build-small-hackathon/OSINTAgentTool
๐ OSINT Threat Analyst
An agentic multi-source open-source intelligence (OSINT) briefing tool that autonomously gathers, fuses, and synthesizes geopolitical conflict data into structured threat assessments โ powered by a domain-specific fine-tuned model and real-time web search.
Links
Dataset: https://huggingface.co/datasets/Firemedic15/TravelRiskData
Model: https://huggingface.co/Firemedic15/qwen25-1.5B-travel-risk-analysis-merged
Youtube Demo: https://youtu.be/7wUZ_K2XoxI
Social Media (x.com): https://x.com/Phreakaz0id/status/2066264751789736093
Blog Post: https://huggingface.co/blog/Firemedic15/osint-agent
GGUF Version (Ollama downloadable): https://huggingface.co/Firemedic15/Qwen2.5Risk1.5B (Quantized version available)
Team:
- Firemedic15
What It Does
Select a country or region, choose your news sources, and click Run Analysis. The agent fans out across live data sources, synthesizes the picture, and returns a structured threat brief covering:
- Severity rating and confidence level
- Recent armed conflict events (ACLED)
- Real-time news headlines (Tavily + RSS)
- State Department travel advisory level
- Airspace restrictions
- Embassy and consulate contacts for your passport country
A raw agent trace tab exposes every tool call and model step for full auditability.
Architecture
This Space demonstrates a context-aware agentic analyst loop backed by a fine-tuned domain model:
User Query
โ
โผ
smolagents ToolCallingAgent
โ
โโโ fetch_acled_events โ Structured conflict event data (ACLED API)
โโโ fetch_rss_headlines โ Open-source reporting (30+ RSS feeds)
โโโ tavily_search โ Real-time web search (Tavily API)
โโโ fetch_travel_advisory โ State Dept advisory level + notes
โโโ fetch_airspace_status โ NOTAM / airspace restriction data
โโโ list_available_sources โ Source inventory
โ
โผ
Modal REST Endpoint
(Firemedic15/qwen25-1.5B-travel-risk-analysis-merged)
โ
โผ
Structured Threat Brief (HTML + PDF export)The inference backend is a Qwen2.5-1.5B model fine-tuned on domain-specific travel risk data, hosted on Modal with an A10G GPU. The Space itself is CPU-only โ all model weight stays off HuggingFace compute.
Tavily provides real-time web search results that fill the gap between ACLED's structured event data and RSS headline coverage, capturing breaking developments and primary-source reporting that feeds don't yet index.
Data Sources
30+ RSS sources are available in the source selector. Select any combination per query.
Model
Inference is handled by [Firemedic15/qwen25-1.5B-travel-risk-analysis-merged](https://huggingface.co/Firemedic15/qwen25-1.5B-travel-risk-analysis-merged) โ a Qwen2.5-1.5B-Instruct model fine-tuned on the Firemedic15/Travel_Risk_Data dataset covering country-level risk assessments, conflict event summaries, advisory reasoning, and structured threat brief generation.
The model is served via a Modal REST endpoint (A10G GPU, serverless, scales to zero). GGUF quantized versions for local use are available at Firemedic15/Qwen2.5_Risk_1.5B.
Setup (Self-Hosting)
Set the following Space secrets under Settings โ Variables and Secrets:
Required
Optional
Research Context
This tool operationalizes the context-aware agentic security analyst architecture explored in ongoing research on converged physical/cyber security intelligence operations. The agentic loop pattern โ autonomous tool selection, multi-source ingestion, real-time search augmentation, and structured synthesis โ mirrors the design described in supporting academic work targeting Computers & Security and Journal of Cybersecurity.
Key contributions demonstrated here:
- Domain fine-tuning at small scale โ A 1.5B parameter model, fine-tuned on structured risk data, handles threat synthesis without relying on frontier model API access
- Real-time augmentation โ Tavily search grounds the model in current events beyond its training cutoff
- Multi-source fusion โ Structured (ACLED), unstructured (RSS), and live (Tavily) data are co-analyzed in a single agent loop
- Transparent reasoning trace โ Every tool call and model step is logged for analyst oversight and auditability
- Serverless GPU inference โ Modal backend scales to zero cost when idle; no always-on GPU expense
Swap the inference backend
The ModalModel class in app.py is a thin wrapper around a POST endpoint. To swap backends, change MODAL_ENDPOINT to any endpoint that accepts {"prompt": "...", "max_new_tokens": N} and returns {"response": "..."}.
Stack
Related Resources
Disclaimer
โ ๏ธ AI-generated from open sources. Not for operational use without independent verification. ACLED data is third-party and subject to their terms of use. Tavily results reflect public web content at time of query. Threat assessments produced by this tool are a starting point for analyst review, not a finished intelligence product.
