What secret-handling checks matter when a tool contract says prompt-only input?