Goal
Prevent agents from exposing secrets while still allowing configuration changes through the repository's environment-variable workflow.
Repository Context
This application uses environment variables for external services.
Code exampleMarkdown
integration-service/
├── src/
├── .env.example
├── .gitignore
├── package.json
└── AGENTS.md
The repository follows these rules:
.env.exampledocuments required variable names using non-secret placeholder values.- Local secrets belong in ignored environment files or an approved secret store.
- Real API keys, tokens, passwords, and credentials must never be committed.
- Source code should read configuration from environment variables rather than hardcoding credentials.
Current AGENTS.md
Code exampleMarkdown
# Project Instructions
## Development
- Use `pnpm`.
- Add required environment variables to `.env.example`.
- For convenience, temporary API keys may be hardcoded in source code while developing.
- Real credentials may be added to `.env.example` so other developers can test integrations.
## Validation
- Run `pnpm test` after changing integration behavior.
Your Task
Repair the environment and secrets guidance.
Prevent credentials from being committed or hardcoded while preserving .env.example as documentation for required environment-variable names.