mrkeyoor.com_
Tue 29 Sept 06:19 UTC
Dataevaluationupdated 29 Sept 2026

instagram-private-graph review

Instagram Private Graph is a local OSINT application that ranks accounts appearing around an Instagram target and draws them as a radial network. It collects through an authorized Instagram session, stores raw evidence locally, and produces candidate lists and reports, but its scores are uncalibrated triage signals rather than verified relationships.

Verdict

Our run installed 46 packages in 18 seconds and found 0 known vulnerabilities, but the repository supplied no test target and its score model has no published calibration. Use it only to order manual review in a lawful investigation, with a disposable authorized account and independent corroboration for every material claim. Missing license terms and the risk to the Instagram account rule out routine organizational deployment.

We ran it

Lab card: what happened when we ran instagram-private-graph
Install✓ · 18s46 packages · 243 MB
Build✓ · 4s
Testsn/ano test script
Known vulns0(pip-audit)
Repo48 files~27,134 lines of source · 2.2 MB · 0 CI workflows

Answers from our run

Does instagram-private-graph build from source?

Dependencies installed in 18 seconds (46 packages), and the build succeeded in 4 seconds. We cloned commit 6b738ff into a clean Debian container with 3 CPUs and no project-specific setup.

Does instagram-private-graph have tests you can run?

Not through a standard command: the project exposes no test script or target that our harness could run.

Does instagram-private-graph have known vulnerabilities in its dependencies?

pip-audit found none in the dependency tree at the time of our run.

Who should not use instagram-private-graph?

Anyone seeking proof of a follow, friendship, identity, location, or offline relationship: the README explicitly says graph lines and scores do not establish those facts.

What are the alternatives to instagram-private-graph?

Instaloader, Instagrapi, Sherlock. Our run installed 46 packages in 18 seconds and found 0 known vulnerabilities, but the repository supplied no test target and its score model has no published calibration.

Setup2/5Install is quick; cookies, Chromium, and account risk are not
Docs5/5Unusually candid model, safety, storage, and evidence guidance
Community2/5414 stars, 0 open items, and all visible commits on one day
Maturity1/5No tests, license, release, or calibrated relationship model

Who it’s for

Authorized OSINT investigators who need a candidate list to check against independent evidence.
Researchers studying how repeated Instagram recommendations change across sessions and viewers.
Analysts who can isolate case artifacts, record collection conditions, and explain the model's limits.
Python users willing to risk only a dedicated, replaceable test account.

Who it’s NOT for

Anyone seeking proof of a follow, friendship, identity, location, or offline relationship: the README explicitly says graph lines and scores do not establish those facts.
Investigators without lawful access to a private target: the viewing account must already be a genuine accepted follower.
Users protecting a primary or business Instagram account: undocumented endpoints can trigger checkpoints, restrictions, session loss, or a permanent ban.
Remote or shared deployments: the app has no remote-user login or TLS and refuses non-loopback hosts.
Organizations requiring a licensed, release-tagged, CI-tested dependency: the repository has no detected license, no releases, no CI workflow, and no test target.

Setup reality

Our sandbox installed commit 6b738ff in 18 seconds, adding 46 packages and using 243 MB. The build passed in 4 seconds. The repository provides no test script or target, so tests were skipped. Pip-audit found 0 known vulnerabilities in the installed environment.

Collection needs Python 3.10 or newer, a Playwright browser runtime, internet access, and an authorized test account. IG_SESSIONID and IG_DS_USER_ID are required; four other cookies are optional. The README recommends Python 3.11 or 3.12 and a dedicated account whose loss you can accept.

Keep the server on 127.0.0.1; it has no remote login or TLS. Private targets require the test account to be an accepted follower already. Raw artifacts and cookies need encrypted, non-synced storage, and Instagram can rate-limit or ban the account despite conservative settings.

A 0 to 100 score is only a review order

The graph looks definitive because every candidate receives a position, line, color, and confidence tier. The underlying number is a repeated-appearance estimate. For one phase, the model compares binomial likelihoods using hand-set assumptions of 0.70 and 0.16. The README says those constants did not come from a published benchmark. A line therefore means the tool ranked an association for display, not that Instagram confirmed a follow or relationship.

Even the top tier needs that caveat. Raw scores from 99 to 100 display as very high model confidence, yet a 99 is not a measured 99 percent probability. Viewer account, session, selected phases, depth, and date all change what Instagram returns. Scores from different runs are not directly comparable. The application is honest about this, which makes it useful for triage and unsuitable as standalone evidence.

What happened when we ran it

Our sandbox installed commit 6b738ff in 18 seconds. The unprivileged Debian container had 3 CPUs, 8 GB of RAM, Python 3.12, and no secrets. Installation succeeded with 46 packages and occupied 243 MB. The build completed in 4 seconds. Pip-audit reported 0 known vulnerabilities in the environment we installed.

