Do not commit real credentials. Use agent-os/.dev.vars.example for variable names and set real values in Cloudflare or local .dev.vars.
CI runs typecheck and production dependency audit on every push and pull request.
Report security issues privately to the repository owner. Rotate exposed credentials before discussing the incident publicly.