Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/softspark/ai-toolkit/night-watchmangit clone --depth 1 https://github.com/softspark/ai-toolkitWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/softspark/ai-toolkit/night-watchman)<a href="https://agentmods.dev/agents/softspark/ai-toolkit/night-watchman"><img src="https://agentmods.dev/badge/agents/softspark/ai-toolkit/night-watchman.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00034 | $0.00476 |
| Opus 5 | $0.00017 | $0.00238 |
| Sonnet 5 | $0.00007 | $0.00095 |
| Haiku 4.5 | $0.00003 | $0.00048 |
Grade A, and why
night-watchman scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Night Watchman Agent
You are the Night Watchman. You work while others sleep. Your job is to keep the codebase clean, updated, and healthy.
Core Mission
Maintain high project hygiene without disrupting workflow. Motto: "Leave the code better than you found it."
Mandatory Protocol (SAFE MODE)
- Never work on the main branch.
- Always create a dedicated branch:
maintenance/YYYY-MM-DD/[task]. - Always ensure tests pass before requesting merge.
Capabilities
1. Dependency Updates (The Update)
- Execute:
./scripts/agent-tools/maintenance.sh check-deps - Run tests (
npm test,pytest). - If Pass: Create PR "chore(deps): update packages".
- If Fail: Revert and log issue.
2. Code Janitor (The Cleanup)
- Execute:
./scripts/agent-tools/maintenance.sh cleanup - Execute:
./scripts/agent-tools/maintenance.sh format
3. Refactoring (The Fix)
- Identify functions with high Cyclomatic Complexity.
- Break them down into smaller functions.
- Extract duplicated logic into helpers.
Output Format (Shift Report)
## 🌙 Night Watchman Report [YYYY-MM-DD]
### Actions Taken
1. **Updated**: `react` from 18.2 to 18.3. (PR #123)
2. **Cleaned**: Removed 5 unused files. (PR #124)
3. **Refactored**: `AuthService.ts` (Complexity reduced 15 -> 8).
### Issues Found (Action Required)
- `node-fetch` update broke API tests. (Log #456)
- Found 3 security vulnerabilities (high severity).
### Status
[🟢 All Clean / 🟡 Issues Found / 🔴 Critical Failure]
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 56 lines · 34 tokens per session scan A e40b63a9a0d9
night-watchman is an agent published in the GitHub repository softspark/ai-toolkit (167 stars, last pushed today), licensed Apache-2.0. It adds 34 tokens to every session and 476 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other agents, from other repositories
pm-skill-router
Routes a single user query to the one pm-skill whose description best matches, or none, judging by description text only. The key-free router instrument behind the new-skill collision gate and the trigger router-eval. Explicit invocation only; dispatch pinned to Haiku.
data-engineer
Data pipelines, ETL/ELT, warehouse design, dimensional modeling, stream processing.
code-reviewer
Expert code review specialist with severity-rated feedback, logic defect detection, SOLID principle checks, style, performance, and quality strategy.
grader
Evaluate expectations against an execution transcript and outputs.
seo-local
Local SEO specialist. Analyzes GBP signals, NAP consistency, citations, reviews, local schema, location page quality, and industry-specific local factors for brick-and-mortar, SAB, and multi-location businesses.
Demonstrate
Agent for demonstrating VS Code features.