Shallow `snapshot verify` only checked that each blob object existed and
then reported "All blobs verified", overstating what it did.
It now compares each blob's stored size against the manifest's
compressed_size, using the same comparison as the deep path, and checks
that the snapshot's encrypted database (db.zst.age) is present. A blob of
the wrong size no longer counts as verified. The final line reports only
what was checked: presence and size, not contents.
The README verify description and the CLI short/long text are corrected
to match. Removed the now-unused resolveAndDownloadManifest helper and
errBlobsMissing sentinel.
Model: opus-4-8