070422bb95
Zhipu Coding Plan keys are formatted '<id>.<secret>' (no 'sk-' prefix), so the OAuth login prompt's 'sk-...' placeholder misled users into thinking their pasted key was malformed. Also extended the SECRET_PATTERNS redaction example in docs/skills/authoring-hooks.md with the Zhipu shape and a comment noting the list is not exhaustive, so hook authors referencing the example do not silently miss Zhipu keys. Fixes #2106