sh.clearfront/clearfront MCP Server
sh.clearfront/clearfront
AI-powered OSINT agent: scan digital footprints across 3,400+ public data sources in one sweep.
What is the sh.clearfront/clearfront MCP server?
Clearfront is an open-source OSINT agent that investigates digital footprints by scanning 3,400+ public data sources for breaches, accounts, data brokers, domains, and IPs. It exposes 30 modular tools via an interactive REPL, CLI, web console, MCP server, or agent skill, powered by Claude, Ollama, or any OpenAI-compatible endpoint.
Clearfront automates open-source intelligence gathering on emails, usernames, domains, IPs, and names. It chains multiple reconnaissance tools—breach databases, username enumeration, subdomain discovery, WHOIS, Shodan, VirusTotal, GitHub, DNS, and more—into a single AI-driven investigation. Run it locally with your own API keys; nothing is sent to external servers. Ideal for security researchers, penetration testers, and anyone auditing their own digital exposure.
How to install sh.clearfront/clearfront
Copy-paste configuration for popular MCP clients.
HIBP_API_KEYsecretHave I Been Pwned API key, enables breach and paste lookups
IPINFO_TOKENsecretipinfo.io token, enables IP geolocation and exposure reports
SHODAN_API_KEYsecretShodan API key, enables internet-exposed device lookups
VIRUSTOTAL_API_KEYsecretVirusTotal API key, enables reputation checks on IPs, domains, URLs and file hashes
ANTHROPIC_API_KEYsecretAnthropic API key, only needed for the AI-assisted multi-target sweep tool
Tools & capabilities
Tools this server exposes to the agent.
search_email— Enumerate social accounts linked to an email address via holehesearch_username— Check username presence across 300+ platforms via sherlocksearch_breach— Query data breach exposure via HaveIBeenPwned v3 APIsearch_whois— Retrieve domain registrant and DNS info via python-whoissearch_ip— Geolocate and profile an IP (ASN, hostname) via ipinfo.iosearch_domain— Enumerate subdomains via sublist3rsearch_crt— Discover subdomains from certificate transparency logs (crt.sh)search_wayback— Recover historical/deleted URLs from Internet Archivesearch_greynoise— Check if an IP is mass-scanner noise vs. targeted actor (GreyNoise Community)generate_dorks— Generate 12 targeted Google dork URLs for reconnaissancesearch_paste— Search pastebin dump mentions via psbdmp.wssearch_phone— Retrieve phone carrier, country, and line type via phoneinfogasearch_shodan— Query open ports, banners, and CVEs via Shodan APIsearch_virustotal— Check file/URL verdicts from 70+ antivirus engines via VirusTotal APIsearch_ip2location— Enhanced IP intelligence (VPN/Proxy/Tor/datacenter flags) via IP2Location.iosearch_censys— Discover internet-facing infrastructure and certificates via Censys Search APIsearch_abuseipdb— Check IP abuse reputation and reports via AbuseIPDB v2search_github— Profile GitHub users, repos, and discover exposed emails/secretssearch_dns— Query DNS records (A/AAAA/MX/NS/TXT/CNAME/SOA) and analyze SPF/DMARC/DKIMsearch_dorks_live— Execute live Google search for dork queries via Bright Data SERP API
Use cases
- Audit your own digital footprint: find which accounts, breaches, and data brokers expose your email or username.
- Investigate a domain or IP during a penetration test: discover subdomains, open ports, historical URLs, and associated infrastructure.
- Perform rapid OSINT on a target during authorized security research: correlate findings across breach databases, social platforms, and public records.
- Identify infostealer exposure and compromised credentials for an email or username without accessing plaintext dumps.
- Generate and execute Google dorks to surface unintended public exposure of a domain or organization.
sh.clearfront/clearfront MCP server FAQ
Clearfront is an open-source OSINT agent that scans 3,400+ public data sources to investigate digital footprints. It automates reconnaissance across breaches, accounts, domains, IPs, and names, then compiles findings into a calibrated report with an interactive evidence graph.
Yes. Clearfront is MIT-licensed and open-source. It runs locally with your own API keys (Anthropic, Shodan, VirusTotal, etc.). Many tools work without paid keys; optional keys unlock enhanced rate limits and additional data sources.
For Claude Desktop, add it to `~/Library/Application Support/Claude/claude_desktop_config.json` as an MCP server pointing to the `mcp_server.py` script. For Claude Code, run `claude mcp add clearfront python /path/to/mcp_server.py`. For Cursor, use the Agent Skills standard: `npx skills add scottmartinanderson/clearfront` (also install `pip install clearfront`).
Clearfront requires an AI backend: either an Anthropic API key (default), a local Ollama model (free, offline), or an OpenAI-compatible endpoint. Optional API keys for Shodan, VirusTotal, HaveIBeenPwned, and other data sources unlock additional tools; many tools work without them.
