Спроєктувати safe test contract
Відокремити application-flow, provider-integration і production-smoke tests.
Обрати official test key або non-production test mode.
Описати scope, secret storage, allowlist, rotation, logging і expiry.
Додати negative test, який підтверджує, що звичайний traffic не отримує bypass.
Threat-reviewed contract не містить hardcoded production bypass і має окрему перевірку provider integration.