Implement Content-Security-Policy headers and strict content-type handling for non-API responses, with x-content-type-options applied to all routes. Adds security-headers test suite to verify header presence. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>