v1.0.11: fix security_mode leaking into baseline/resilience trace cases Only set security_mode in event context when the current phase is security. Previously the agent detected security capability was attached to every event regardless of phase, causing the dashboard to show Attack Succeeded: agent input on all traces including baseline.