dcdbcb8a2b
Widening secret_source_names() to include skipped_existing names silently changed tools/mcp_tool_config.py::_build_safe_env, an untouched consumer that forwards every returned name into MCP stdio child envs. That consumer wants only names a source actually APPLIED (pre-stack semantics), so secret_source_names() goes back to tuple(_SECRET_SOURCES). The routed-child scrub in strip_launch_profile_env is the one site that must also see names a source supplied but lost to a pre-existing process value, so it reads the new source_supplied_names() accessor instead. tools/mcp_tool_config.py is byte-identical to origin/main.