- Remove duplicate security check in _cleanup_sdk_tool_results (copy-paste)
- Don't delete transcript on transient errors — only the current
turn failed, the transcript is still valid for future resume
- Add post-construction realpath check in write_transcript_to_tempfile
to satisfy CodeQL taint analysis