Your dependencies, auditedwhile you sleep.
Give an agent card a daily prompt — card menu → Schedule — and at 02:00 it sends itself the audit instructions. The checks run in a terminal card, the findings go into a note, a leaked secret reaches your Telegram at once, and a safe fix waits on the agent’s own branch for your OK in the morning.
Two vulnerable packages and a leaked key. Allow the fix when it asks.
The agent’s own daily prompt fires at 02:00: dependency audits and a secrets scan run in a terminal card, the report goes into a note, and a leaked key reaches your Telegram before you wake up.
One daily prompt
A text and a time on the agent card. Every day at that time it arrives as the agent’s prompt — nothing else to set up.
Real tools, in plain sight
npm audit, osv-scanner and gitleaks run in a terminal card, so the report comes with the output behind it.
Loud only when it matters
Routine findings wait in the note; a leaked key goes to your Telegram straight away.
Fixes on a branch
The agent works in its own git worktree, and the upgrade waits for your OK.
One night, four steps
Started by the card’s own daily prompt.
More work on a schedule
One daily prompt, a different job.
Agents for marketplace sellers
Prices, listings, reviews and stock — handled in your own seller account, in a browser card you can watch. Each page is a live, clickable scenario.
Put the audit on the night shift
Critical findings reach you first.
macOS and Linux are coming later.
The first-run wizard installs an agent CLI, Git and the dictation model for you — or skips each step.