AI-LSC Release v3.3.0

Registry git-pull URL sync against the systems-architect reference
(ai-stack-guide-v12.md, "Approaching the Local AI Stack Like a Systems
Architect") + bandwidth-aware git-pull-on-update logic for already-cloned
tools + new ComfyUI registry entry. 52 patches across 8 layer files plus
a runtime/installer.py hardening.

Five categories of installer-URL patches:

A. git / git_node / custom installer `pkg` URLs corrected to match the
   v12 markdown reference (28 patches). The previous registry was
   pointing at placeholder repos (``github.com/nicely-done/...``) or at
   wrong upstreams (e.g. ``airllm`` at ``liguodongiot/llm-airforce``,
   ``llamacpp`` at ``ggerganov/llama.cpp`` instead of ``ggml-org/llama.cpp``).

B. script-type installers (fabric, grafana_alloy, llamafile, meilisearch,
   ollama, qdrant) get a new ``pkg`` field added referencing the github
   repo, while the existing working ``cmd`` (curl release tarball, etc.)
   is left untouched (6 patches).

C. registry-only git tools with no v12 markdown entry were resolved
   via web search to their official upstreams (10 patches):
     - agent_reach    -> Panniantong/Agent-Reach
     - everos_memory  -> EverMind-AI/EverOS
     - headroom       -> headroomlabs-ai/headroom
     - mnemo_cortex   -> GuyMannDude/mnemo-cortex
     - nightshift     -> johndaskovsky/nightshift
     - openbrain      -> NateBJones-Projects/OB1
     - turbovec       -> ryancodrai/turbovec
     - crossplane     -> crossplane/crossplane
     - keycloak       -> keycloak/keycloak
     - dma            -> distcc/distcc (closest parent)

D. type-mismatch fixes (3 patches): the v12 markdown lists these 3
   tools with installer type `git` or `git_node`. The user manually
   tested every entry in the md before publishing it; the registry
   had them as `uv` package-manager installs, which would have
   called `uv tool install <pkg>` against PyPI — wrong for tools that
   are installed by cloning their github repo:
     - pm_skills : uv:pm-skills    -> git:https://github.com/product-on-purpose/pm-skills
     - agno      : uv:agno         -> git:https://github.com/agno-agi/agno
     - openhands : uv:openhands-ai -> git_node:https://github.com/All-Hands-AI/OpenHands.git

E. user-provided URLs for the 4 previously-unresolved registry-only
   tools (4 patches).  These tools had placeholder
   `github.com/nicely-done/<tid>` URLs; the user provided the
   official upstream URLs directly:
     - algory    -> aryaghan-mutum/algory
     - atlas_os  -> atlas-os/atlas
     - eagle_eye -> thoughtfuldev/eagleeye
     - glassmind -> khodges42/glassMind

New tool entry (1):
  - comfyui (user_interfaces.py):  ComfyUI was referenced in the
    `ai-image-gen-local.json` stack template but had no registry
    entry.  Added as a Level 10 (Human Interface & System Operations)
    tool with installer `git:https://github.com/comfy-org/comfyui`,
    launcher `python main.py --listen 0.0.0.0 --port 8188`,
    deps [cuda], license GPL-3.0.  Total registry size is now 187
    tools (was 186).

Runtime: bandwidth-aware git-pull-on-update (runtime/installer.py)

  The existing install_git / install_git_node methods already did
  `git pull --ff-only` if the destination dir existed, but the check
  was `os.path.exists(dest)` — which is True for any dir, not just a
  git working tree.  An empty or non-git dir at the destination would
  cause `git pull` to fail and abort the install.  Hardened to:

  1. Check `os.path.isdir(dest/.git)` to confirm a real git repo.
  2. On pull failure (diverged branches, network errors, corrupted
     index, etc.), move the old dir aside to `<dest>.bak.<unix_ts>`
     and re-clone fresh — so the install always ends in a usable
     state instead of leaving a half-broken tree.
  3. If the dest dir exists but is not a git repo, back it up and
     clone fresh.
  4. Log clearly which path was taken (pulled / re-cloned / new clone
     / non-git-dir backed up) so the user can see what happened.

  Effect: re-running install on a tool that's already cloned only
  fetches the diff (a few KB / MB), not the entire repo.

Intentionally NOT touched:
  - apex (md says `pip — https://github.com/NVIDIA/apex`): kept as
    uv:apex (pip-installed).  The md's `pip` installer type is
    authoritative and the user did not call this one out.
  - 12 git-ish installers that already matched the v12 reference
    (anythingllm, dify, heretic, homelab, invokeai, koboldcpp,
    librechat, mcp_drift_state_tracker, openjarvis, paperlessngx,
    synapscli, wayland_ai).
  - 3 registry-only git tools with real-looking URLs already in
    place (goose -> block/goose, nvidia_agent_skills ->
    NVIDIA/agent-skills, picode -> jasonjmcghee/picode.git).
  - APP_CODENAME ("Decalogue") and all historical codename
    references in docstrings / UI labels / README banner / bootstrap
    banner — left as-is per user's clarification.

All 0 placeholder `github.com/nicely-done/...` URLs have been
removed from the registry.

Versioning:
  - pyproject.toml: 3.2.0 -> 3.3.0
  - src/ai_lsc/constants.py: APP_VERSION 3.2.0 -> 3.3.0
    (APP_CODENAME unchanged: "Decalogue")
  - docs/REGISTRY-URLS-v3.3.0.md: per-file old -> new URL table.

Verification:
  - All 94 Python files under src/ AST-parse cleanly.
  - Registry extractor re-reads the patched tree and confirms all 52
    patches landed + the new ComfyUI entry.  Total tools: 187 (was
    186).
  - Each old `pkg` URL string was unique within its file and matched
    exactly once during the patch — no blind global replaces.
  - install_git / install_git_node hardened: the new logic
    branches on `os.path.isdir(.git)`, falls back to re-clone on pull
    failure, and uses `import time` for backup-dir timestamps.  All
    confirmed present in installer.py.
  - 0 `nicely-done` placeholder URLs remain in the registry.

Layer ladder (unchanged from v3.2):
  L1  Host Platform & Infrastructure          L6  Multi-Agent Orchestration Runtimes
  L2  Development Runtime & Environment       L7  Agentic Software Engineering & Sandboxes
  L3  GPU Acceleration & Optimization         L8  Decentralized Knowledge & Vector Stores
  L4  Local Inference Engines                 L9  Data Extraction & Pipeline Harvest
  L5  Intelligent API Routers & Proxies       L10 Human Interface & System Operations
