Produce a publishable branch of a repository with private directories removed from the whole history, not just the tip. Finds .NOT_PUBLIC markers, rewrites history with git-filter-repo (run from nix-shell) in a throwaway clone, audits the rewritten history for leaked keywords with git log -p, and lands the result as public-scrubbed/$YYMMDD-HHMMSS/$original_sha. Use before open-sourcing a repo, before pushing an internal repo to a public remote, or when asked to strip vendor/employer-specific material from history.