overcast-follow-the-money

overcast-follow-the-money is a skill for Claude Code from kdr/overcast. It costs 90 tokens per session (1,485 once invoked), scanned A, original, Apache-2.0.

An investigation skill for tracing public money records from cryptocurrency addresses or companies. SEC EDGAR is the U.S. government database of company filings; OSINT means using publicly available information.

In plain words
What is it for?
Reviewing Bitcoin or Ethereum activity, searching SEC company filings, tracing counterparties, and recording possible findings on a case graph.
Why use it?
It collects transactions or filings into cited records and links related parties, making a money trail easier to follow and review.

Skill for Claude Code

Written for Claude Code: shipped in a Claude Code plugin.

Part of the overcast plugin — 35 skills, 1 hook shipped together

Good fit Reviewing Bitcoin or Ethereum activity, searching SEC company filings, tracing counterparties, and recording possible findings on a case graph.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/kdr/overcast/overcast-follow-the-money
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add kdr/overcast --skill overcast-follow-the-money
Clone the repo
git clone --depth 1 https://github.com/kdr/overcast

Made for: Claude Code.

Or install overcast, the plugin that ships this one along with the rest of its 35 skills, 1 hook.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for overcast-follow-the-money

README.md
[![agentmods](https://agentmods.dev/badge/skills/kdr/overcast/overcast-follow-the-money/github.svg)](https://agentmods.dev/skills/kdr/overcast/overcast-follow-the-money)
Your own site
<a href="https://agentmods.dev/skills/kdr/overcast/overcast-follow-the-money"><img src="https://agentmods.dev/badge/skills/kdr/overcast/overcast-follow-the-money/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for overcast-follow-the-money

Your own site · 80×15
<a href="https://agentmods.dev/skills/kdr/overcast/overcast-follow-the-money"><img src="https://agentmods.dev/badge/skills/kdr/overcast/overcast-follow-the-money.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 90 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 1,485 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe. Third-party audits
  • NVIDIA SkillSpector pass 7 Sept 2026
How audits are shown
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00090 $0.01485
Opus 5 $0.00045 $0.00743
Sonnet 5 $0.00018 $0.00297
Haiku 4.5 $0.00009 $0.00148

Measured 12d ago against content hash 223daca321c4, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-11, from the pricing page.

Security

Grade A, and why

overcast-follow-the-money scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/overcast-follow-the-money/SKILL.md · 104 lines

How it starts

The opening of the file, as written. The whole thing — 104 lines — stays where its author put it; the contents beside it link to each section on GitHub.

overcast-follow-the-money

Use this skill to work the PUBLIC money trail: crypto transaction history and SEC corporate filings, driven by the existing scan/capture/monitor verbs. Two sources ship:

  • chain — crypto tx history. chain:btc:<address> (BTC via mempool.space, keyless) and chain:eth:<address> (ETH via Etherscan, free ETHERSCAN_API_KEY). Each transaction becomes one scan record with payload.created = the block time, media.ref = a per-tx explorer deep link, amount in whole units (sats→BTC, wei→ETH), direction in/out/self, and counterparties[].
  • edgar — SEC EDGAR filings (keyless). edgar:<CIK> → a company's recent filings; edgar:"<company or query>" → full-text search. Each filing becomes a scan record with payload.created = the filing date and media.ref = the sec.gov/Archives filing document (form/accession/cik/company in the payload).

Money has no coordinates — these records carry no payload.gps, so the trail plots on graph (flow-of-funds + counterparties), not map. Use the broad overcast skill and overcast/reference/verbs.md for exact flags.

Workflow

  1. Register the address / filer as a source (confirm it shows the right key status first — chain is keyless for BTC, keyed for ETH; edgar is keyless):
overcast doctor --sources --json
overcast case init --json
overcast source add "chain:btc:1A1zP1eP5QGefi2DMPTfTL5SLmv7DivfNa" --json   # BTC address (keyless)
overcast source add "chain:eth:0xde0B295669a9FD93d5F28D9Ec85E40f4cb697BAe" --json  # ETH address (ETHERSCAN_API_KEY)
overcast source add "edgar:0000320193" --json                              # SEC filer by CIK (Apple)
overcast source add "edgar:Tesla Inc" --json                               # or by company / full-text query
  1. Scan the trail. Each tx/filing is one cited scan record; --since filters by block/filing time, --limit caps newest-first (the edgar:<CIK> path is chronological; an edgar:"<query>" full-text scan is relevance-ranked — use a CIK for strict newest-first coverage):

Read the full file on GitHub · 104 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 12d ago First seen · 104 lines · 90 tokens per session scan A 223daca321c4

Subscribe to this mod's changes

overcast-follow-the-money is a skill published in the GitHub repository kdr/overcast (16 stars, last pushed 9d ago), licensed Apache-2.0. It adds 90 tokens to every session and 1,485 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.