Clearfront is for legal and authorized use only. Users are solely responsible for ensuring compliance with all applicable laws and regulations. Investigate only targets you own or have explicit permission to investigate. See DISCLAIMER.md in the repository.
Yes. Use a local Ollama model as the AI backend (`--provider ollama`) and skip optional API keys. Many tools (DNS, WHOIS, local EXIF extraction) work without network calls. Tools requiring external APIs (Shodan, VirusTotal, breach databases) will return errors if keys are absent.
README (reference)
Source of truth, from the repository.
- 30 modular tools, email, username (sherlock + WhatsMyName), broad username discovery across 3,400+ sites (maigret), search-based footprint discovery, IP, IP self-exposure report, domain, WHOIS, breach, Gravatar profile, EmailRep reputation, phone, paste, EXIF/GPS metadata, Shodan, VirusTotal, Censys, IP2Location, AbuseIPDB, GitHub (profile + public code/secret exposure), DNS, subdomain discovery via certificate transparency (crt.sh), historical URL recovery via the Wayback Machine (Internet Archive), mass-scan visibility (GreyNoise Community), infostealer-exposure check (Hudson Rock, free tier, no plaintext credentials), dork generation, live dork search, URL scraping, BTC/ETH address lookup, and passive domain recon (theHarvester)
- MCP server built in, expose all 30 tools natively to Claude Code, Claude Desktop, and any MCP-compatible client
- Three AI backends, Anthropic Claude (default), local Ollama, or any OpenAI-compatible endpoint; tool results come from real subprocess calls, never hallucinated
- Fully async, parallel tool execution via
asyncio.gather()with hard subprocess timeouts - MIT licensed, no embedded LLM; bring your own API key or run fully offline
Legal Disclaimer: Clearfront is intended for legal and authorized use only. Users are solely responsible for ensuring their use complies with all applicable laws and regulations. The authors accept no liability for misuse. See DISCLAIMER.md.
What is Clearfront?
Clearfront is an AI agent for Open Source Intelligence with five interfaces: an interactive terminal REPL, a direct CLI, a browser-based web console, an MCP server exposable to Claude Code, Claude Desktop or any MCP-compatible client, and an agent skill for any client following the Agent Skills standard. The AI layer uses Anthropic's native tool use API (or a local Ollama model, or any OpenAI-compatible endpoint): the model issues hard stops when it needs a tool, your code executes the real binary, the actual output goes back, hallucination in tool results is structurally impossible.
Installation
pip install clearfront
Or from source, if you want to modify it:
git clone https://github.com/scottmartinanderson/clearfront
cd clearfront
pip install -e .
External binaries (must be in PATH):
| Binary | Purpose | Install |
|---|---|---|
holehe | Email account enumeration | pip install holehe |
sherlock | Username enumeration (300+ platforms) | pip install sherlock-project |
sublist3r | Subdomain enumeration | pip install sublist3r |
phoneinfoga | Phone number intelligence | Download binary |
theHarvester | Passive domain recon (emails/subdomains) | pip install git+https://github.com/laramies/theHarvester.git |
If a binary is absent, the corresponding tool returns a descriptive error string. All other tools remain operational.
Quick Start
# Interactive AI REPL (default)
clearfront
# Web interface
clearfront web
# Direct tool (no AI)
clearfront email target@example.com
Configuration
Store all keys in a .env file at the project root (copy .env.example). python-dotenv loads it automatically at startup.
| Variable | Tool | Required | Purpose |
|---|---|---|---|
ANTHROPIC_API_KEY | AI agent | Yes (or use Ollama / OpenAI) | Anthropic API key |
OPENAI_BASE_URL | AI agent | Optional | Base URL of an OpenAI-compatible endpoint (e.g. http://localhost:4000/v1). When set and ANTHROPIC_API_KEY is absent, it is used as the AI backend (takes precedence over Ollama). The model must support tool/function calling. |
OPENAI_API_KEY | AI agent | Optional | API key for the OpenAI-compatible endpoint (local servers may ignore it) |
OPENAI_MODEL | AI agent | Optional | Model name to request from the endpoint (default: gpt-4o-mini) |
HIBP_API_KEY | search_breach | Optional | HaveIBeenPwned v3, get one |
IPINFO_TOKEN | search_ip | Optional | ipinfo.io higher rate limits |
SHODAN_API_KEY | search_shodan | Optional | Shodan API, get one |
VIRUSTOTAL_API_KEY | search_virustotal | Optional | VirusTotal API v3, get one |
IP2LOCATION_API_KEY | search_ip2location | Optional | IP2Location.io enhanced IP intelligence, get one |
CENSYS_PAT + CENSYS_ORG_ID | search_censys | Optional | Censys Platform API: Personal Access Token + Organization ID, get one |
ABUSEIPDB_API_KEY | search_abuseipdb | Optional | AbuseIPDB v2, get one |
GITHUB_TOKEN | search_github | Optional | GitHub API, raises rate limit from 60 to 5000 req/h, get one |
SERPER_API_KEY | search_dorks_live, search_footprint | Optional | Serper.dev Google SERP API, the preferred SERP backend (~$1/1k, 2,500 free), get one. |
BRIGHTDATA_API_KEY | search_dorks_live, scrape_url | Optional | Bright Data API key, get one (free tier: 5,000 req/month). |
BRIGHTDATA_SERP_ZONE | search_dorks_live | Optional | Your Bright Data SERP API zone name (e.g. serp_api1). |
BRIGHTDATA_UNLOCKER_ZONE | scrape_url | Optional | Your Bright Data Web Unlocker zone name (e.g. web_unlocker1). |
The Bright Data link above is a referral link; signing up through it supports Clearfront at no extra cost to you.
