dev-env-doctor is designed to report local setup problems without exposing secrets.
Please report security issues privately by opening a minimal GitHub issue that says a security report is available, without including the sensitive details in public text.
When contributing checks:
- never print access tokens, private keys, cookies, or passwords
- avoid dumping full environment variables
- redact machine-specific identifiers unless they are essential to the check
- prefer high-level status and concrete remediation steps