Enable Content Security Policy with directives tailored for Alpine.js and Bluesky CDN
CSP was disabled — this enables it with self-only defaults, unsafe-eval for Alpine.js
(which uses new Function()), unsafe-inline for Alpine's dynamic styles, and allowlisted
Bluesky image/video CDN domains. Also adds design context to AGENTS.md.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>