klever-go: Percentage-transfer royalty skips the source debit at exactly-100% splits (CVE-2026-55763) | HOL Guard CVE