How can I delete sensitive information copied into `/nix/store` by flake?

Well they’re using flakes, even plain ol’ direnv will (incidentally) create a gc root for those: