remix: use trust-gate for dangerous-accept bypass
Replace inline trust check with shouldBypassVet() from trust-gate.
When agent detected and ref not trusted, error now includes
dangerous-accept hint alongside the standard vet instructions.
Tests cover: untrusted ref error with hint, dangerous-accept bypass.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>