__pycache__/
.pytest_cache/
.coverage*
*.pyc
*.pyo
*.pyd
.Python
build/
dist/
out/
*.egg-info/
src/*.egg-info/
.venv/
venv/
.env
.env.*
!.env.example
.DS_Store
src/browsertap_mcp/chrome_extension/config.js
*.log
log
temp_desktop.png

# browser state and user-derived data
.browsertap/
browser-profile*/
profiles/
sessions/
downloads/
screenshots/
test-results/
*.har
cookie*.json
cookies*.json
junit*.xml
coverage.xml

# local agent/acceptance material
#
# `AGENTS.md` itself is tracked: it is the contributor-facing document every
# agent reads. Machine-specific notes -- absolute paths, which browser profile is
# in use, how one maintainer's skill manager is wired -- go in `AGENTS.local.md`,
# which stays untracked so that none of it reaches a public tree.
.superpowers/
artifacts/
AGENTS.local.md
CLAUDE.md
BUGREPORT.md
SPEC.md
DELIVER.md
# Whole directory, not just `plans/`. The three files under `specs/` were tracked
# and shipped 686 lines of internal design notes -- named after the private
# framework that produced them, linked from nothing in README, and useful only to
# whoever was mid-implementation. They stay on disk for that person and out of the
# published tree. Design decisions a reader needs are in README, CONTRIBUTING and
# AGENTS.md; anything here that outlives its task belongs there instead.
docs/superpowers/

# Local development-agent frameworks, task records, and store drafts.
# Caller skills under src/browsertap_mcp/skills are part of the product.
/.agents/
# Public Codex marketplace metadata; all other local agent files stay ignored.
!/.agents/
/.agents/*
!/.agents/plugins/
/.agents/plugins/*
!/.agents/plugins/marketplace.json
/.claude/
/.trellis/
/store-assets/

# local scratch files, repository root only
#
# Anchored with a leading slash on purpose. Unanchored, `_*.json` matches at
# every depth, so a real fixture like `tests/fixtures/_expected.json` would
# vanish from `git status` and never make it into a commit -- the build would
# still pass locally and a clone would be missing the file. There is
# deliberately no `_*.py` rule in any form: it would hide
# `src/browsertap_mcp/_version.py`, the single source of the release version.
/_*.json
/_*.txt
/_*.md
/.tmp_*.txt
/PLAN.md
/JSON_PARSE_TIGHTEN.md

# local MCP client wiring
#
# This project is an MCP server, so a maintainer testing it naturally drops a
# client config into the repository root. Those files carry an absolute
# interpreter path and sometimes an API key in `env`, which is machine
# configuration and occasionally a secret -- neither belongs in a public tree.
# CI workflows under `.github/` are part of the public project.
.mcp.json
.vscode/
.idea/
.cursor/mcp.json
.gemini/settings.json

# Backups of local configuration can also appear outside ignored directories.
*.bak-*
*-bak-*

# local agent configs with absolute paths
CODE_REVIEW_REPORT.md
.codex/
opencode.json
*.bak

# local test/build caches that are safe to regenerate
htmlcov/
.mypy_cache/
.ruff_cache/
.tox/

# supply-chain scan output, all regenerated by .github/workflows/supply-chain.yml
#
# Comments stay on their own line: a trailing comment on a pattern line becomes
# part of the pattern and silently matches nothing. `*-venv/` covers the
# throwaway environments the SBOM and the install check build, because `venv/`
# above matches that exact name only.
*-venv/
sbom/
runtime-requirements.txt
pip-audit.*
gitleaks
gitleaks.tar.gz
gitleaks-*.json

# The JavaScript half of the lint gate (`package.json`, `eslint.config.mjs`
# and `package-lock.json` are tracked; what npm unpacks is not).
node_modules/
