Previously the public key was only written on first key generation.
If a CI step (sign-audit-head.sh via Vault KMS) overwrote audit-public.pem
after the key was generated, subsequent calls to append_tool_audit signed
with the local key while audit-public.pem held the Vault key — causing
verify-tool-audit.sh to fail with signature mismatch.
Now the public key is re-exported on every call so audit-public.pem always
matches the private key used to sign tool-calls-head.sig.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>