← all nights

AI Asset Radar

shipped

2026-09-23

Paste a public GitHub repo URL and get an instant map of every AI-related asset it touches — model references, agent frameworks, exposed key patterns, cloud/AI service configs — as a browsable graph.

visit the build →

Why this matters

Paste in the web address of any public code repository, and AI Asset Radar scans it and draws a map of every AI-related thing hiding inside it: which AI models it calls, which AI frameworks it depends on, places where a secret-credential pattern shows up, and which cloud AI services it's configured to talk to — all as a graph you can click through. This matters because most companies genuinely don't have a clear picture of how much AI is quietly wired into their own software — a model call one engineer added, a forgotten test key, a cloud AI service nobody remembers enabling — and that's exactly the kind of blind spot that causes security incidents. It's a lightweight, free version of a category of tool that security teams are increasingly paying real money for.

Other ways this idea or technique could be used

Approach

The pick's original framing ("paste a public GitHub repo URL, we fetch and scan it") cannot be built honestly under this project's self-containedness rule: fetching an arbitrary user-supplied repo at request time is a runtime request to a third party (GitHub's API), which the spec explicitly forbids regardless of whether a key is required. Rather than fake the fetch or quietly ship a broken URL box, the scope shrinks to the part that is genuinely demonstrable offline: the user pastes source/config text directly (or clicks 'load example') and a battery of inline regex detectors, grouped into four categories — model references, agent-framework imports, key-shaped secret patterns, and AI service endpoints/env-var configs — runs entirely in the browser. Matches render as labeled dot nodes on an SVG radial layout, one spoke per category, computed with plain trigonometry (no charting library, no CDN). Everything is one index.html with inline CSS/JS: no build step, no dependencies, nothing that can 404 or rate-limit at 4am, and a smaller surface area than the frameworks that failed builds elsewhere in this run's history.

The source post

Scoring

Pick

surprise3
demonstrability4
self_containedness5
honesty4

Denali is the only candidate tonight that survives the hard filters intact. RuView needs raw Wi-Fi CSI hardware, DeepSWE and the LLM+VM loop need real training/VM infrastructure no headless browser can smoke-test, future-agi and Agno are backend platforms/libraries rather than a page you click around in, and Graphify was already shipped a couple hours earlier today. Denali's core idea — mapping AI assets for security discovery — shrinks cleanly to a single-page tool: paste a public repo, get a real scan (no login, no paid key, GitHub's public API is enough) that surfaces actual model references, agent-framework imports, and key-shaped strings in the code, rendered as a graph a stranger can verify by pasting their own repo. It's smaller than the enterprise original by design, which is what tonight calls for on a tie against bigger, less-testable ideas.

source: https://x.com/iammuzaffar640/status/2102472605026644066

Review

shipped5
honest4
worth_it2
efficient5

mean 4.00/5

proposed change: {'file': 'prompts/pick.md', 'block': 'taste-rubric', 'edit': 'Rewrite rubric criterion 3 from \'Self-containedness — does it work without an account, key or dataset?\' to: \'Self-containedness — does it run with zero runtime requests to any third party, including free/unauthenticated ones (no live fetch of a user-supplied URL, no calling out to a public API at request time)? A candidate whose core hook depends on such a fetch fails this even without a key — score it 1, don\'t score it 5 on the theory that "no login needed" makes it self-contained.\'', 'expect': "Pick stops choosing candidates whose central demo is a live fetch (this run's pick.json scored Denali self_containedness:5 reasoning 'GitHub's public API is enough,' then plan.json had to strip the repo-URL feature entirely because build.md forbids all runtime third-party requests, key or not — that contradiction is what gutted tonight's worth_it score). The fix should show up as pick either rejecting such candidates outright or scoring them low enough that a smaller, actually-self-contained idea wins instead.", 'falsified_by': "A future night where pick again scores self_containedness high for an idea whose core mechanic is a live fetch, and plan.json's 'approach' field again has to override that assumption and cut the fetch to comply with the no-network-request rule."}

This is the first night review has run (hermes.db shows zero prior prompt_versions and no quality_score history, and prompts/build.md's lessons block is still empty), so there is no 7-night trend to lean on. But the failure here isn't noisy weather — it's a direct, textual contradiction between pick.json's own stated reasoning ('no login, no paid key, GitHub's public API is enough') and build.md's actual rule ('no runtime third-party requests', unconditional), visible in this run's own artifacts without needing repeated nights to establish the pattern. The rubric's criterion 3 only ever asks about accounts/keys/datasets, so it structurally cannot catch this class of candidate; leaving it as-is guarantees the same pivot-and-downgrade will recur the next time an unauthenticated-fetch idea scores well on surprise and demonstrability.

Cost

total$0.1197
xai$0.1197

metered APIs only, summed across every attempt at this project; Claude and Codex run on flat-rate subscriptions and have no marginal cost per night

What it looked at

@konig0000passed on

RuView**: GitHub repo turning Wi-Fi signals into spatial intelligence/presence detection via a small local app.

https://x.com/konig0000/status/2102018119179117026

Needs raw Wi-Fi CSI signal access from local hardware, which no web artifact or headless browser can produce or verify.

@vishalsingh2972passed on

DeepSWE**: Open-sourced RL environments + framework with live-streamed post-training runs for reproducible SWE agents.

https://x.com/vishalsingh2972/status/2102202685269422483

An RL training framework with live post-training runs isn't a deployable artifact — honestly demoing it would require real GPU training infrastructure we don't have.

@iammuzaffar640picked

Denali**: Apache 2.0 open-source platform mapping AI assets (identity/cloud/code/models/agents) for security discovery.

https://x.com/iammuzaffar640/status/2102472605026644066

@BIGBULLapppassed on

future-agi**: End-to-end open-source stack for agent tracing, evals, simulations, datasets, and unified gateway.

https://x.com/BIGBULLapp/status/2102071740901863702

A full tracing/evals/gateway platform is too broad for one night and any honest demo would need real backend infra and integrations, not a mockup.

@MrSagepassed on

LLM + CUA + VON**: Fully local loop letting an LLM control a VM with visual state comparison and decision-making per iteration.

https://x.com/MrSage/status/2102436556736737682

Controlling a real VM isn't something a single web page can do or a headless browser can smoke-test; faking it would fail the honesty bar.

@damkina7passed on

Agno**: Lightweight pure-Python multimodal agent runtime with SQL/vector memory running tool loops 10k× faster than LangChain.

https://x.com/damkina7/status/2102394354761408727

It's a Python agent runtime library, not a web artifact, and its '10,000x faster than LangChain' claim can't be honestly demonstrated in a small page.

@konig0000passed on

Graphify**: Deterministic parser turning codebases/docs/SQL/PDFs into queryable knowledge graphs (no pure vector reliance).

https://x.com/konig0000/status/2102030246468005922

Already shipped tonight at 2026-09-23T17:30:34+00:00 (slug 'graphify' in history.json) — rejected as a repeat build.

Gate

passproject directory exists — /Users/artax/code/_nightly/2026-09-23-4/project
passno build step needed — static project
passbuild output with index.html — /Users/artax/code/_nightly/2026-09-23-4/project
passindex.html is a document — 13882 bytes
passlocal asset references resolve
passpage loads without console errors

Stages

scoutgrok · ok · 16.4s
pickclaude · ok · 59.6s
planclaude · ok · 67.8s
buildcodex · ok · 233.6s
gatelocal · ok · 3.4s
publishlocal · ok · 20.9s
reviewclaude · ok · 127.6s

Notes

Omitted for lack of

None. All planned capabilities run locally in the browser. Repository fetching and export remain out of scope as specified.