User-Scanner Development Roadmap: Strategic Priorities for the OSINT Engine
The user-scanner development roadmap prioritizes expanding the 465+ vector module ecosystem, enhancing async concurrency in the orchestrator, deepening AI integrations through Model Context Protocol (MCP), and adding enterprise export formats while maintaining rigorous security standards.
The kaifcodec/user-scanner repository is a mature, production-ready OSINT suite currently at version 1.5.1.1. While the project does not maintain a standalone roadmap file, its architectural patterns in user_scanner/core/ and module organization reveal a clear strategic trajectory focused on scalability, AI interoperability, and developer experience.
Current Architecture Foundation
The user-scanner engine currently supports over 465 investigation vectors, including approximately 175 email-scan modules and 290 username-scan modules distributed across user_scanner/user_scan/ and user_scanner/email_scan/. The architecture centers on a concurrent processing core implemented in user_scanner/core/orchestrator.py, which provides ThreadPoolExecutor management and validation helpers like generic_validate and impersonate_validate.
Cross-scan intelligence operates through user_scanner/core/cross_scan.py, implementing graph-based pivot logic documented in docs/CROSS_SCAN.md. Export capabilities reside in user_scanner/core/pdf_generator.py and user_scanner/core/formatter.py, supporting PDF, JSON, and CSV outputs. The continuous integration pipeline in .github/workflows/ validates changes across the entire module library.
Core Development Priorities
Module Ecosystem Expansion
The roadmap emphasizes continuous expansion of the platform coverage library. New validators for emerging social networks and developer services will join the existing 465+ modules, while broken or deprecated modules move to a dedicated abandoned/ directory. Contributors should follow the skeleton pattern demonstrated in CONTRIBUTING.md, utilizing the Result object from user_scanner/core/result.py and the generic_validate helper from core/orchestrator.py.
Concurrency Engine Enhancements
Future releases will evolve the parallel execution model in user_scanner/core/engine.py and core/orchestrator.py to support dynamic worker scaling based on runtime load rather than static pools. Additionally, the impersonate_validate function will receive more granular TLS fingerprint profiles to enhance stealth capabilities during high-volume scans.
Cross-Scan Intelligence and Pivoting
The --cross-scan functionality, currently implemented in core/cross_scan.py, will advance toward multi-hop graph-based pivoting capabilities. Confidence scoring algorithms in core/confidence.py will undergo refinement to provide more nuanced probability assessments when correlating identities across disparate platforms.
AI Agent Integration via MCP
The user-scanner-mcp server represents the project's entry point for Model Context Protocol integration. Roadmap items include expanding the AI agent toolset with new descriptors and implementing streaming interfaces that push real-time scan results to LLM consumers without blocking the orchestration pipeline.
Export Format Diversification
Beyond the current PDF, JSON, and CSV exporters in core/pdf_generator.py and core/formatter.py, the development trajectory includes native HTML and Markdown generation. Enterprise users can expect custom templating capabilities that allow branded report generation with embedded media and structured metadata.
Network Resilience and Proxy Management
While the current implementation supports proxy rotation and health checks via --validate-proxies (documented in docs/FLAGS.md), the roadmap targets automatic proxy pool refresh mechanisms and intelligent fallback strategies when network failures occur during async validation cycles.
Developer Experience and Documentation
The project plans to migrate from static markdown documentation to interactive web-based resources, potentially using MkDocs for searchable API references. Auto-generated documentation from Python type-hints will supplement the existing guides in docs/USAGE.md and docs/FLAGS.md.
Security Auditing and Compliance
Security enhancements focus on static analysis integration to detect secret leakage in the 465+ modules and comprehensive auditing of third-party API key usage. The existing rate-limit handling and CSRF token management patterns will serve as the foundation for automated compliance checking in CI pipelines.
Extending the Engine: Practical Implementation
Developers contributing to the roadmap can implement new username validators using the established pattern in user_scanner/core/orchestrator.py. The following skeleton demonstrates the required structure:
# user_scanner/user_scan/social/newsite.py
from user_scanner.core.result import Result
from user_scanner.core.orchestrator import generic_validate
def validate_newsite(user: str) -> Result:
url = f"https://newsite.com/{user}"
show_url = f"https://newsite.com/{user}"
def process(resp):
if resp.status_code == 404:
return Result.available()
if resp.status_code == 200 and "profile-header" in resp.text:
return Result.taken(extra={"display_name": user})
return Result.error("Unexpected response")
return generic_validate(url, process, show_url=show_url)
For programmatic access to the engine, applications can leverage the async interface in user_scanner/core/engine.py:
import asyncio
from user_scanner.core import engine
from user_scanner.user_scan.social.github import validate_github
async def main():
result = await engine.check(validate_github, "octocat")
print(result.to_json())
asyncio.run(main())
CLI users can execute comprehensive investigations using the cross-scan capability. The CLI parsing logic in user_scanner/cli/__init__.py forwards the -u flag to core/engine.check() for concurrent execution:
user‑scanner -u johndoe --cross‑scan
Summary
- The user-scanner project maintains an implicit roadmap focused on ecosystem growth rather than a static document, targeting module expansion and architectural refinement.
- Key file locations include
user_scanner/core/orchestrator.pyfor concurrency,core/cross_scan.pyfor pivot logic, andcore/pdf_generator.pyfor reporting. - Future development prioritizes dynamic scaling of the
ThreadPoolExecutor, MCP streaming capabilities for AI agents, and multi-hop graph analysis in cross-scan operations. - Security roadmap items include static analysis integration and automated secret detection across the 465+ OSINT vectors.
- Contributors add functionality by implementing validators using
generic_validateand following patterns established inCONTRIBUTING.md.
Frequently Asked Questions
Does user-scanner maintain a public roadmap document?
No, the kaifcodec/user-scanner repository does not contain a dedicated roadmap file. Instead, strategic priorities emerge from the codebase structure in user_scanner/core/, recent commit history, and architectural patterns supporting 465+ scan vectors. Development focus areas can be inferred from the modular design and explicit extension points in CONTRIBUTING.md.
How can I contribute new scan modules to the project?
Contributors should implement validators in the appropriate subdirectory of user_scanner/user_scan/ or user_scanner/email_scan/, utilizing the Result class from user_scanner/core/result.py and the generic_validate helper from user_scanner/core/orchestrator.py. The validator function must accept a username string and return a Result object indicating availability, ownership, or error states. See CONTRIBUTING.md for coding standards and testing requirements.
What is MCP integration in user-scanner?
MCP (Model Context Protocol) integration exposes the scanner's capabilities to AI agents through the user-scanner-mcp server component. This allows large language models to invoke OSINT investigations as tools, receiving structured JSON results from the engine. The roadmap includes expanding the MCP toolset descriptors and implementing real-time streaming of partial scan results to LLM consumers.
Which file controls the concurrent execution of scans?
The primary concurrency controller is user_scanner/core/orchestrator.py, which manages the shared ThreadPoolExecutor and provides request handling utilities like generic_validate and impersonate_validate. High-level async orchestration occurs in user_scanner/core/engine.py, which coordinates execution across the 465+ modules while managing rate limiting and retry logic.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →