Atlas / MCP servers / sixhq / Overture

OvertureSAFE

mcp/sixhq/overture

Overture is an open-source, locally running web interface delivered as an MCP (Model Context Protocol) server that visually maps out the execution plan of any AI coding agent as an interactive flowchart/graph before the agent begins writing code.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
13 6r · 7w · 0d
Transport
stdio
License
MIT
Stars
641
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

See the plan before the code. Approve it. Then watch it execute.

Problem • Solution • Install • Features • Marketplace • Config • Discussions

https://github.com/user-attachments/assets/eeb9c4cb-c80d-42da-bf63-c0c4ecb1e5d6

🔥 The Problem

Every AI coding agent today — Cursor, Claude Code, Cline, Copilot — works the same way:

What Happens Now

  1. You type a prompt
  2. Agent immediately starts writing code
  3. Yo
Read from source at commit df8e09a3fb86OBSERVED · 2026-09-28
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add ui -- npx -y @overture/[email protected]
claude-desktop
{
  "mcpServers": {
    "ui": {
      "command": "npx",
      "args": [
        "-y",
        "@overture/[email protected]"
      ]
    }
  }
}
03

Exposed tools (13)

6 read · 7 write · 0 destructive.

ToolRiskDescription
check_pausereadCheck if the user has paused execution. Call this before starting each node to respect user pause requests. If wait=true, blocks until the user resumes.
check_rerunwriteCheck if the user has requested to re-run any nodes. Call this after plan_completed to allow users to re-run specific nodes or re-run from a node to the end. Returns immediately if there\
create_new_planwriteSignal that you are creating a completely new, unrelated plan. IMPORTANT: Call get_usage_instructions first if you haven\
get_approvalreadWait for user approval of the plan in the Overture UI. Returns status:
get_node_inforeadGet detailed information about a specific node in the plan. Returns the node\
get_usage_instructionsreadGet detailed usage instructions for Overture MCP. CALL THIS FIRST before using any other Overture tools. Returns comprehensive documentation on how to structure plans, use XML format, handle approvals, and execute nodes. Pass your agent type to get agent-specific instructions.
plan_completedreadMark the plan as successfully completed. Call this after all nodes have been executed.
plan_failedreadMark the plan as failed. Call this if an unrecoverable error occurs during execution.
request_plan_updatewriteUpdate an existing plan with incremental operations. Pass an array of operations to insert, delete, or replace nodes. Operations are applied in order with smooth animations. After calling this, call get_approval to confirm changes with the user.
submit_planwriteSubmit a complete plan XML to Overture. IMPORTANT: Call get_usage_instructions first to learn the correct XML format and workflow. Use this if you have the entire plan ready at once. The plan will be parsed and displayed on the canvas.
update_node_detailwriteUpdate the details of a specific node in the plan. Use this to modify the title, description, complexity, expected output, or risks of a node. The UI will update in real-time.
update_node_statuswriteUpdate the status of a node during execution. Use this to show progress as you work through the plan. The node will visually update on the canvas.
update_nodes_detailwriteUpdate details for multiple nodes at once (batch operation). Use this to efficiently modify title, description, complexity, expected output, or risks for multiple nodes in a single call. More efficient than calling update_node_detail multiple times.
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (6 observation(s))
Network
declared (7 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (15)

LOWInventory / provenance · inv.hidden_file · CWE-1104
packages/mcp-server/.eslintrc.cjs
.eslintrc.cjs
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/mcp-server/src/http/server.ts:24
path.resolve(__dirname, '../../ui-dist'),        // packages/mcp-server/ui-dist
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/mcp-server/src/http/server.ts:25
path.resolve(__dirname, '../../../ui/dist'),     // packages/ui/dist
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/mcp-server/src/tools/handlers.ts:1513
path.resolve(__dirname, '../../prompts'),        // npm installed (dist/tools -> prompts)
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/mcp-server/src/tools/handlers.ts:1515
path.resolve(__dirname, '../../../../prompts'),  // Development (monorepo root)
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/mcp-server/src/tools/handlers.ts:1516
path.resolve(__dirname, '../../../prompts'),     // Alternative dev location
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
packages/mcp-server/package.json
@modelcontextprotocol/sdk, express, ws, sax, open, chalk, zod, @types/express
Why it matters. 17 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
packages/ui/package.json
@monaco-editor/react, @xyflow/react, clsx, dagre, date-fns, framer-motion, lucide-react, react
Why it matters. 19 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
.claude/agents/principal-qa-engineer.md:9
You are a Principal QA Engineer with an obsessive, uncompromising dedication to quality. You are legendary in the industry for your meticulous testing standards—nothing ships past you with even the sl
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
.claude/agents/senior-engineer.md:9
You are a Principal Software Engineer with 20+ years of experience across every major technology stack, architecture pattern, and scale of system. You're the engineer who gets paged at 3 AM when billi
INFOInventory / provenance · inv.oversize · CWE-1104
assets/feature-attachments.png
assets/feature-attachments.png
Why it matters. 1218941 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
assets/feature-checklist.png
assets/feature-checklist.png
Why it matters. 1776398 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
assets/feature-dynamic-fields.png
assets/feature-dynamic-fields.png
Why it matters. 1268568 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
assets/feature-meta-instructions.png
assets/feature-meta-instructions.png
Why it matters. 1210359 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
assets/hero-demo.mp4
assets/hero-demo.mp4
Why it matters. 4797846 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-09-28 · audit v0.4.1 · source sha df8e09a3fb86full audit observations/trust-audit/mcp-server/sixhq__overture.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-28df8e09a3fb86SAFEB89first audit
06

Questions

What is the Overture MCP server?

Overture is an open-source, locally running web interface delivered as an MCP (Model Context Protocol) server that visually maps out the execution plan of any AI coding agent as an interactive flowchart/graph before the agent begins writing code.

What tools does Overture expose?

13 in total: 6 read-only, 7 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Overture safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Overture need?

No credential environment variables were found in its source, so it appears to need none.

How does Overture run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @overture/ui at 0.1.0.

How current is this page?

The grade is for one exact copy of the source (df8e09a3fb86), read on 2026-09-28. The repository is watched and re-audited when it changes.

Advertisement