- frame-key remove deletes only the exact line add wrote, through a private
temporary file, and leaves authorized_keys alone if it can't read or
rewrite it. add checks the VM's key is a plain ed25519 key, keeps a last
line without a newline intact, and doesn't duplicate a key the headset
already trusts.
- The input helper stops on any error before acknowledging, refuses a
second click while one is in flight, and coordinates are bounded.
- Host, container and user names are checked before they reach a remote
shell; PowerShell errors come back as plain text.
- docs/testing.md says what frame-key does and doesn't undo.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>