OvertureSAFE
Overture is an open-source, locally running web interface delivered as an MCP (Model Context Protocol) server that visually maps out the execution plan of any AI coding agent as an interactive flowchart/graph before the agent begins writing code.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
See the plan before the code. Approve it. Then watch it execute.
Problem • Solution • Install • Features • Marketplace • Config • Discussions
https://github.com/user-attachments/assets/eeb9c4cb-c80d-42da-bf63-c0c4ecb1e5d6
🔥 The Problem
Every AI coding agent today — Cursor, Claude Code, Cline, Copilot — works the same way:
What Happens Now
- You type a prompt
- Agent immediately starts writing code
- Yo
df8e09a3fb86OBSERVED · 2026-09-28Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add ui -- npx -y @overture/[email protected]
{
"mcpServers": {
"ui": {
"command": "npx",
"args": [
"-y",
"@overture/[email protected]"
]
}
}
}Exposed tools (13)
6 read · 7 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
check_pause | read | Check if the user has paused execution. Call this before starting each node to respect user pause requests. If wait=true, blocks until the user resumes. |
check_rerun | write | Check if the user has requested to re-run any nodes. Call this after plan_completed to allow users to re-run specific nodes or re-run from a node to the end. Returns immediately if there\ |
create_new_plan | write | Signal that you are creating a completely new, unrelated plan. IMPORTANT: Call get_usage_instructions first if you haven\ |
get_approval | read | Wait for user approval of the plan in the Overture UI. Returns status: |
get_node_info | read | Get detailed information about a specific node in the plan. Returns the node\ |
get_usage_instructions | read | Get detailed usage instructions for Overture MCP. CALL THIS FIRST before using any other Overture tools. Returns comprehensive documentation on how to structure plans, use XML format, handle approvals, and execute nodes. Pass your agent type to get agent-specific instructions. |
plan_completed | read | Mark the plan as successfully completed. Call this after all nodes have been executed. |
plan_failed | read | Mark the plan as failed. Call this if an unrecoverable error occurs during execution. |
request_plan_update | write | Update an existing plan with incremental operations. Pass an array of operations to insert, delete, or replace nodes. Operations are applied in order with smooth animations. After calling this, call get_approval to confirm changes with the user. |
submit_plan | write | Submit a complete plan XML to Overture. IMPORTANT: Call get_usage_instructions first to learn the correct XML format and workflow. Use this if you have the entire plan ready at once. The plan will be parsed and displayed on the canvas. |
update_node_detail | write | Update the details of a specific node in the plan. Use this to modify the title, description, complexity, expected output, or risks of a node. The UI will update in real-time. |
update_node_status | write | Update the status of a node during execution. Use this to show progress as you work through the plan. The node will visually update on the canvas. |
update_nodes_detail | write | Update details for multiple nodes at once (batch operation). Use this to efficiently modify title, description, complexity, expected output, or risks for multiple nodes in a single call. More efficient than calling update_node_detail multiple times. |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (6 observation(s))
- Network
- declared (7 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (15)
.eslintrc.cjs
path.resolve(__dirname, '../../ui-dist'), // packages/mcp-server/ui-dist
path.resolve(__dirname, '../../../ui/dist'), // packages/ui/dist
path.resolve(__dirname, '../../prompts'), // npm installed (dist/tools -> prompts)
path.resolve(__dirname, '../../../../prompts'), // Development (monorepo root)
path.resolve(__dirname, '../../../prompts'), // Alternative dev location
@modelcontextprotocol/sdk, express, ws, sax, open, chalk, zod, @types/express
@monaco-editor/react, @xyflow/react, clsx, dagre, date-fns, framer-motion, lucide-react, react
You are a Principal QA Engineer with an obsessive, uncompromising dedication to quality. You are legendary in the industry for your meticulous testing standards—nothing ships past you with even the sl
You are a Principal Software Engineer with 20+ years of experience across every major technology stack, architecture pattern, and scale of system. You're the engineer who gets paged at 3 AM when billi
assets/feature-attachments.png
assets/feature-checklist.png
assets/feature-dynamic-fields.png
assets/feature-meta-instructions.png
assets/hero-demo.mp4
Gates applied: no_behavioural_pass.
df8e09a3fb86full audit observations/trust-audit/mcp-server/sixhq__overture.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-28 | df8e09a3fb86 | SAFE | B | 89 | first audit |
Questions
What is the Overture MCP server?
Overture is an open-source, locally running web interface delivered as an MCP (Model Context Protocol) server that visually maps out the execution plan of any AI coding agent as an interactive flowchart/graph before the agent begins writing code.
What tools does Overture expose?
13 in total: 6 read-only, 7 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Overture safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Overture need?
No credential environment variables were found in its source, so it appears to need none.
How does Overture run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @overture/ui at 0.1.0.
How current is this page?
The grade is for one exact copy of the source (df8e09a3fb86), read on 2026-09-28. The repository is watched and re-audited when it changes.