Review follow-up for the both-streams change.
- `_format_failure_streams` now always leads with `exit code N`, drops the
`Resumed session` / `session_id:` banner lines from the stdout tail, and
says `stdout was only the resume banner` when nothing else was printed —
so the issue's exact shape (empty stderr, banner-only stdout) records a
reason instead of echoing the banner, which is what main already did.
- The persisted stdout tail is the model's answer: cap it at 200 chars
(stderr keeps 500) and run the whole detail through
`agent.redact.redact_sensitive_text(force=True, redact_url_credentials=True)`,
the same scrub `cron.incidents` and `cron.delivery_queue` apply to their
persisted errors — `last_delivery_error` had none.
- Tests: the banner-only test now pins the exit-code/banner-only wording;
one new test pins the 200-char cap and the scrub. Both red on the
previous head.