audit Run 15 Phase 5: CSP script-src drops 'unsafe-inline'
ux: extract all executable inline JS from templates into static files
server: gallery/carousel, promo-validator, fuzz #11/#12 remediations, embed port, observability