Two holes in _strip_cron_safe_constructs (one a regression from
70411a615, two days old):
1. The [^\n]* tail erased everything after api.github.com on the line,
so a payload smuggled after ; && or | was never scanned. A cron
prompt carrying a benign-looking GitHub curl followed by
'cat ~/.hermes/.env' or 'rm -rf /' passed the scanner and persisted
(verified end-to-end through the cronjob tool). Bound the tail to
the URL path ([^\s;&|]*), so same-line payloads survive the strip.
2. The (?:/|\b) host boundary treated lookalike authorities
(api.github.com.evil.com, api.github.com@evil.com) as the trusted
GitHub construct, erasing even exfil of the GitHub token itself to a
non-GitHub host. Require the exact host followed by /, whitespace,
or end.
Also add SSH private-key files to the read_secrets pattern — a
coverage gap found during adversarial testing (cat ~/.ssh/id_rsa was
invisible to the scanner even outside the exemption).