overcast
Video OSINT agent: senses + OSINT reach for any agent.
overcast gives an agent senses and recon and targeting reach, organized
around an investigation case: a working directory with a local .overcast/
store where every result is kept. Point it at a corpus, 10 clips or 1,000, and it
turns footage into cited evidence: speech and audio with listen, full video
understanding with watch, on-screen text and objects with see, faces and
cross-corpus person search with face, and named entities with index entities.
Results persist as evidence-only case memory, so intelligence accumulates across
sessions instead of vanishing between runs, and ask answers cite the exact
record and timestamp.
Every subcommand is modular: each verb is a standalone CLI command that emits a portable JSON record, so you can run the whole pipeline as one agent or drop a single step into another recon/security workflow. overcast ships as a pi package, a standalone bun binary, and agent skills that drive the CLI from any harness. The brain LLM is BYO; the default perception backend is the Tinycloud Video Agent CLI. Every verb runs over one provider contract, so you can rebind any sense to another backend or your own script with no code changes.
📣 News
overcast is at DEF CON 34 Demo Labs — "Overcast: Video OSINT Agent. Point It at 100 Videos, Ask Anything", presented by Kevin Dela Rosa. Two sessions, both in LVCC L1, Exhibit Hall West 3 – 902 (Demo Labs Track 6):
| Session | When |
|---|---|
| 1 | Fri, Aug 7, 2026 · 12:00–12:45 PDT |
| 2 | Sat, Aug 8, 2026 · 16:00–16:45 PDT |
Come see it run live, or read the abstract.
⚠️ Responsible use & security model
overcast is a dual-use tool. Its OSINT sources can reach personal information about real people (reverse-face and reverse-image search, skip-trace / people-search, phone, property, and license-plate lookups). Use it only for lawful purposes against targets you are authorized to investigate. The high-sensitivity sources are opt-in and never enabled by default, and each carries legal constraints (DPPA, not-an-FCRA-report, biometric-privacy law, third-party ToS). Read RESPONSIBLE_USE.md before you point it at anyone.
By design, overcast runs an agent with no sandbox or permission system (inherited from pi) over untrusted media and scraped web content, which are prompt-injection vectors. Run investigations in an environment you're willing to expose to the material you collect. See SECURITY.md for the full trust model and how to report a vulnerability.
Quickstart
npm i -g @kdrrr/overcast && overcast doctor # install + preflight
# 1 — point a case at a target, sweep public sources, ask with citations
overcast case setup --name dock-incident \
--target "white van at pier 9" --source web:"pier 9 dock incident" --yes
overcast scan --pull # enumerate sources → capture → sense each hit
overcast ask "every white van, with timestamps" # answer cites record.id + timestamp
overcast brief --export brief.html # story-first analyst report
# 2 — or analyze a clip directly
overcast watch ./clip.mp4 # full video understanding → a cited record
overcast listen ./clip.mp4 # speech + audio-scene transcript
overcast face ./clip.mp4 --match ./suspect.jpg # find this person across the clip, ranked
A case is just a directory with a .overcast/ store — switch cases with
cd or --case <dir>. pi's per-directory sessions are the case history.
→ Full worked examples — person search, OSINT pulls, continuous monitoring,
visual / audio / voice DBs, the control-room wall, detection crops, and more —
live in the Field Manual (docs/field-manual.md).
Install
npm i -g @kdrrr/overcast # the CLI + pi package → `overcast`
overcast doctor # preflight: pi, ffmpeg/ffprobe, Cloudglue, providers
npx @kdrrr/overcast doctor runs any verb without a global install;
npm i -g @kdrrr/overcast@latest updates one. Or grab a standalone binary
(no Node required) for your platform from the
latest release —
overcast-<os>-<arch>.tar.gz (ships its theme/ + examples/ sidecars) — or
build it with npm run build:bun → dist/bin/overcast.
