diff --git a/AGENTS.md b/AGENTS.md index e944959..a990449 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -18,6 +18,7 @@ A book that a quant-desk reader can act on: signal generation → strategy → s 4. **Live beats backtest.** A claim about trading performance must trace to the tac-rd-book execution trail (round_id, decisions, fills, reconcile: slippage bps, cost), not just to a backtest. 5. **Every quoted number lands in the evidence ledger** (`book/EVIDENCE.md`) with a link to where it was produced. 6. **The book is a living document.** Sections are updated as new experimental results land; a chapter marked `done` is done for its window, not forever. +7. **Never keep credentials or secrets in the book** (or anywhere in the repo that is committed or pushed): API keys, tokens, passwords, `DATABASE_URL` connection strings with credentials, Alpaca keys, git credentials, or any value from env vars like `APCA_API_KEY*`, `GIT_USER`/`GIT_PASS`, etc. Redact to a placeholder (e.g. `***` / ``) and never commit real values. If any exist in the book or repo already, remove them immediately. Secrets belong only in local env files / secret stores, never in text, code, data, or chat transcripts we persist. ## Evidence sources (use in this order of trust)