From 7d4fd6c12ae01f4dd994c397c944be4dbbafaf82 Mon Sep 17 00:00:00 2001 From: TradeAC Book Agent Date: Tue, 18 Aug 2026 23:05:08 +0000 Subject: [PATCH] =?UTF-8?q?AGENTS.md:=20rule=207=20=E2=80=94=20never=20kee?= =?UTF-8?q?p=20credentials/secrets=20in=20the=20book=20or=20repo;=20remove?= =?UTF-8?q?=20any=20existing?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- AGENTS.md | 1 + 1 file changed, 1 insertion(+) diff --git a/AGENTS.md b/AGENTS.md index e944959..a990449 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -18,6 +18,7 @@ A book that a quant-desk reader can act on: signal generation → strategy → s 4. **Live beats backtest.** A claim about trading performance must trace to the tac-rd-book execution trail (round_id, decisions, fills, reconcile: slippage bps, cost), not just to a backtest. 5. **Every quoted number lands in the evidence ledger** (`book/EVIDENCE.md`) with a link to where it was produced. 6. **The book is a living document.** Sections are updated as new experimental results land; a chapter marked `done` is done for its window, not forever. +7. **Never keep credentials or secrets in the book** (or anywhere in the repo that is committed or pushed): API keys, tokens, passwords, `DATABASE_URL` connection strings with credentials, Alpaca keys, git credentials, or any value from env vars like `APCA_API_KEY*`, `GIT_USER`/`GIT_PASS`, etc. Redact to a placeholder (e.g. `***` / ``) and never commit real values. If any exist in the book or repo already, remove them immediately. Secrets belong only in local env files / secret stores, never in text, code, data, or chat transcripts we persist. ## Evidence sources (use in this order of trust)