README: add vault key naming schema (<server-name>-<verwendungszweck>,
kebab-case) and a key-exception example to the mcp/ guard rules.
Reference fragments in mcp/: zugferd-service.yaml (OAuth standard case,
no credential field) and az-zoll-service.yaml (documented key exception
using ${VAULT:az-zoll-service-api-key} placeholder) — neither contains
any secret.
Five invalid mcp fixtures under tests/fixtures/mcp/invalid/ covering all
README-documented failure modes: inline secret, missing server-name
fragment structure, missing url, missing type, wrong placeholder syntax.
Closes az-agent-defaults-95y
az-beitrag (mode: primary): Fachbereichs-Contributor-Assistent guiding
users to draft valid artifacts per README guard rules; keeps full
delegation capability (delegates the formal check to az-pruefer via
task tool) and explicitly acknowledges the managed permission layer.
az-pruefer (mode: subagent): read-only checker with tools [read, glob,
grep] — no edit/bash; invocable via @mention and task tool.
Three invalid agent fixtures under tests/fixtures/agents/invalid/
covering all README-documented failure modes: missing mode, missing
description, invalid mode value.
Closes az-agent-defaults-gyj
Replace the ow-hello pilot skill (never rolled out, dropped before first
commit) with az-hilfe — a German onboarding/help router skill for AZ
users, modeled after the ask-matt pattern: explains the four artifact
types, typical user questions with answer patterns, contribution path
via IT/repo, and honest rollout status (commands/agents/mcp pending).
Add five invalid skill fixtures under tests/fixtures/skills/invalid/,
each failing exactly one README guard rule: missing SKILL.md, missing
frontmatter opener, empty frontmatter, name != folder, missing
description. Remove obsolete .gitkeep placeholders.
Closes az-agent-defaults-dzx, az-agent-defaults-1ub