AGENTS.md: rule 7 — never keep credentials/secrets in the book or repo; remove any existing

This commit is contained in:
TradeAC Book Agent
2026-08-18 23:05:08 +00:00
parent 436692a620
commit 7d4fd6c12a
+1
View File
@@ -18,6 +18,7 @@ A book that a quant-desk reader can act on: signal generation → strategy → s
4. **Live beats backtest.** A claim about trading performance must trace to the tac-rd-book execution trail (round_id, decisions, fills, reconcile: slippage bps, cost), not just to a backtest.
5. **Every quoted number lands in the evidence ledger** (`book/EVIDENCE.md`) with a link to where it was produced.
6. **The book is a living document.** Sections are updated as new experimental results land; a chapter marked `done` is done for its window, not forever.
7. **Never keep credentials or secrets in the book** (or anywhere in the repo that is committed or pushed): API keys, tokens, passwords, `DATABASE_URL` connection strings with credentials, Alpaca keys, git credentials, or any value from env vars like `APCA_API_KEY*`, `GIT_USER`/`GIT_PASS`, etc. Redact to a placeholder (e.g. `***` / `<redacted>`) and never commit real values. If any exist in the book or repo already, remove them immediately. Secrets belong only in local env files / secret stores, never in text, code, data, or chat transcripts we persist.
## Evidence sources (use in this order of trust)