integration "bad-env": env key "AWS_ACCESS_KEY_ID" in resolved env is credential/capability-shaped; use a SecretRef or capability grant instead of env passthrough
