.envfiles, API keys, access tokens, SSH keys, private certificates, or OAuth credentials- Customer or client names, records, screenshots, exports, audit findings, or internal reports
- Internal URLs, IP addresses, hostnames, database names, service-account names, or production configuration
- Private prompts, RAG source documents, vector-store exports, embeddings, or internal agent instructions
- Source PDFs used in private engagements
Open a GitHub issue on this repository describing the concern without attaching secrets or client artefacts.