claudebox v2.3.8 — MCP mode is documented

MCP was reachable but had no docs/modes/ page; the README described it only as
an endpoint inside API mode, never as the standalone mode that coexists with the
others. Documents its port, its separate token (no fallback to the API token,
and empty means no auth), and the five tools. No image behaviour changed.