Prepare to publish
Once something is crawled, it is out. Every check here is cheap; the failure it prevents is permanent.
Core rule
Explicit opt-in only. A page publishes because it says publish: true, never
because nothing excluded it.
Workflow
- List the opt-in set. Every page marked for publication.
- Follow their links. A published page linking to a private one either leaks the title or produces a dead link. Report both.
- Scan for anything that should never ship: credentials, other people's private information, confidential work, personal detail in examples.
- Check the frontmatter for fields not meant to be public, such as confidence labels or private source paths.
- Report, do not export. The user runs the build.
Output format
Publishable: <n> pages
Links to unpublished pages: <n>
[[public page]] -> [[private page]]
Flagged content: <list with reasons>
Frontmatter to strip: <fields>
Verdict: <safe to build | fix these first>
Calibration
Err toward flagging. A false positive costs the user ten seconds; a miss is permanent.
If the user asks to publish the whole vault, ask what they intend to do about the private material rather than proceeding.