Previously only 4 commands (/plan, /goal, /mcp, /ssh) stored their text
in history via per-handler addToHistory calls. All other built-in slash
commands were silently skipped because executeBuiltinSlashCommand returned
true before the input controller's addToHistory was reached.
- Centralize history recording in the input controller after successful
slash command dispatch, for both Enter and Ctrl+Enter submit paths.
- Remove all 10 per-command addToHistory calls from slash command handlers
to prevent duplicates.
- Add shouldSkipHistory() security filter to exclude commands that may
carry secrets: /login <url> (OAuth callback with code=/state= params)
and /mcp add --token <token> (bearer token).
- Add regression tests for the security filter (8 cases).
- Update 7 existing test files to remove handler-level addToHistory
assertions (now the input controller's responsibility).
- Only add /btw, /tan, /omfg to history when their argument is non-empty, so blank invocations rejected by the controller are not persisted.
- Add regression coverage for addToHistory behavior on /btw, /tan, /omfg, /memory, /rename, and /move.