Skip to content
Back to skills

Night Watch

ASecurity

Autonomous maintenance (dep updates, dead code, small refactors) in isolated branch, off-hours. Triggers: night watch, autonomous maintenance, dep updates.

  • 177 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added May 27, 2026
developmentgobashgit

Security analysis

A92/100
  • mediumInstalls packages at runtime which could introduce malicious dependencies

Pro shows the line behind each finding and how to fix it

Scanned May 27, 2026

npx -y skills add softspark/ai-toolkit --skill night-watch --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Night Watch?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Night Watch
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/softspark-night-watch/badge)](https://www.skillsdirectory.com/skills/softspark-night-watch)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: night-watch
description: "Autonomous maintenance (dep updates, dead code, small refactors) in isolated branch, off-hours. Triggers: night watch, autonomous maintenance, dep updates."
effort: medium
disable-model-invocation: true
context: fork
agent: night-watchman
allowed-tools: Bash, Read, Edit, Grep
---

# Night Watch Command

Triggers the autonomous maintenance agent.

## Usage

```bash
/night-watch [scope]
# Example: /night-watch deps
# Example: /night-watch cleanup
# Default: runs full suite
```

## Protocol
1. **Checkout**: Create `maintenance/` branch.
2. **Execute**: Run `night-watchman` agent skills.
3. **Verify**: Run full test suite.
4. **Report**: Generate Shift Report.

## Rules

- **MUST** work on a dedicated `maintenance/` branch — never commit to `main` or the user's active branch
- **NEVER** push without the full test suite passing
- **CRITICAL**: stop on the first failing test and surface it — do not try to "fix" tests opportunistically
- **MANDATORY**: every change lands in a discrete commit with a conventional message

## Gotchas

- `npm audit fix` bumps to the latest **major** version when `--force` is set — quietly introducing breaking changes. Always use plain `npm audit fix` first and only escalate to `--force` after the user approves each named package.
- `pip install --upgrade` without a constraints file resolves differently each run due to transitive dependencies. Pin via `pip-compile` and commit the lockfile, otherwise maintenance runs produce "mysterious" unrelated changes.
- `git add -A` on a maintenance run can pull in build artifacts and IDE caches if `.gitignore` is incomplete. Prefer explicit `git add <path>` per change category (deps, docs, lint-fixes) to keep commits attributable.
- Pre-commit hooks that format on commit may re-modify files AFTER your edit — the resulting commit may differ from the planned diff. Run the formatter as a separate step and verify `git diff --staged` before committing.

## When NOT to Use

- For planned refactors with a known scope — use `/refactor-plan`
- For immediate bug fixes — use `/fix` or `/debug`
- In a repo the user is actively working in — wait for idle time
- When there are uncommitted changes on the current branch — abort until clean

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…