Inline ops-warden credential routing in AGENTS.md and mirror it for Claude Code under .claude/rules so agents route secret requests to the correct subsystem before asking ops-warden or State Hub.