Generated projects accumulate files that were answers to a prompt rather than parts of the program: sample environment files with pretend secrets, a second README, a script that ran once, a component that nothing routes to. Each one looks reasonable alone. Together they make the tree harder to trust.
A file belongs in the repository when a later commit will still need it, and when a newcomer can tell what calls it. If you cannot name the caller, do not add the file yet. Put the experiment somewhere that is not the main branch, or do not write it down as project structure.
Be stricter with anything that looks like configuration. A model will invent keys, ports, and service names. Commit a setting only when the program reads it and you know the real value it should have in each environment. A placeholder that ships is how a fake credential becomes a real incident.
Before you commit, list the new paths in the message, in words. If a path is embarrassing to explain, it is not ready. Delete it. The model can regenerate a file. It cannot regenerate a clear history.