stage_security_review now also refuses a nonzero threats_open count and any missing required T-08-* threat row, not just a missing/unverified file. Adds --security-review-only, a focused mode running just this stage (Task 2's own verify command) with no services booted.