After a real API key leaked through test files with realistic hex patterns,
this adds automated secret detection: .gitleaks.toml with custom rules for
OpenRouter/OpenAI/Anthropic/Google keys, and .pre-commit-config.yaml wiring
gitleaks as a pre-commit hook. Test keys locally updated to use FAKE-/NOTREAL
conventions that pass the allowlist.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>