Second audit wave, targeting three more junk patterns:
- assertion-free cases that run code and assert nothing, so they pass no
matter what the code does;
- inventory literals re-typed from a production declaration, where the only
way the assertion can fail is someone editing one of the two copies;
- export key-set and export-shape loops (`typeof x === 'function'` over every
export) that restate what TypeScript already enforces.
Yield is much smaller than wave 1 on purpose: the assertion-free scanner has
a high false-positive rate, because many flagged blocks assert through a
shared helper or their oracle is "this must not throw". Those were kept.
`mobileWebCheckArgs` in `config/scripts/run-mobile-web-app-checks.mjs` is
de-exported — after the inventory comparison went away, nothing outside the
module read it.