Lightweight agent security audit checks.
This module intentionally starts with deterministic static checks. The goal is to surface risky agent surfaces early without executing untrusted code.