Finding (backlog grooming, verified against current main)
`.gitleaks.toml`'s `[allowlist]` block exempts 6 paths, intended for documented example secrets / deliberate test fixtures. All six are absent from this repo's tree:
```
docs/explorations/downscoping-github-credentials-for-local-agents.md
docs/getting-started.md
docs/safety-guidance.md
docs/test-cases-schema.md
.agents/skills/secure-code-review/tests/*
scripts/tests/test_validate_sensitive_terms.py
test/sandbox-unit.sh
```
Verified with `find . -iname ""` for each — zero matches, repo-wide, excluding `node_modules`/`.git`. These read like paths copied from the patterns repo's config (which does have a `secure-code-review` skill and a `test_validate_sensitive_terms.py`), not this repo's actual tree.
Impact
A full-history gitleaks scan of this repo gets no functional allowlist — every exemption is inert. If any file matching one of those literal (non-existent) names is ever added, it would be silently exempted without anyone having reviewed whether that's still appropriate; more importantly, whatever files in THIS repo actually need the exemption (if any) are currently unprotected.
Fix
Either:
- Remove the dead allowlist entirely if this repo has no files needing a documented-secret exemption today, or
- Replace the paths with this repo's actual equivalents, if the intent was e.g. `docs/QUICKSTART.md`/`docs/KNOWN_FAILURE_MODES.md` (which do contain illustrative placeholder secrets) — needs a maintainer decision on which files genuinely need the exemption.
Low urgency (gitleaks' base ruleset still runs; this is a missing convenience allowlist, not a missing scan), but it's a security-tooling correctness gap worth fixing rather than leaving decorative.
AI-assisted (OpenCode), found during backlog grooming.
Finding (backlog grooming, verified against current main)
`.gitleaks.toml`'s `[allowlist]` block exempts 6 paths, intended for documented example secrets / deliberate test fixtures. All six are absent from this repo's tree:
```
docs/explorations/downscoping-github-credentials-for-local-agents.md
docs/getting-started.md
docs/safety-guidance.md
docs/test-cases-schema.md
.agents/skills/secure-code-review/tests/*
scripts/tests/test_validate_sensitive_terms.py
test/sandbox-unit.sh
```
Verified with `find . -iname ""` for each — zero matches, repo-wide, excluding `node_modules`/`.git`. These read like paths copied from the patterns repo's config (which does have a `secure-code-review` skill and a `test_validate_sensitive_terms.py`), not this repo's actual tree.
Impact
A full-history gitleaks scan of this repo gets no functional allowlist — every exemption is inert. If any file matching one of those literal (non-existent) names is ever added, it would be silently exempted without anyone having reviewed whether that's still appropriate; more importantly, whatever files in THIS repo actually need the exemption (if any) are currently unprotected.
Fix
Either:
Low urgency (gitleaks' base ruleset still runs; this is a missing convenience allowlist, not a missing scan), but it's a security-tooling correctness gap worth fixing rather than leaving decorative.
AI-assisted (OpenCode), found during backlog grooming.