Security remediation and enforcement operator — the execution half of the security pair. oc-security-auditor assesses (/oc-hardening audits the posture); oc-security-hardening executes (/oc-harden writes the fixes): security headers, staged CSP rollout, TLS/WAF/rate-limit config as code, secrets hygiene, dependency-pinning policy. Maintains `.opchain/hardening.yaml` — the declared-controls manifest — and stands the per-deploy gate that verifies it, the "before every deploy" step auditor findings never had. Use for /oc-harden, /oc-harden baseline, /oc-harden fix, /oc-harden csp, /oc-harden gate, "harden this", "fix the security findings", "the pen test found", "add securit…