CLI for LLM agent secret safety — load env secrets without exposing values
Secret-safe workflow reminder that steers Pi agents to use nopeek instead of exposing .env values