add PDS-backed mention consent system
mention allowlist is now runtime state on phi's PDS instead of
hardcoded config. phi knows about the mechanism and can manage it
via operator-only tool. posting fails safe if PDS read errors.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>