7930a31b94
herdr protocol 19's agent.start takes a fixed `kind` (herdr resolves the executable) plus trailing CLI args for that binary; only tab.create/pane.split accept an env map, and that IS the round-1 pane-creation overlay already shipped. There is no argv/env control point that runs after the pane's login shell and before the agent process starts, so the proposed `env NAME=value ...` argv prefix cannot be implemented against this API. Documented the finding and corrected bridged.example.yaml's round-1 comments, which had overclaimed that the overlay survives the login shell. Kept everything else: added a startup WARN (Bridged.reportMemberCredentialsGap) when memberCredentials: is absent or its known: list is empty, so CB-592's protection loss is never silent, mirroring CB-594's reportRequiredSecrets.