CRITICAL fixes:
- Path traversal prevention in brain/backup/skill/file endpoints
- Unsafe tar extraction with safe_extractall() path validation
HIGH fixes:
- XSS: encodeURIComponent for onclick handlers in skills/memory/prompts/standards/backups
- XSS: escapeHtml() for user-controlled text in cost/plugins/settings/audit/dashboard
- XSS: safe class name mapping in setup-wizard (attribute injection)
- Security headers middleware (CSP, HSTS, X-Frame-Options, X-Content-Type-Options)
- CORS restricted to localhost:8080
- Settings API keys masked before returning to client
- Session replay content limited to 2000 chars + path validation
MEDIUM fixes:
- Chat message length limit (10000 chars)
- Input validation on brain/skill/backup file names (reject .. and /)