No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by assafkip · Agent Tool · ★ 68
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is kipi safe to install? View the security audit →
kipi Drop a dense intel report on it. Get a live, investigated entity graph. The graph above built itself. One seed domain went in. An agent pulled WHOIS, DNS, certificates, and the live sites, then pivoted on what it found. No queries to write. Watch the full 75 seconds, with sound. kipi is an open-source, self-hosted OSINT investigation platform. It turns documents into an investigation. PDFs, screenshots, spreadsheets, pasted notes go in. A typed entity graph comes out. Then an autonomous investigator digs the open web and builds the graph out in front of you: infrastructure pivots, typed edges, gated findings, a written brief. The analyst stays the top authority. Every schema, finding, and edge gets confirmed, corrected, or rejected by a human. The machine proposes. You decide. Two things sit together here that I never found in one commercial OSINT platform: document ingestion into entities, and real graph analytics (centrality, communities, pathfinding) on the same investigation canvas. What you're watching The demo runs a real case. Two seed domains go in: and . By the end, kipi has mapped a Russian-language affiliate fraud network. White-label fake crypto casinos.
| Stars | 68 |
| Forks | 12 |
| Language | Python |
| Category | Agent Tool |
| Quality Score | 56.8365483162987/100 |
| Open Issues | 2 |
| Last Updated | 2026-09-05 |
| Created | 2026-06-10 |
| Platforms | python |
| Est. Tokens | ~15k |
These tools work well together with kipi for enhanced workflows:
Looking for a kipi alternative? If you're comparing kipi with other agent tool tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.
Agentic memory for CTI in Python — STIX knowledge graphs, threat-actor alias resolution, offline-first RAG, MC
Self-hosted framework for orchestrating fleets of specialist AI agents — ensemble reasoning and a full agentic
Your Digital Companion. Self-hosted Telegram bot orchestrating multiple AI providers (OpenAI, Anthropic, Googl
Provide AI agents with full Tor network access and dark web data through a zero-config OpenClaw skill or stand
Polymcp provides a simple and efficient way to interact with MCP servers using custom agents
Build AI-powered security tools. 50+ hands-on labs covering ML, LLMs, RAG, threat detection, DFIR, and red tea
Explore other popular agent tool tools:
kipi is Open-source, self-hosted OSINT investigation platform: turn documents into a live, investigated entity graph. Autonomous agent, graph analytics (centrality, communities, pathfinding), keyless-first to. It is categorized as a Agent Tool with 68 GitHub stars.
kipi is primarily written in Python. It covers topics such as ai-agent, anthropic, cybersecurity.
You can find installation instructions and usage details in the kipi GitHub repository at github.com/assafkip/kipi. The project has 68 stars and 12 forks, indicating an active community.
The top alternatives to kipi on Agent Skills Hub include zettelforge, captain-claw, chibi. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: