check / check (push) Successful in 49s
`secret rm ..` deleted the whole vault; `secret rm .` and `secret rm ""` deleted every secret. rm, mv, the version commands, encrypt and decrypt built paths from the name unchecked; import checked it only after reading the source file. Each now calls vault.ValidateSecretName, which wraps the existing rule, on the name as given, before building any path; MoveSecret checks both names before switching the current vault. Its error and README.md state the rule. The test-only copy of the rule in internal/secret is removed. The regression test runs each rejected command on a copy of two in-memory vaults and requires the exact error and an unchanged state directory. Model: opus-5-5