Prerequisites
- Node.js ≥ 22 (with npm) — to install and run overcast. The compiled
bunbinary bundles its own runtime, butnpm i -gneeds Node 22+. - FFmpeg —
ffmpeg+ffprobeon yourPATH(the internal media toolkit forenhance, frame extraction, detection crops, andview).brew install ffmpeg·apt install ffmpeg(or pointOVERCAST_FFMPEG/OVERCAST_FFPROBEat specific binaries). - tinycloud CLI +
CLOUDGLUE_API_KEY— the defaultwatch/listen/face/indexbackend (Cloudglue). Needs ≥ 0.3.12 (single-call verbatim transcripts);face+indexneed ≥ 0.3.4, the opt-in imageseeprovider ≥ 0.3.7.npm i -g @cloudglue/[email protected]ortinycloud update.
Optional, feature-gated backends — each reports cleanly (needs_credentials)
when absent, so the rest of overcast is unaffected:
- yt-dlp on
PATH— theyoutube/dlsources and post-page fetches ontiktok/x/instagram/telegram. - qmd — optional local semantic case search
(
npm install -g @tobilu/qmd); plainaskdoes not need it. - ExifTool / c2patool — the
exif(metadata + GPS) andverify(C2PA / Content Credentials) forensic senses.brew install exiftool c2patool. - Playwright — browser capture for the
screenshotverb andbrowsersource.npm install --include=optionalthennpx playwright install chromium. - uv-managed Python — local face / CLIP / CLAP / audio / voice DBs and the
split
enhanceops (scripts/visual-db-uv.sh).
overcast doctor verifies core prerequisites and reports optional backends when
installed or configured. Full version nuances and env knobs →
docs/configuration.md.
Use it from your agent
overcast drives any harness three ways — pick whichever fits:
Agent skills (Claude Code, Cursor, Codex, …) — install the bundled skills with
the CLI, or pull them straight from this repo with the harness-agnostic
skills installer:
overcast skills install --dest ~/.codex/skills # recommended for Codex/Cursor/other agents
overcast skills install # Claude Code default: copies into ~/.claude/skills
overcast skills install --harness claude-code # explicit Claude Code target
npx skills add kdr/overcast # vercel-labs/skills; pulls skills from this repo
Shipped skills — overcast (the broad driver + reference/verbs.md man pages),
overcast-init (one-time setup), overcast-skill-creator (author your own), and
focused workflows:
| Skill | Trope / job |
|---|---|
overcast-recon-brief |
scan/monitor public sources → cited brief |
overcast-archive |
save media into global buckets, reuse + match across cases |
overcast-dork-recon |
Google-dork a domain for exposed assets → exposure brief |
overcast-attack-surface |
map a target's public attack surface (dork + shodan) |
overcast-visual-target-search |
find a person/logo/object across clips |
overcast-media-bug-triage |
screen recordings/audio → cited bug reports |
overcast-copycat-sweep |
hunt re-uploads/reskins of original video |
overcast-lineup |
build a face DB, run a probe through it ("the lineup") |
overcast-stakeout |
standing monitor + findings review + control-room wall |
overcast-scene-locate |
"where was this taken?" — clues → reverse-image search |
overcast-ocr-translate-search |
read foreign text off a frame → translate → re-search in the source language |
overcast-enhance-and-resolve |
"zoom in… enhance" — upscale, re-read, honestly |
overcast-wiretap |
diarize + audio-scene + spectrogram + voice-isolate/separate |
overcast-provenance |
"is this clip real?" — trace to the earliest source |
overcast-timeline |
reconstruct one event across multiple clips |
overcast-crime-board |
crops + person links + CLIP themes → CSI board + wall |
overcast-pinpoint |
pinpoint WHEN something happens — coarse→fine temporal search |
overcast-frame-grid |
triage a clip in one VLM call via a labeled frame contact sheet |
overcast-event-bisect |
binary-search the exact instant of a one-way state change |
overcast-where |
locate WHERE in a frame — detect box + VLM-verify the crop |
overcast-presence-window |
find the interval a person/object is on screen |
overcast-situation-room |
stand up the live monitoring page over the case ("monitor the situation") |
overcast-connect-the-dots |
build + read the case knowledge graph to link people/media/entities |
overcast-scanner |
police-CAD incident watch via the dispatch source → map + triage |
overcast-voiceprint |
speaker-ID lineup via the voice-print index |
overcast-camera-ballistics |
camera-fingerprint device linking via exif + devices |
overcast-verify-media |
"is this real?" triage — C2PA + exif + ELA |
overcast-skip-trace |
authorized identity dossier via username → person → phone → property |
overcast-audio-match |
same-recording hunt via audio fingerprints |
Each is generated from src/skill-gen.ts (one source of truth). The CSI/crime-trope
skills (lineup…crime-board) are exercised end-to-end against real media in
test/e2e/live/cases/80–90; the visual-CoT localization skills
(pinpoint…presence-window) in test/e2e/live/cases/18_grid.
