# Scripting Conventions - All scripts live in `scripts/` and run from the repository root - Scripts should be idempotent and safe to re-run - Use colour output for pass/fail indicators in verification scripts - Verification scripts should check for default/insecure credentials and print remediation instructions on failure - Scripts should exit non-zero on failure so `&&` chains work naturally - **Never hardcode secrets, tokens, or access keys in scripts.** Accept them via environment variables, stdin, or `@file` references. If a script needs a secret at runtime, read it from `~/dev/claude/secrets/` or accept it as a parameter — never embed it.