Optional Python packages:
| Package | Purpose | Install |
|---|---|---|
ollama | Local LLM backend (no API key) | pip install ollama (also install the Ollama runtime) |
openai | OpenAI-compatible backend for the REPL/CLI (--provider openai) | pip install "clearfront[openai]" |
shodan | Shodan API client | pip install shodan |
reportlab | PDF report export | pip install reportlab |
censys | Censys API client | pip install censys |
Tools
| Tool | Powered by | What it investigates |
|---|---|---|
search_email | holehe | Social accounts linked to an email address |
search_username | sherlock | Username presence across 300+ platforms |
search_breach | HaveIBeenPwned v3 API | Data breach exposure |
search_whois | python-whois | Domain registrant and DNS info |
search_ip | ipinfo.io | Geolocation, ASN, hostname |
search_domain | sublist3r | Subdomain enumeration |
search_crt | crt.sh | Subdomains from certificate transparency (keyless, passive) |
search_wayback | Internet Archive | Historical/deleted URLs archived under a domain (keyless, passive) |
search_greynoise | GreyNoise Community | Mass-scanner noise vs. targeted actor for an IP (free, 50/week) |
generate_dorks | built-in | 12 targeted Google dork URLs (no network calls) |
search_paste | psbdmp.ws | Pastebin dump mentions |
search_phone | phoneinfoga | Carrier, country, line type |
search_shodan | Shodan API | Open ports, banners, CVEs |
search_virustotal | VirusTotal API v3 | Verdict from 70+ antivirus engines |
search_ip2location | IP2Location.io API | Enhanced IP intel: VPN/Proxy/Tor/datacenter flags |
search_censys | Censys Search API | Internet-facing infrastructure, certificates |
search_abuseipdb | AbuseIPDB v2 API | IP abuse reputation: confidence score, reports, country, ISP |
search_github | GitHub REST API | Profile, repos, commit-discovered emails, username/keyword search |
search_dns | dnspython (built-in) | A/AAAA/MX/NS/TXT/CNAME/SOA records; SPF, DMARC, DKIM analysis |
search_dorks_live | Bright Data SERP API | Live Google search results for dork queries (title, URL, snippet) |
scrape_url | Bright Data Web Unlocker | Fetch any URL bypassing Cloudflare/CAPTCHA, returns clean Markdown |
search_maigret | maigret | Username presence across 3,400+ sites |
search_footprint | SERP (Serper / Bright Data / DuckDuckGo) | Search-based footprint discovery for a name or handle |
search_gravatar | Gravatar API | Public Gravatar profile for an email: avatar, display name, linked accounts |
search_emailrep | EmailRep.io | Email reputation and footprint summary |
search_hudsonrock | Hudson Rock Cavalier (free) | Infostealer-exposure check for an email or username (no plaintext credentials) |
search_exif | exiftool | EXIF / IPTC / XMP metadata and embedded GPS from a local file |
search_crypto | public chain APIs | Bitcoin / Ethereum address summary: balance, transaction count |
search_harvester | theHarvester | Passive domain recon: emails, subdomains, hosts |
search_exposure | built-in (composite) | Self-exposure report for an IP across the infrastructure tools |
Interfaces
Interactive REPL
Run clearfront with no arguments to start the AI-powered REPL. Type a target (email, username, domain, IP, name) or a question; the agent decides which tools to run, chains them on findings, and compiles a report.
REPL commands: <target>, clear, save, tools, config, history, help, exit / Ctrl-D.
All sessions are auto-saved to ~/.clearfront/history/. Browse with clearfront history.
Web UI
pip install "clearfront[web]"
clearfront web
# Opens http://localhost:8080 automatically
Browser-based AI chat with streaming tool output, inline result cards, and a light/dark theme toggle. Supports fully local inference via Ollama or any OpenAI-compatible endpoint (no Anthropic API key required when using a local backend).