There was no test script or target, so the lab skipped tests. The checkout contained 48 files, about 27,134 lines of source, and 2.2 MB before dependencies. It had no CI workflow, Dockerfile, or tests directory. Install and build results say the package environment can be assembled. They say nothing about collection accuracy, endpoint compatibility, graph calibration, or whether an authenticated Instagram run completes.

Private targets require two live cookie values

IG_SESSIONID and IG_DS_USER_ID are the 2 required credentials. Four supplementary cookie values may be supplied or discovered during warmup. A session ID is equivalent to authenticated account access, so the README tells users to keep it out of screenshots, chat, logs, browser cookie extensions, archives, and cloud shares. If it leaks, log out every Instagram session, rotate the test-account password, and collect fresh cookies.

A private target adds a firm access condition: the test account must already be a genuine accepted follower with lawful visibility. The tool does not bypass Instagram privacy controls, and its documentation rejects deceptive follow requests. A new or inactive viewing account also has weak ranking history, so its suggestions may reflect generic onboarding rather than anything about the target.

Depth 5 is the lowest documented request setting

Fast mode with network depth 5 is the recommended starting point. Values from 6 through 15 make more requests and raise runtime plus account-restriction risk. That depth controls repeated discovery calls, not graph hops. The local server rejects overlapping analysis jobs, but a second application instance can still create parallel traffic, so one-target-at-a-time discipline remains an operator responsibility.

Instagram supplies no ban-proof request rate or guaranteed cooldown. HTTP 429, changed 401 or 403 responses, checkpoints, forced logins, and unusual notifications are stop signals. Empty, 400, or 404 responses do not prove that an account or relationship is absent. Undocumented endpoints can change without notice, making a previously successful workflow incomplete the next day.

Port 8000 must stay on loopback

The launcher defaults to 127.0.0.1:8000 and refuses non-loopback hosts. That restriction is essential because the app has no remote-user authentication or TLS. Do not publish it through a tunnel, router, reverse proxy, LAN address, or public VM. Browser automation and cookies run on the same machine as case evidence, so a casual remote exposure could compromise both the viewing account and collected data.

Outputs include ranked JSON and CSV, separate node and edge CSV files, GEXF, and a text report. Raw phase data and cached avatars can remain beside them. A partial refresh updates only selected phases and can be recomputed alongside older files, so time-sensitive work should use a new artifact directory for each event and record the viewer, target numeric ID, phases, and timestamp.

Four same-day commits are the whole visible history

GitHub showed 414 stars, 0 combined open issues and pull requests, and a September 3, 2026 last push when checked on September 29. The visible history contained 4 commits, all dated September 3, including the initial release and README updates. There was no GitHub release, no CI workflow, and no test target. Zero open issues here signals an empty tracker, not proof of defect-free operation.

GitHub also detected no license, and the 8-item root listing contained no license file. That leaves no standard permission grant for reuse or redistribution. The README says academic and technical details will be presented later, but it does not claim that validation already exists. A promised paper cannot substitute for measured precision, recall, false-positive rates, or calibration.

Use the ranking to choose what a human checks next

The model's own validation section asks for precision, recall, false-positive rates, Brier scores, and calibration curves before anyone interprets its output as probability. None is supplied. Until that work exists, the defensible use is narrow: generate candidates, preserve provenance, and confirm every important statement through independent lawful sources. Do not convert a close node on the radial graph into a sentence about friendship, location, or identity.

Our 18-second install and 4-second build make the software easy to inspect. The hard part is protecting the account, securing artifacts, respecting access, and refusing to overread the score. Investigators who already practice those controls may get a useful review queue. Everyone else should choose a simpler collection tool and avoid turning undocumented platform suggestions into claims about real people.

Alternatives

ProjectWhat it isPick it when
InstaloaderAn MIT-licensed tool for downloading Instagram media, captions, and metadata.pick this instead when collection and archival matter more than inferred relationship scoring.
InstagrapiA Python client for Instagram's private API with a broad set of account and media operations.pick this instead when you need an API building block and will design your own lawful analysis workflow.
Sherlock gh↗An MIT-licensed username discovery tool spanning many social networks.pick this instead when the question is where a username appears, without inferring a private social graph.

What people are saying

  1. [velocity-scout] 0x6rss/instagram-private-graph

Sources

  1. Instagram Private Graph repository and README
  2. Measured commit 6b738ff
  3. Python dependency requirements

More data reviews

OpenBB · polyledger · timeseries-atlas · opendataloader-pdf · data-formulator · toasty · the whole board →