03cdc3b20c
- --ignore-scripts on every real npx agent-browser invocation. AGENT_BROWSER_NPX_SPEC is a floating ^0.26.0 range, not an exact pin, and none of these sites passed it (unlike install.sh/ install.ps1's own npm install of the same package). Verified against the real CLI: `npx --ignore-scripts --prefer-offline -y "agent-browser@^0.26.0" --version` resolves cleanly on npm 11.19.0/node 26. - _resolve_npx_bin() now checks the Hermes-managed/extended search before a bare ambient PATH lookup, validating each candidate with node_tool_runnable before trusting it — a bare PATH-first lookup let a broken system npx shadow a healthy managed one with no recovery. - warm_agent_browser_npx_cache() now runs a credential-scrubbed, PATH-propagated environment (matching every other agent-browser subprocess spawn) instead of inheriting the full parent environment including every provider/gateway credential Hermes holds, and kills the whole process tree (not just the top-level npx PID) on timeout via the new _kill_process_tree helper, since a surviving descendant can otherwise hold a capture pipe open past the nominal deadline.