Best AI Agent Skills for OSINT & Threat Intel in 2026
A. Frans
Published August 15, 2026
Table of Contents
Of the eight OSINT and threat-intelligence skills worth knowing about, six are marked unreviewed in our database. That's the highest unreviewed ratio of any skill category we track, and it's not an accident. This is offensive tooling, written by offensive-security people, distributed the way offensive-security people distribute things.
So this list comes with a rule attached: read the repo before you install. Not skim the README. Read what it shells out to.
With that said, the good ones are very good, and they collapse work that used to take an afternoon into a prompt.
The eight
| Skill | Author | Stars | Trust tier | Security status | Install type |
|---|---|---|---|---|---|
| Claude OSINT | elementalsouls | 2,290 | Community | Unreviewed | Skill |
| OSINT Cheat Sheet | Jieyab89 | 2,146 | Verified | Community-reviewed | Skill |
| Pentest AI | 0xSteph | 1,588 | Community | Unreviewed | MCP |
| LitterBox | BlackSnufkin | 1,514 | Verified | Community-reviewed | MCP |
| OpenOSINT | OpenOSINT | 1,399 | Community | Unreviewed | MCP |
| MCP Scanner | cisco-ai-defense | 1,030 | Community | Unreviewed | MCP |
| MCP Security Hub | FuzzingLabs | 758 | Community | Unreviewed | MCP |
| OSINT Tools MCP Server | frishtik | 229 | Community | Unreviewed | MCP |
Start with Claude OSINT
Claude OSINT is the one I'd install first, and it's the one whose source I'd read most carefully.
claude skill add elementalsouls/Claude-OSINT
It ships as two paired skills covering 90+ recon modules, 48 secret-regex patterns for credential hunting, and 80+ search dorks. The detail that matters: nine of its modules are read-only. That distinction is the whole game in OSINT tooling. A read-only module queries a public source. A non-read-only module touches the target.
If you're doing pre-engagement recon on a client who has signed a scope document, both are fine. If you're doing due diligence on a company you have no relationship with, only the read-only set is defensible.
Repo: github.com/elementalsouls/Claude-OSINT
The reference layer
OSINT Cheat Sheet isn't a tool. It's a hand-assembled corpus of tool lists, wikis, datasets, articles, and red-team references, packaged so your agent can reason over it.
claude skill add Jieyab89/OSINT-Cheat-sheet
This sounds unglamorous next to skills that run scans. It's the highest-value install on the list for most people. An agent that knows which tool applies to which question makes better decisions than an agent holding a hammer, and this skill is pure knowledge with no execution surface. It's also verified and community-reviewed, which makes it the safest thing here by a wide margin.
Repo: github.com/Jieyab89/OSINT-Cheat-sheet
The MCP servers that run things
Four entries on this list are MCP servers wrapping real offensive tooling. The security calculus changes completely once you cross that line.
Pentest AI is the most ambitious: 205 wrapped tools, 17 specialist agents, and 60 SPA-aware probes.
claude mcp add pentest-ai -- npx -y 0xSteph/pentest-ai
The SPA-aware probing is the interesting part. Traditional web scanners choke on single-page applications because there's nothing to crawl. The routes live in JavaScript. Probes built for that shape find things a 2015-era scanner walks straight past. It's unreviewed, it's 1,588 stars, and it will happily point 205 tools at whatever hostname is in your prompt. Scope discipline is on you.
MCP Security Hub from FuzzingLabs takes the same idea narrower: a growing collection of MCP servers exposing tools like Nmap and Ghidra to an assistant.
claude mcp add mcp-security-hub -- npx -y FuzzingLabs/mcp-security-hub
Ghidra access from an agent pays off on reverse-engineering work, where the tedium is navigation rather than insight. FuzzingLabs is a known name in the fuzzing world, which is worth something even at an unreviewed status.
OpenOSINT is smaller and better-behaved: 16 tools, with an interactive REPL, an MCP server, and a CLI. It works across Claude and other assistants.
claude mcp add OpenOSINT -- npx -y OpenOSINT/OpenOSINT
Sixteen tools instead of 205 means you can audit the whole surface in an evening. For anyone who wants OSINT capability without adopting a full offensive framework, this is the proportionate choice.
OSINT Tools MCP Server is the smallest at 229 stars, exposing multiple OSINT tools over MCP.
claude mcp add osint-tools-mcp-server -- npx -y frishtik/osint-tools-mcp-server
Low adoption cuts both ways. Fewer eyes on the code, but also a small enough codebase to review yourself.
The defensive two
Two entries here defend rather than attack, and they're the ones most readers should install.
