v0.10.1 — docs: correct counts, optional labels, fix broken browser examples

Docs-only patch. No code changes.

Fixed:
- model count 82 → 94, provider count 12 → 13, MCP tool count 34 → 18
- architecture diagram: removed duplicate provider block, added .env flags
- all non-core services labeled optional with their controlling flag
- SAB MCP section rewritten for v1.0.0 (1 run_script tool, not 17)
- all browser REST API examples now include auth header (were broken)
- vision model list expanded (8 missing multimodal models)
- admin rate limit: 5 → 30 r/m, API rate limit comment: 120 → 500 r/m
- cloudflared docs: COMPOSE_PROFILES → CLOUDFLARED=1
- SAB auth: "leave empty to disable" → "defaults to lulz-4-security"
- testing.md: stale counts and wrong /ui claim fixed