\`lh doctor\`'s context7 check is a required, env-only check by design
(ADR: never inferred, never persisted). Tests that shell out to \`lh\`
or \`scripts/onboard.mjs\` inherited whatever CONTEXT7_API_KEY the
developer's shell happened to export, so \`doctor passes once the repo
is initialised\` and the onboard-script e2e test only ever passed on
machines with a real key set — never verified in a clean environment
until this CI run (no secret configured, correctly).
Fixed by injecting an obviously-fake fixture key (TEST_ENV in
helpers.mjs, exported and reused by onboard.test.mjs) into every
subprocess these tests spawn, so behaviour no longer depends on the
ambient shell. Verified locally with \`env -u CONTEXT7_API_KEY\` to
reproduce the CI environment exactly: 58/58 pass either way now.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>