- anthropic-teams.js: detect HTTP 400 extra-usage policy blocks, return
status='policy_rejected' with quota headers still readable
- report.js: display policy_rejected as CRITICAL with 'POLICY BLOCKED' label
- getSeverity: treat policy_rejected as critical
Currently the direct API (used by monitor) returns 200; pi's OAuth path
returns 400. This fix future-proofs against the block extending to direct
API calls, and correctly classifies the status if it does.
Refs: trentuna/commons#17, trentuna/token-monitor#4