Secret
Any piece of information that must not be seen by others: passwords, API keys, tokens. It never goes into git.
How it appears in the course
"deny" — the list of things that are forbidden. Here: reading the .env file (where passwords and secret keys are usually kept), the secrets folder, forced deletion (rm -rf) and downloading from the internet (curl).
Secrets and tokens (passwords and access keys). CLAUDE.md usually ends up in git, so others can see it.
${GITHUB_TOKEN} is an empty spot. Claude Code fills it in with the key saved on each colleague’s computer. That way the secret keys don’t end up in the file or in git.
Where you learn it
In module 03 · Permissions: what Claude may do, in the Claude Code for Beginners course.
Related terms
Learn Claude Code from zero, in plain English
12 modules with 1–2 minute lessons, which you can also do on your phone. The first two modules are free.