Expose validate/copy/format/annotate tools with dry-run by default, and switch is_equal matching to candidate hashing. Remove prompt-append warning to avoid writing into OpenCode input.
Adds safe matching/scanning endpoints so workflows can validate secrets without reading .env files.