daemon-setup

Warn

Audited by Socket on Feb 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The fragment is conceptually consistent with a legitimate daemon-setup utility: it describes phases, credential handling via Keychain, and system daemon installation via launchd with guided, interactive steps. It does not itself contain hardcoded secrets or direct network exfiltration; however, it does enable potentially sensitive actions (Keychain access, PAT storage, daemon installation, and Pushover integration). Given the potential for credential access and persistent system changes, the footprint is appropriate for the stated purpose but warrants careful review of the external guides and any embedded scripts to ensure least privilege, explicit user consent, and secure handling of tokens. Overall risk is moderate and acceptable for a setup tool when used by a trusted developer, but the pattern should be audited for how credentials flow through external guides and how access prompts are presented to users.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 27, 2026, 05:31 PM
Package URL
pkg:socket/skills-sh/terrylica%2Fcc-skills%2Fdaemon-setup%2F@765d98971a9f083bf08d74cf429ac0edc7f23243