Score tool call replay risk from idempotency, nonce use, payload sensitivity, retry policy, and audit coverage