The console runs entirely locally and binds to 127.0.0.1 by default. Choose your backend and paste your own key in Settings; your keys and the targets you investigate never touch our servers. Screenshots are in media/.
MCP Server
Expose all 30 tools to any MCP-compatible AI client.
Claude Code:
claude mcp add clearfront python /absolute/path/to/clearfront/mcp_server.py
claude mcp list
Claude Desktop, add to ~/Library/Application Support/Claude/claude_desktop_config.json:
{
"mcpServers": {
"clearfront": {
"command": "python",
"args": ["/absolute/path/to/clearfront/mcp_server.py"]
}
}
}
Agent Skill
skills/clearfront-osint teaches an agent
how to drive Clearfront: which approach fits a given request, the direct
subcommands, how to read the confidence ratings, and the authorized-use rules.
It follows the Agent Skills open standard, so it works
in Claude Code, Cursor, Codex, Copilot, VS Code, Gemini, Windsurf, Zed and the other
skills-compatible clients.
npx skills add scottmartinanderson/clearfront
Install Clearfront itself as well (pip install clearfront); the skill is the
instructions, not the tool. Use the skill when you want the agent to decide how
to run a sweep, and the MCP server above when you want it calling the 30 tools
directly.
Docker
docker compose up --build
docker compose run --rm clearfront email target@example.com --json
Set ANTHROPIC_API_KEY (and optionally HIBP_API_KEY, IPINFO_TOKEN) in a .env file or export them before running. Reports persist to ./reports/ via a volume mount.
CLI Reference
| Flag / Subcommand | Description |
|---|---|
clearfront | Interactive AI REPL (default) |
clearfront web [--port N] [--no-browser] | Launch browser UI |
clearfront email ADDRESS [-t N] | Direct email scan |
clearfront username HANDLE [-t N] | Direct username scan |
clearfront shodan QUERY [-t N] | Shodan lookup |
clearfront virustotal TARGET [-t N] | VirusTotal lookup |
clearfront censys TARGET [-t N] | Censys lookup |
clearfront ip2location IP [-t N] | IP2Location lookup |
clearfront abuseipdb IP [-t N] | AbuseIPDB reputation check |
clearfront github QUERY [-t N] | GitHub profile/repo/email discovery |
clearfront dns DOMAIN [-t N] | DNS records + email security analysis |
clearfront multi TARGETS | Parallel multi-target investigation (max 10) |
clearfront graph TARGET [-o PATH] [--format graphml|json|mermaid|all] | Auto-pivot and export the entity correlation graph (GraphML/JSON/Mermaid) |
clearfront history [--all] [open N] [clear] | View/manage REPL session history |
-v, --verbose | Enable debug logging to stderr |
-t, --timeout N | Override subprocess timeout (seconds) |
--api-key KEY | Anthropic API key (overrides env var) |
--parallel | Run complementary tools concurrently |
--json | Output results as structured JSON |
-o, --output FILE | Write results to FILE instead of stdout (raw; combine with --json for a JSON file) |
--provider {anthropic,ollama,openai} | AI provider (default: anthropic) |
--ollama-model MODEL | Ollama model name (default: llama3.2) |
--ollama-host URL | Ollama server URL (default: http://localhost:11434) |
--openai-base-url URL | OpenAI-compatible endpoint base URL (env: OPENAI_BASE_URL) |
--openai-model MODEL | Model to request from the endpoint (env: OPENAI_MODEL) |
--openai-api-key KEY | API key for the endpoint (env: OPENAI_API_KEY) |
--no-pdf | Disable automatic PDF generation |
Contributing
Issues and pull requests are welcome. See CONTRIBUTING.md for the development workflow and coding conventions. Please read DISCLAIMER.md before contributing.
License
Clearfront is open source under the MIT License.
The bundled username dataset clearfront/tools/data/wmn-data-unique.json is a filtered
adaptation of the WhatsMyName project
by Micah Hoffman, used under the CC BY-SA 4.0
license; that file (and adaptations of it) remains under CC BY-SA 4.0. See
clearfront/tools/data/NOTICE.
For authorized security research only. See DISCLAIMER.md.
Related MCP servers

sh.clearhouse/clearhouse
One search across every agent registry: 100K+ MCP/A2A/x402 services, signed receipts.

Clearly
Find and manage Clearly workspace docs, canvases, sheets, decks, projects, boards, and tickets.
Ship production-ready TypeScript code in half the time, at half the cost.
Score your copy instantly and access 560+ guides on persuasion, hooks, and sales writing.
Your sales pipeline as tools: deals by stage, playbook tasks, contacts, companies, and timeline.
Physics-based validation of simulation results: receipts with per-check verdicts, via MCP.