TOKEN-LEAK GREP — on the COMMITTED log, with a positive control first.
Target: /mnt/5_hdd/felhom.eu/git/felhom.eu/documentation/tests/golden-0.216.0-2026-08-18/bake.log
Method: grep -c -F against the LITERAL token value (a broad [a-f0-9]{40} pattern false-hits image shas).

-- POSITIVE CONTROL: seed a throwaway copy with the token, prove the grep can find it --
   seeded copy match count = 1   (MUST be 1 — otherwise the instrument is blind)
   seeded copy shredded

-- THE REAL MEASUREMENT, now that the grep is shown to work --
   committed log match count = 0   (MUST be 0)

VERDICT: PASS — the grep works AND the committed log is clean.
