# IDE / local prompt scratch
.prompt
.pypi-key
.googlelogin-key

# Secrets and config (never commit). Keep ALL local credential files out of git:
# platform/service tokens live only on disk and in the deploy secret store, never here.
.env
.env.*
!.env.example
config.local.*
# Local campaign configs mounted into the Docker container (target URLs, planted prompts).
/config/
*.key
*-key
*-keys
.secrets/

# Red-team run artifacts (can contain harmful content and secrets; keep out of git).
# Root-anchored so they only match top-level output dirs, NOT source packages like
# src/modelwrecker/evidence/ or src/modelwrecker/findings/.
/runs/
/sessions/
/evidence/
/findings/

# Datasets fetched at runtime (respect each dataset's own license)
/library/
/datasets/_cache/

# Python
__pycache__/
*.py[cod]
.venv/
venv/
*.egg-info/
.pytest_cache/
.ruff_cache/
.mypy_cache/
dist/
build/

# Web apps (landing in src/web, dashboard in src/dash) and any Node tooling
node_modules/
**/node_modules/
**/dist/
**/.vite/
.wrangler/

# OS / editor
.DS_Store
Thumbs.db
.idea/
.vscode/