Remove cat from allowed_commands to close shell redirect bypass vector
(read_file provides safer alternative). Update display tests to match
render_user_message returning Text instead of Panel, and shell test to
use head instead of cat.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>