This repository must not contain:
- passwords, API keys, app secrets, tokens, recovery codes, private keys, or auth cookies
- real user OpenIDs, emails, phone numbers, addresses, or third-party contact records
- raw private conversations or sensitive project memory
- local credential files, keychains, OAuth payloads, or machine-specific private configuration
- private hot-cache contents, internal task state, and project-specific agent handoffs
Examples and commands must use placeholders. Credentials should remain in the underlying CLI configuration, environment, or operating-system keychain.
If you find a credential or private identifier in the repository, do not include the value in a public issue. Contact the repository owner privately, remove the material from the working tree and Git history, and rotate or revoke the affected credential.
AgentWorkspaceOS is currently a protocol MVP. It does not claim enterprise compliance, hardened multi-tenant isolation, or formal security certification.