SIGN IN SIGN UP

fix: [ENG-2883] drop ambiguous-ref warning, address PR #690 review nits

The previously-warned "both <ref>.html and <ref>/ exist" case is not
actually a failure mode — the suffix the agent wrote IS the choice
(bare → folder, .html → file per the convention) and the FE routes by
suffix. The other on-disk shape is irrelevant. Removing the case and
all references to it:

- checkRef now reduces to a single broken check: warn only when neither
  <ref>.html nor <ref>/ exists.
- HtmlWriteSuccess + CurateSessionEnvelope JSDocs dropped the "broken /
  ambiguous" mention.
- Removed the ambiguous-ref test block from related-ref-warner.test.ts
  (and the both-exist no-warning block that I had repurposed mid-cycle).
  The remaining tests cover the actual behavior cleanly.
- Updated the MCP renderer multi-warning test to use two broken-ref
  fixtures instead of broken + ambiguous.

Also addressed two PR #690 review nits in the same pass:
- Stale comment in related-ref-warner.ts:82-87 still referenced the old
  existsSync + statSync TOCTOU shape; rewrote to describe what the
  current safeStat helpers actually do.
- Added MCP rendering tests for the new ⚠ branch (warnings present,
  warnings empty, warnings field absent — defends against pre-commit
  daemon payloads). Mirrors the CLI-side coverage added previously.

Two review nits deferred and resolved as follow-ups:
- chmodSync(…, 0) test fragility under root uid (Docker node:* images).
- WebUI Tasks panel does not yet decode/render the new warnings field.
N
Nguyễn Thuận Phát committed
ffe685622b7531ec114fc82e912a460af85c60c7
Parent: f6ec3c2