Claude Code plugin (slash commands + skills as one package):
/plugin marketplace add kdr/overcast
/plugin install overcast@overcast
Interactive/headless overcast agent — both overcast and
overcast -p "<task>" load the same system prompt and tool surface. The prompt
steers the agent to start with zero-config ask, rebuild qmd before semantic
queries, use ask --deep for configured semantic memory, and bind remote indexes
with index attach instead of note bookkeeping. Case memory is evidence-only:
setup/doctor/index/target/source/prebrief/read bookkeeping is excluded from ask
and brief. See the Field Manual for the agent's memory
model in depth.
VS Code extension
Overcast for VS Code (vscode/, extension id
kdrrr.overcast) puts
the situation room in your editor as a thin client of this CLI: right-click any
media file for the senses (watch / listen / see / faces / EXIF / …), an
activity-bar view with a command deck laid out along the intelligence cycle plus
Investigation / Sources / Records / Runs trees, evidence artifacts (map, graph,
wall, brief, situation) as editor tabs, and @overcast chat + #overcast*
language-model tools when a chat provider is installed. Every action spawns
overcast … --json; records land in the case and the sidebar follows the
.overcast/ store live.
Install it from the
VS Code Marketplace
(search "Overcast", or ext install kdrrr.overcast), or install the
overcast-<version>.vsix attached to the
latest release (code --install-extension overcast-<version>.vsix, or "Install from VSIX…" in the
Extensions view), or build it from source:
cd vscode && npm install && npm run build && npm run package
code --install-extension ../.dev/overcast-*.vsix
Live control room
overcast runs as a live operation, not just a batch tool:
- Man in the chair — remote-drive the running TUI session from your phone
(
/chair on tailnet, or launch withovercast --chair): a live assistant stream, steer / follow-up / ABORT prompts (typed or spoken via the browser's speech recognition), and a read-only case glance, over a token-authed localhost/tailnet HTTP+SSE bridge (pair with Tailscale or an SSH tunnel). - Situation room —
situationserves a self-updating monitoring page (wall tiles + reverse-chron scan/monitor feed + live GPS map + refreshing webcam/browser stills), auto-picked from the case's sources;/situation onruns the same page in-process, bound to the session. - Reports —
briefanswers "what does the evidence say?" (story-first, short by default),case statusis the mission board ("where is this case?"), andcase recordsis the append-only audit log ("what exactly happened?"). The/debriefprompt drives the analyst loop over them.
Full setup, secure-origin voice, fallbacks, and the report anatomy → Field Manual.
Verbs
overcast is ~35 verbs across four groups; each is a standalone CLI command that emits a portable JSON record:
- Senses (media → records) —
watchlistenseefaceimageaudiovoiceclustersimilarexifverifyscreenshotenhancereconstructchronolocate - Inspect (look at the evidence) —
viewcropgridwallsituationmapdevicesgraph - OSINT (search / capture / monitor) —
scancapturemonitorindexarchivetargetsourcenotefindingprebrief - Read (synthesize the case) —
askbriefcase
Plus pi's base verbs (read write edit bash grep find ls).
Full per-verb reference + every built-in source ref →
docs/verbs.md. The authoritative registry is
overcast commands --json; overcast <verb> --help is a man page for any verb,
and overcast --help shows the full surface + env vars.
