Do not include API keys, provider tokens, local .env files, or
~/.gitai/config.json contents in issues, pull requests, or logs.
If you discover a vulnerability, report it privately when GitHub private
vulnerability reporting is available for this repository. Otherwise, contact the
maintainer listed in pyproject.toml.
If a real provider key was committed or shared, rotate that key with the provider. Removing it from the working tree is not enough if it was already published in Git history.