In scope
What the daemon is designed to defend against.
- An agent reading or exfiltrating credentials in ~/.ssh, ~/.aws, ~/.gnupg, .env, .netrc, or .npmrc.
- An agent planting a .git/hooks payload that runs the next time you commit (enforced on macOS).
- A forged inbound webhook impersonating Slack, Discord, or GitHub to drive the daemon.
- A replayed inbound delivery executing the same slash command twice.
- An agent escaping its worktree to scribble over the rest of the repo.