night-watch

night-watch is a skill for Claude Code, Codex from softspark/ai-toolkit. It costs 36 tokens per session (535 once invoked), scanned A, original, Apache-2.0.

An autonomous maintenance workflow for dependency updates, dead-code removal, and small refactors in a separate Git branch.

In plain words
What is it for?
Use it for off-hours cleanup, dependency updates, small refactors, full test runs, and maintenance reports.
Why use it?
It keeps routine maintenance isolated and requires tests and discrete commits before changes are accepted.

Skill for Claude CodeCodex

Part of the ai-toolkit plugin — 114 skills, 44 agents, 14 hooks shipped together

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/softspark/ai-toolkit/night-watch
Any agent
npx skills add softspark/ai-toolkit --skill night-watch
Clone the repo
git clone --depth 1 https://github.com/softspark/ai-toolkit

Made for: Claude Code, Codex.

Or install ai-toolkit, the plugin that ships this one along with the rest of its 114 skills, 44 agents, 14 hooks.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for night-watch

README.md
[![agentmods](https://agentmods.dev/badge/skills/softspark/ai-toolkit/night-watch.svg)](https://agentmods.dev/skills/softspark/ai-toolkit/night-watch)
Your own site
<a href="https://agentmods.dev/skills/softspark/ai-toolkit/night-watch"><img src="https://agentmods.dev/badge/skills/softspark/ai-toolkit/night-watch.svg" alt="Measured on agentmods" height="20"></a>
Per session 36 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 535 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00036 $0.00535
Opus 5 $0.00018 $0.00267
Sonnet 5 $0.00007 $0.00107
Haiku 4.5 $0.00004 $0.00053

Measured yesterday against content hash f9bf7596a43e, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

night-watch scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

app/skills/night-watch/SKILL.md · 50 lines

What it actually says

Night Watch Command

Triggers the autonomous maintenance agent.

Usage

/night-watch [scope]
# Example: /night-watch deps
# Example: /night-watch cleanup
# Default: runs full suite

Protocol

  1. Checkout: Create maintenance/ branch.
  2. Execute: Run night-watchman agent skills.
  3. Verify: Run full test suite.
  4. Report: Generate Shift Report.

Rules

  • MUST work on a dedicated maintenance/ branch — never commit to main or the user's active branch
  • NEVER push without the full test suite passing
  • CRITICAL: stop on the first failing test and surface it — do not try to "fix" tests opportunistically
  • MANDATORY: every change lands in a discrete commit with a conventional message

Gotchas

  • npm audit fix bumps to the latest major version when --force is set — quietly introducing breaking changes. Always use plain npm audit fix first and only escalate to --force after the user approves each named package.
  • pip install --upgrade without a constraints file resolves differently each run due to transitive dependencies. Pin via pip-compile and commit the lockfile, otherwise maintenance runs produce "mysterious" unrelated changes.
  • git add -A on a maintenance run can pull in build artifacts and IDE caches if .gitignore is incomplete. Prefer explicit git add <path> per change category (deps, docs, lint-fixes) to keep commits attributable.
  • Pre-commit hooks that format on commit may re-modify files AFTER your edit — the resulting commit may differ from the planned diff. Run the formatter as a separate step and verify git diff --staged before committing.

When NOT to Use

  • For planned refactors with a known scope — use /refactor-plan
  • For immediate bug fixes — use /fix or /debug
  • In a repo the user is actively working in — wait for idle time
  • When there are uncommitted changes on the current branch — abort until clean
Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 50 lines · 36 tokens per session scan A f9bf7596a43e

Subscribe to this mod's changes

night-watch is a skill published in the GitHub repository softspark/ai-toolkit (168 stars, last pushed yesterday), licensed Apache-2.0. It adds 36 tokens to every session and 535 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.

Related

Other skills, from other repositories

dimension-door

Dimension Door is the quick-switch spell: branch to branch, environment to environment, project to project. It is not a migration and it is not discovery. It assumes both endpoints are known, prepared, and close enough in shape that you can step across with only the context you actually need.

Hmbown/Wizards-of-the-Ghosts · 61 tokens

file-organizer

Intelligently organizes your files and folders across your computer by understanding context, finding duplicates, suggesting better structures, and automating cleanup tasks. Reduces cognitive load and keeps your digital workspace tidy without manual effort.

foryourhealth111-pixel/Vibe-Skills · 46 tokens

screen-detox

当用户刷手机/短视频/社交媒体上瘾、感觉空虚、想戒断多巴胺零食时调用。 核心理念: 所有屏幕活动与更少幸福相关(作者断言无例外); 屏幕=用长期后果换短期快感的多巴胺零食; 用习惯替换五步戒断。 不适用于: 工作需要屏幕的职业场景(区分工作屏幕与消费屏幕)。 Triggers: 刷手机/上瘾/短视频/社交媒体/多巴胺/戒断/屏幕时间/screen time/dopamine/addiction.

kangarooking/cangjie-skill · 148 tokens

happiness-skill

当用户问「怎么才能更幸福/为什么得到了还不满足/怎么减少焦虑」时调用。 核心理念: 幸福是缺憾感清空的默认状态, 是可训练的技能; 欲望是与自己的契约(得到前不快乐), 同时只留一个重大欲望; 活在当下。 不适用于: 临床抑郁等需要专业治疗的场景(本书方法不能替代医疗)。 Triggers: 幸福/不快乐/欲望/焦虑/知足/活在当下/happiness/desire/anxiety.

kangarooking/cangjie-skill · 136 tokens

monkey-mind-meditation

当用户脑子停不下来、焦虑反刍、想学冥想/提升专注力时调用。 核心理念: 内心独白(心猴)是失控程序不是"我"; 用调试模式逐条观察念头, 意识到即失去控制; 冥想=收件箱归零/心灵间歇性禁食。 不适用于: 严重精神疾病急性发作(先就医); 需要立刻处理的实际问题(先做事)。 Triggers: 冥想/焦虑/脑子停不下来/胡思乱想/专注/心猴/monkey mind/meditation/anxiety.

kangarooking/cangjie-skill · 158 tokens

37signals-way

Build lean, opinionated products using the 37signals philosophy from "Getting Real", "Rework", and "Shape Up". Use when the user mentions "Getting Real", "Rework", "Shape Up", "37signals", "Basecamp method", "six-week cycles", "fixed time variable scope", "appetite vs estimates", "betting table", "breadboarding", "fat…

wondelai/skills · 177 tokens