harden like-as-authorization: scope to likes/reposts only, add prompt guard
_is_owner in batch mode now only counts owner likes/reposts (not
mentions/follows), and operational instructions explicitly state that
a like only authorizes the specific action in that thread, not other
requests that happen to land in the same batch.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>