AI Asset Radar
shippedPaste a public GitHub repo URL and get an instant map of every AI-related asset it touches — model references, agent frameworks, exposed key patterns, cloud/AI service configs — as a browsable graph.
Why this matters
Paste in the web address of any public code repository, and AI Asset Radar scans it and draws a map of every AI-related thing hiding inside it: which AI models it calls, which AI frameworks it depends on, places where a secret-credential pattern shows up, and which cloud AI services it's configured to talk to — all as a graph you can click through. This matters because most companies genuinely don't have a clear picture of how much AI is quietly wired into their own software — a model call one engineer added, a forgotten test key, a cloud AI service nobody remembers enabling — and that's exactly the kind of blind spot that causes security incidents. It's a lightweight, free version of a category of tool that security teams are increasingly paying real money for.
Other ways this idea or technique could be used
- A due-diligence tool for a company about to acquire a startup: instantly see how much of their product actually depends on which AI vendors.
- A compliance checker: flag every place a codebase sends data to an external AI service, for privacy-law reporting.
- An onboarding map for a new security hire: see every AI-touching system in a codebase in one picture.
- A budget-forecasting tool: count every AI API call site in a codebase to estimate what switching providers would actually cost.
Approach
The pick's original framing ("paste a public GitHub repo URL, we fetch and scan it") cannot be built honestly under this project's self-containedness rule: fetching an arbitrary user-supplied repo at request time is a runtime request to a third party (GitHub's API), which the spec explicitly forbids regardless of whether a key is required. Rather than fake the fetch or quietly ship a broken URL box, the scope shrinks to the part that is genuinely demonstrable offline: the user pastes source/config text directly (or clicks 'load example') and a battery of inline regex detectors, grouped into four categories — model references, agent-framework imports, key-shaped secret patterns, and AI service endpoints/env-var configs — runs entirely in the browser. Matches render as labeled dot nodes on an SVG radial layout, one spoke per category, computed with plain trigonometry (no charting library, no CDN). Everything is one index.html with inline CSS/JS: no build step, no dependencies, nothing that can 404 or rate-limit at 4am, and a smaller surface area than the frameworks that failed builds elsewhere in this run's history.
The source post
https://x.com/iammuzaffar640/status/2102472605026644066
Scoring
Pick
| surprise | 3 |
|---|---|
| demonstrability | 4 |
| self_containedness | 5 |
| honesty | 4 |
Denali is the only candidate tonight that survives the hard filters intact. RuView needs raw Wi-Fi CSI hardware, DeepSWE and the LLM+VM loop need real training/VM infrastructure no headless browser can smoke-test, future-agi and Agno are backend platforms/libraries rather than a page you click around in, and Graphify was already shipped a couple hours earlier today. Denali's core idea — mapping AI assets for security discovery — shrinks cleanly to a single-page tool: paste a public repo, get a real scan (no login, no paid key, GitHub's public API is enough) that surfaces actual model references, agent-framework imports, and key-shaped strings in the code, rendered as a graph a stranger can verify by pasting their own repo. It's smaller than the enterprise original by design, which is what tonight calls for on a tie against bigger, less-testable ideas.
Review
| shipped | 5 |
|---|---|
| honest | 4 |
| worth_it | 2 |
| efficient | 5 |
proposed change: {'file': 'prompts/pick.md', 'block': 'taste-rubric', 'edit': 'Rewrite rubric criterion 3 from \'Self-containedness — does it work without an account, key or dataset?\' to: \'Self-containedness — does it run with zero runtime requests to any third party, including free/unauthenticated ones (no live fetch of a user-supplied URL, no calling out to a public API at request time)? A candidate whose core hook depends on such a fetch fails this even without a key — score it 1, don\'t score it 5 on the theory that "no login needed" makes it self-contained.\'', 'expect': "Pick stops choosing candidates whose central demo is a live fetch (this run's pick.json scored Denali self_containedness:5 reasoning 'GitHub's public API is enough,' then plan.json had to strip the repo-URL feature entirely because build.md forbids all runtime third-party requests, key or not — that contradiction is what gutted tonight's worth_it score). The fix should show up as pick either rejecting such candidates outright or scoring them low enough that a smaller, actually-self-contained idea wins instead.", 'falsified_by': "A future night where pick again scores self_containedness high for an idea whose core mechanic is a live fetch, and plan.json's 'approach' field again has to override that assumption and cut the fetch to comply with the no-network-request rule."}
This is the first night review has run (hermes.db shows zero prior prompt_versions and no quality_score history, and prompts/build.md's lessons block is still empty), so there is no 7-night trend to lean on. But the failure here isn't noisy weather — it's a direct, textual contradiction between pick.json's own stated reasoning ('no login, no paid key, GitHub's public API is enough') and build.md's actual rule ('no runtime third-party requests', unconditional), visible in this run's own artifacts without needing repeated nights to establish the pattern. The rubric's criterion 3 only ever asks about accounts/keys/datasets, so it structurally cannot catch this class of candidate; leaving it as-is guarantees the same pivot-and-downgrade will recur the next time an unauthenticated-fetch idea scores well on surprise and demonstrability.
Cost
| total | $0.1197 |
|---|---|
| xai | $0.1197 |
What it looked at
RuView**: GitHub repo turning Wi-Fi signals into spatial intelligence/presence detection via a small local app.
DeepSWE**: Open-sourced RL environments + framework with live-streamed post-training runs for reproducible SWE agents.
Denali**: Apache 2.0 open-source platform mapping AI assets (identity/cloud/code/models/agents) for security discovery.
future-agi**: End-to-end open-source stack for agent tracing, evals, simulations, datasets, and unified gateway.
LLM + CUA + VON**: Fully local loop letting an LLM control a VM with visual state comparison and decision-making per iteration.
Agno**: Lightweight pure-Python multimodal agent runtime with SQL/vector memory running tool loops 10k× faster than LangChain.
Graphify**: Deterministic parser turning codebases/docs/SQL/PDFs into queryable knowledge graphs (no pure vector reliance).
Gate
| pass | project directory exists — /Users/artax/code/_nightly/2026-09-23-4/project |
|---|---|
| pass | no build step needed — static project |
| pass | build output with index.html — /Users/artax/code/_nightly/2026-09-23-4/project |
| pass | index.html is a document — 13882 bytes |
| pass | local asset references resolve |
| pass | page loads without console errors |
Stages
| scout | grok · ok · 16.4s |
|---|---|
| pick | claude · ok · 59.6s |
| plan | claude · ok · 67.8s |
| build | codex · ok · 233.6s |
| gate | local · ok · 3.4s |
| publish | local · ok · 20.9s |
| review | claude · ok · 127.6s |
Notes
Omitted for lack of
None. All planned capabilities run locally in the browser. Repository fetching and export remain out of scope as specified.