Do not report exposed production credentials through a public issue. Contact the repository owner privately and rotate the affected credential.
This repository must not contain platform cookies, API keys, OAuth tokens, private narration, confidential source material, or authentication files. The validator checks several common sensitive filenames, but it cannot recognize every secret. Review staged changes manually before every push.