## Security & Secret-Handling Rules (all agents, all tasks) These rules exist because a past audit documented a leaked secret by quoting it, and the audit report itself was then committed — re-leaking the secret in git history on the public remote. Do not repeat this. 1. **Secrets are never quoted.** If you discover a real credential, phone number, birthday, or other PII, reference it by type + location only (e.g., "admin birthday at src/...:42"). Never reproduce the value in reports, commit messages, code comments, chat output, or test fixtures. This applies double when documenting a leak: describe the evidence, do not copy it. A security report must itself pass the same secret scan it demands. 2. **Findings ledgers stay out of git.** Any security-audit output (`red-team-output/`, audit notes, PoC payloads) is local-only and gitignored. Record dispositions as one-line summaries in commit messages — never by committing the ledger. Before any commit, run `git status --short` and confirm no audit artifacts, `.env` files, `.npmrc`, or tool-state dirs (`.claude/`, `.cursor/`, `.impeccable/`) are staged. **`git add -A` is forbidden in this repo** — stage files by name. 3. **No auto-executing tool state in git.** Editor/agent hook configs (`.claude/settings.local.json`, `.cursor/hooks.json`) execute code on tool events. Committing them turns every clone into code execution on someone else's machine. They are gitignored; keep them that way. 4. **History rewrites need explicit owner approval, every time.** Even when a secret is in history, present the rewrite plan and wait. After any force-push to the public tangled.org remote, note that unreachable objects may persist server-side — record the exposure window in the ledger. 5. **Deployable = `out/` only.** Never deploy `.next/`. After builds, scan the deployable tree: `grep -rE "\+1[0-9]{10}|ADMIN_" out/` must return nothing. 6. **OneDrive builds:** npm/git commands may fail with ETIMEDOUT on dataless files. Stage to /tmp (excluding `node_modules`), work there, copy results back. Never "fix" this by committing `node_modules` or disabling git safety features. 7. **Failed auth flows leave residue.** After any OAuth/tooling auth problem (wispctl, etc.), check for stale state (e.g., `oauth_state` rows in `~/.config/wispctl/state.sqlite`) and clear it once resolved.