Addresses the unresolved review comment on #30674 — avoid deep-copying
the whole conversation (including large tool outputs and attachments) to
sanitize two top-level keys on a handful of tool-role messages.
Switches to a shallow outer-list copy + shallow per-message dict copy,
applied only to messages that actually carry name/tool_name. Matches the
copy-on-write pattern already used by the shared sanitizer in
agent/transports/chat_completions.py and by QwenProfile.prepare_messages().
The needs_sanitize early-return path is preserved unchanged so the
existing identity check (prepare_messages returns the original list object
when nothing needs sanitizing) continues to hold.