[security] /api/identity/handle が client-supplied handle を did_handle_cache に保存。自 DID で他人 handle を claim 可能、UI 表示 / agent-account auto-provision が誤誘導。fix: DID resolver で server-side resolve、または resolved_did(handle)==owner_did 検証。src/api.rs:175