Add CLI flake and use it in top-level flake
Build the CLI from apps/cli via a new flake (pocketenv-cli) instead of
fetching prebuilt release tarballs. Bump npm package to 0.6.8
(package-lock updated). Update nixpkgs to release-25.05 and refresh
flake.lock to include the new pocketenv-cli path input.