Do not commit secrets, credentials, .env files, service-account keys, or production data. Report security-sensitive findings privately rather than placing exploitable details in public issues. Production secrets, IAM changes, destructive data operations, and production deployments require explicit human approval.