Security Do not commit credentials, API keys, local profile files, private vault content, or absolute user paths. Before release, run: make scan Report security issues privately to the repository maintainer before opening a public issue.