c91395425c
Per-bottle sidecar that fronts the agent's git remotes, runs gitleaks via a pre-receive hook, and only forwards to the real upstream on a clean scan. Upstream push credentials live in the gate, not the agent — so a misbehaving agent cannot push a secret-bearing commit past it.