MCP server safe?
Probably. Read the findings first.
Use with care. Some checks failed or could not be verified.
What to know before installing
- highNetwork call to a paste/tunnel/webhook host
Public scan report
scanner v0.1.8 · 2026-09-19 · same rubric, same numbers if you re-run it
1 high
- Code scan86 source files scanned13/25
- –Live reliabilityno gateway calls yet and no remote to proben/a
- –Tool poisoningtools not inspected (local package is not executed); not countedn/a
- Auth qualitystatic API keys via environment variables6/15
- Maintenancelast push 1 days ago15/15
- Maintainer identityregistry namespace matches repository owner7/10
Findings (1)
- highNetwork call to a paste/tunnel/webhook host
net.suspicious-hostopenosint-2.29.0/openosint/tools/search_paste.py: …known date") lines.append(f"[+] https://pastebin.com/{paste_id} ({date})") if count > _M…
Overall 63/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON
Other servers that do what OpenOSINT does
- Apixies Developer API Suite50 developer utility APIs as tools: SSL, DNS, WHOIS, email checks, HTML to PDF, sitemaps and more.not reviewedGrowingB
- NetintelMCP server for NetIntel — DNS, SSL, WHOIS, email security, OSINT via x402 micropaymentsnot reviewedGrowingB
- Penniless Data UtilitiesTen x402-paid tools for JSON, YAML, cron, diff, text, DNS, WHOIS, GitHub, crypto, and email.not reviewedGrowingB