Empirical/ ReferenceBack to guide

Security model

Empirical treats requests, repository content, specs, decisions, evidence, receipts, Git metadata, policies, CLI/MCP inputs, and remote observations as untrusted.

Do not place secrets in requests, chat, Socratic answers, specifications, decisions, evidence summaries, screenshots, tracker configuration, tool input, tool output, commands, shell history, process arguments, or delivery inputs. Never paste credentials into chat. Tracker credential fields contain environment-variable names, never values. New defaults are LINEAR_SECRET_KEY, GITHUB_TOKEN, and the Jira pair JIRA_EMAIL plus JIRA_API_TOKEN; review setup names EMPIRICAL_REVIEWER_TOKEN. Historical or custom valid names remain supported. .empirical/ is committed project data; Git-common-dir claim records are local coordination metadata.