Providers & configuration
Every verb runs over one provider contract, so you can rebind any sense to another backend — or your own script — with no code changes:
overcast provider setup apply --verb see --choice fal --yes # e.g. fal.ai for `see`
overcast provider create myfeed --kind source # scaffold your own source
overcast provider install ./myfeed --yes # register it — no fork
Shipped providers carry a provider.json manifest and are scanned at runtime;
bindings reference scripts as location-independent shipped: refs, so profiles
survive the install moving. A source package makes a new scan/monitor type; a
sense package a new --choice.
- Bind backends, profiles, findings tuning, local visual/audio/voice DBs, and the full environment-variable surface → docs/configuration.md
- Author your own provider (manifest schema,
provider install) → docs/providers.md
Documentation
| Doc | What's in it |
|---|---|
| docs/field-manual.md | Field Manual — the operational playbook: the quickstart cookbook + end-to-end investigation flows (scan → capture → sense → ask/brief), the live control room, and the case memory model. |
| docs/verbs.md | Verb & source reference — every verb and built-in source ref. |
| docs/configuration.md | Binding backends, the profile system, findings tuning, local DBs, and environment variables. |
| docs/providers.md | Authoring your own provider — manifests, provider install, the binding model. |
| RESPONSIBLE_USE.md | Dual-use / acceptable-use policy and per-source legal constraints. |
| SECURITY.md | Trust model and vulnerability disclosure. |
| CLAUDE.md | Architecture guide (written for agents, accurate for humans) — invariants, stack, verb surface. |
Authoritative, always-current: overcast commands --json (the verb registry),
overcast <verb> --help (a man page), overcast doctor (what's installed).
Distribution
Three surfaces from one source of truth (src/registry/verbs.ts):
- pi package (
@kdrrr/overcast) —tsupbundlesdist/{bin,index,extension}.js; pi + ffmpeg/ffprobe stay external (pinned / runtime-resolved). Apostinstallbrands the pinned pi host as "overcast" without moving~/.pi. - standalone binary —
bun build --compile→ a single executable (+ a sidecarpackage.jsonfor branding). - agent skills + Claude Code plugin —
skills generaterendersskills/overcast/{SKILL.md, reference/verbs.md}from the registry;skills install --dest <dir>copies them into any agent skills directory, while bareskills installtargets Claude Code.
Development
npm run build # tsup (dev/library build)
npm run typecheck # tsc --noEmit
npm test # unit tests (offline; fixtures)
npm run test:e2e # offline e2e (fixture providers, no creds)
npm run test:e2e:live # live real-data e2e (builds the bun binary, sources .env)
E2E_VERBOSE=1 npm run test:e2e # include exact commands + output snippets in report.md
npm run build:bun # bun build --compile → dist/bin/overcast
npm run pack:check # verify synced versions + fresh dist/bin/overcast.js before npm pack
overcast commands --json # the authoritative verb registry
overcast doctor # preflight
npm pack runs npm run pack:check first. Build with npm run build before
packing; if the ignored dist/ tree is missing or stale, the pack fails with a
message showing the version or command-registry drift.
Contributing & community
- CONTRIBUTING.md — dev setup, the architecture invariants, how to add a provider, and the PR checklist.
- RESPONSIBLE_USE.md — the dual-use / acceptable-use policy and per-source legal notes. Read this before using the OSINT sources.
- SECURITY.md — the trust model and how to report a vulnerability (privately, via GitHub Security Advisories).
- CODE_OF_CONDUCT.md — how we treat each other.
- SUPPORT.md — where to get help.
- Questions and ideas → Discussions; bugs and features → Issues.
License
Licensed under the Apache License 2.0. Built on top of pi. You are responsible for how you use this tool and for complying with all applicable laws and the terms of any third-party services you configure — see RESPONSIBLE_USE.md.
Credits
Created by Kevin Dela Rosa — co-founder & CTO of Cloudglue and creator of Tinycloud, the default perception backend here.
No comments yet
Be the first to share your take.