Ensure BETTER_AUTH_SECRET is set before seal() is called in test #5, add
it to the DB-only run command in the header comment, and surface cleanup
errors to stderr instead of silently swallowing them.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>