v0.4.1

Fixes the release pipeline, which failed before any job ran. The pipeline now
starts, so a tag push builds and publishes the Docker image, creates the GitHub
release, and publishes the skill to ClawHub.

- Grants the `publish-to-clawhub` job `contents: read`. Under the top-level
  `permissions: {}`, that job inherited no permissions, so the ClawHub reusable
  workflow could not be granted the `contents: read` its jobs need and GitHub
  rejected the whole workflow file at parse time.