- Replace sk-ant-... placeholder with non-secret string to pass secret scan - Add .gitignore (venv, __pycache__, .env) - Bind server to 0.0.0.0:8000 so audit HTTP check can reach it Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>