MCP Scanner comes from Cisco's AI Defense group and scans MCP servers for threats and security findings.
claude mcp add mcp-scanner -- npx -y cisco-ai-defense/mcp-scanner
Read that capability twice against the rest of this article. You're being asked to install six unreviewed MCP servers with shell access. MCP Scanner is the thing that inspects them. Install it first, scan the others, then decide. A vendor security team publishing tooling that audits the category it sells into is a stronger signal than any star count on this page.
LitterBox is a sandbox for malware developers and red teamers to test payloads safely.
claude mcp add litterbox -- npx -y BlackSnufkin/LitterBox
Verified and community-reviewed. If your threat-intel work involves detonating samples, doing it inside a purpose-built sandbox rather than a VM you configured at 11pm is the difference between analysis and an incident.
The order I'd install these in
MCP Scanner, then OSINT Cheat Sheet, then one capability skill.
That ordering is deliberate. The scanner gives you a way to evaluate everything after it. The cheat sheet gives your agent judgment about which capability it needs. Only then does adding actual execution make sense, and you'll probably find that Claude OSINT or OpenOSINT covers your real work without the 205-tool framework.
The failure mode I see repeatedly: someone installs the biggest offensive framework first because it has the most impressive feature list, runs it against a target, and discovers afterward that "205 wrapped tools" included three that generated logged, attributable traffic they can't explain to a client.
How to read one of these repos in fifteen minutes
"Read the repo" is easy advice to give and vague enough to ignore. Here is what I check, in order, and it fits in a coffee break.
Find the shell-out points. Grep for child_process, subprocess, exec, spawn, and os.system. Every one is a place where the server hands your prompt to a program. Count them. If the number is large and the arguments are built by string concatenation from model output, you have found the risk.
Check what the target argument accepts. A well-built OSINT server validates that a target is a hostname or IP before it reaches a tool. A careless one passes the string straight through, which turns any command-injection bug in a wrapped tool into a bug in your machine.
Look for network calls that are not the scan. Telemetry, update checks, and "anonymous usage stats" in an offensive-security tool mean your target list is leaving your network. This is the single most common thing I find and the one most people never look for.
Read the install command word by word. npx -y accepts the package without prompting. That flag is convenience for you and a free pass for whatever the package publishes on its next version. Pin a version in production.
Check the commit history, not the star count. Three thousand stars and eleven months since the last commit describes a tool built against an API surface that has since moved. Recency beats popularity in this category, because the wrapped tools update constantly.
None of this makes an unreviewed skill safe. It makes it a known quantity, which is the most you get with community tooling.
The part about authorization
Every skill on this page can produce evidence of unauthorized access if pointed at the wrong host. An agent doesn't check whether you have a signed engagement letter.
Keep the scope in the prompt, keep the read-only and active modules separated, and log what the agent runs. If you can't produce a record of which tool touched which host at what time, you don't have an OSINT workflow. You have a liability with good autocomplete.
For the broader tooling picture, our full list for cybersecurity professionals covers the commercial platforms that sit alongside these skills.
FAQ
What's the difference between a skill and an MCP server here? Skills installed with claude skill add are instructions and knowledge loaded into context. MCP servers installed with claude mcp add run as processes and can execute commands. Three entries on this list are skills; five are MCP servers. The MCP servers carry the real risk.
Is "unreviewed" the same as unsafe? No. It means nobody in the community has published a security review. Most unreviewed skills are fine. The point is that you're the reviewer by default, so budget the time.
Can I run these against any public website? Passive collection from public sources is generally lawful in most jurisdictions. Active scanning and probing usually is not, without written authorization. The tools don't enforce this distinction and neither does the agent.
Which single skill gives the most value for the least risk? OSINT Cheat Sheet. It's verified, community-reviewed, has no execution surface, and makes every other tool you use more effective by improving the agent's tool selection.
Should I install MCP Scanner even if I'm not doing security work? Yes, if you install community MCP servers of any kind. Its usefulness has nothing to do with whether your job is security. It has to do with whether you run code from strangers.
Share this article
📄Related Articles
The Risk of Installing Community Skills (And How to Reduce It)
7 min read
A Practical Security Checklist for Claude Skills
8 min read
Best AI Tools for Cybersecurity Professionals in 2026
9 min read
Best AI Agent Skills for Cybersecurity Professionals in 2026
10 min read
How to Audit a Claude Skill Before Installing in 2026
9 min read
Get More AI Tool Guides
New comparisons and guides every week. Join thousands of professionals staying ahead of the AI curve.