docs(security): add repo-specific security scope and practices (#17)
Replaces generic boilerplate with frontend-specific security guidance
covering XSS, CSRF, CSP, OAuth token leakage, SSR information
disclosure, clickjacking, and prototype pollution.
authored by