chore: harden repo for open source contributors

- Expand .gitignore with .env, .DS_Store, node_modules, editor files,
  and macOS iCloud duplicate patterns
- Add security section to CLI README warning against hardcoded keys
- Update AGENTS.md with CLI tools in repo structure and build commands
- Trash 40 macOS "2.md" duplicate files from working tree

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
Corey Haines
2026-02-17 15:12:00 -08:00
parent 2349865acb
commit c4b698f996
3 changed files with 44 additions and 3 deletions
+9
View File
@@ -88,6 +88,15 @@ Every CLI reads credentials from environment variables:
| `wistia` | `WISTIA_API_KEY` |
| `zapier` | `ZAPIER_API_KEY` |
## Security
**Never hardcode API keys or tokens in scripts.** All CLIs read credentials exclusively from environment variables.
- Store keys in your shell profile (`~/.zshrc`, `~/.bashrc`) or a `.env` file
- The `.env` file is gitignored — but double-check before committing
- Use `--dry-run` on any command to preview the request without sending it (credentials are masked as `***`)
- If you fork this repo, audit your commits to ensure no secrets are included
## Command Pattern
All CLIs follow the same structure: