A newer version of the Gradio SDK is available: 6.20.0
title: OSINT Threat Analyst
emoji: π
colorFrom: indigo
colorTo: blue
sdk: gradio
sdk_version: 5.23.0
app_file: app.py
pinned: false
license: apache-2.0
tags:
- track:backyard
- sponsor:modal
- achievement:offgrid
- achievement:welltuned
- achievement:offbrand
- achievement:llama
- achievement:sharing
- achievement:fieldnotes
- osint
- security
- geopolitics
- threat-intelligence
- agentic
- smolagents
- conflict-analysis
- travel-risk
- nlp
π OSINT Threat Analyst
An agentic multi-source open-source intelligence (OSINT) briefing tool that autonomously gathers, fuses, and synthesizes geopolitical conflict data into structured threat assessments β powered by a domain-specific fine-tuned model and real-time web search.
Links
Dataset: https://huggingface.co/datasets/Firemedic15/Travel_Risk_Data
Model: https://huggingface.co/Firemedic15/qwen25-1.5B-travel-risk-analysis-merged
Youtube Demo: https://youtu.be/7wUZ_K2XoxI
Social Media (x.com): https://x.com/Phreakaz0id/status/2066264751789736093
Blog Post: https://huggingface.co/blog/Firemedic15/osint-agent
GGUF Version (Ollama downloadable): https://huggingface.co/Firemedic15/Qwen2.5_Risk_1.5B (Quantized version available)
Team:
- Firemedic15
What It Does
Select a country or region, choose your news sources, and click Run Analysis. The agent fans out across live data sources, synthesizes the picture, and returns a structured threat brief covering:
- Severity rating and confidence level
- Recent armed conflict events (ACLED)
- Real-time news headlines (Tavily + RSS)
- State Department travel advisory level
- Airspace restrictions
- Embassy and consulate contacts for your passport country
A raw agent trace tab exposes every tool call and model step for full auditability.
Architecture
This Space demonstrates a context-aware agentic analyst loop backed by a fine-tuned domain model:
User Query
β
βΌ
smolagents ToolCallingAgent
β
βββ fetch_acled_events β Structured conflict event data (ACLED API)
βββ fetch_rss_headlines β Open-source reporting (30+ RSS feeds)
βββ tavily_search β Real-time web search (Tavily API)
βββ fetch_travel_advisory β State Dept advisory level + notes
βββ fetch_airspace_status β NOTAM / airspace restriction data
βββ list_available_sources β Source inventory
β
βΌ
Modal REST Endpoint
(Firemedic15/qwen25-1.5B-travel-risk-analysis-merged)
β
βΌ
Structured Threat Brief (HTML + PDF export)
The inference backend is a Qwen2.5-1.5B model fine-tuned on domain-specific travel risk data, hosted on Modal with an A10G GPU. The Space itself is CPU-only β all model weight stays off HuggingFace compute.
Tavily provides real-time web search results that fill the gap between ACLED's structured event data and RSS headline coverage, capturing breaking developments and primary-source reporting that feeds don't yet index.
Data Sources
| Source | Type | Coverage | Access |
|---|---|---|---|
| ACLED | Structured conflict events | 80+ countries | Free API key |
| Tavily | Real-time web search | Global | Free tier available |
| BBC, Al Jazeera, Reuters | RSS news | Global | Open |
| Bellingcat, Crisis Group, War on the Rocks | OSINT / analysis | Conflict-specific | Open |
| UN News, Human Rights Watch, Amnesty | Policy / humanitarian | Global | Open |
| Middle East Eye, AllAfrica, Radio Free Asia | Regional reporting | Regional | Open |
| State Department | Travel advisories | All countries | Open |
| AVWX / AviationWeather | Airspace / NOTAMs | Global | Free token |
30+ RSS sources are available in the source selector. Select any combination per query.
Model
Inference is handled by Firemedic15/qwen25-1.5B-travel-risk-analysis-merged β a Qwen2.5-1.5B-Instruct model fine-tuned on the Firemedic15/Travel_Risk_Data dataset covering country-level risk assessments, conflict event summaries, advisory reasoning, and structured threat brief generation.
The model is served via a Modal REST endpoint (A10G GPU, serverless, scales to zero). GGUF quantized versions for local use are available at Firemedic15/Qwen2.5_Risk_1.5B.
Setup (Self-Hosting)
Set the following Space secrets under Settings β Variables and Secrets:
Required
| Secret | Description | Where to get it |
|---|---|---|
MODAL_ENDPOINT |
Your Modal inference URL | Printed after modal deploy serve.py |
MODAL_API_TOKEN |
Bearer token protecting your Modal endpoint | Set via modal secret create api-token |
ACLED_USERNAME |
ACLED API username | developer.acleddata.com |
ACLED_EMAIL |
Email registered with ACLED | Same registration |
TAVILY_API_KEY |
Tavily search API key | tavily.com β free tier available |
HF_TOKEN |
HuggingFace token | Auto-injected in Spaces |
Optional
| Secret | Description | Where to get it |
|---|---|---|
AVWX_TOKEN |
Enables NOTAM / airspace lookups | avwx.rest β free |
Research Context
This tool operationalizes the context-aware agentic security analyst architecture explored in ongoing research on converged physical/cyber security intelligence operations. The agentic loop pattern β autonomous tool selection, multi-source ingestion, real-time search augmentation, and structured synthesis β mirrors the design described in supporting academic work targeting Computers & Security and Journal of Cybersecurity.
Key contributions demonstrated here:
- Domain fine-tuning at small scale β A 1.5B parameter model, fine-tuned on structured risk data, handles threat synthesis without relying on frontier model API access
- Real-time augmentation β Tavily search grounds the model in current events beyond its training cutoff
- Multi-source fusion β Structured (ACLED), unstructured (RSS), and live (Tavily) data are co-analyzed in a single agent loop
- Transparent reasoning trace β Every tool call and model step is logged for analyst oversight and auditability
- Serverless GPU inference β Modal backend scales to zero cost when idle; no always-on GPU expense
Swap the inference backend
The ModalModel class in app.py is a thin wrapper around a POST endpoint. To swap backends, change MODAL_ENDPOINT to any endpoint that accepts {"prompt": "...", "max_new_tokens": N} and returns {"response": "..."}.
Stack
| Component | Role |
|---|---|
| smolagents | HuggingFace-native agentic framework |
| Firemedic15/qwen25-1.5B-travel-risk-analysis-merged | Domain fine-tuned inference model |
| Modal | Serverless GPU hosting for model inference |
| Tavily | Real-time web search API |
| ACLED API | Structured armed conflict event data |
| Gradio 5 | UI framework |
| AVWX | Airspace and NOTAM data (optional) |
Related Resources
| Resource | Link |
|---|---|
| Fine-tuned model | Firemedic15/qwen25-1.5B-travel-risk-analysis-merged |
| GGUF (local inference) | Firemedic15/Qwen2.5_Risk_1.5B |
| Training dataset | Firemedic15/Travel_Risk_Data |
| GitHub | de0015 |
Disclaimer
β οΈ AI-generated from open sources. Not for operational use without independent verification. ACLED data is third-party and subject to their terms of use. Tavily results reflect public web content at time of query. Threat assessments produced by this tool are a starting point for analyst review, not a finished intelligence product.