Route remote workspace filesystem operations through the extracted files router without starting agent-file synchronization.
Resolve SSH download targets before applying sensitive-path policy and stream authorized files without buffering or preview-size limits.
Tests: python -m pytest tests/hermes_cli/test_web_server_fs.py tests/hermes_cli/test_ssh_workspace_fs.py tests/tools/test_ssh_environment.py -q.
Original implementation authored by fangliquanflq.