docs: add security + XRPC API + verify-before-claim principles to agent guide
rookery is an identity provider (auth/DPoP/DID resolution) but the agent guide
only carried generic 'fail fast'. Inlines the security, API-design, and
verify-before-claim principles a hopper lode needs (it can't read the private
org standards), plus the operator-driven/no-CI note. (CIO AGENTS.md audit.)
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>