docs(agents): add output escaping and input handling rules
Document security guideline: accept raw input, validate on input, escape on output by context.
Add notes for URL scheme allowlist, JSON encoding, rich content sanitization, and avoiding double-escaping.