v0.38.2 — document the imported-by badge

It shipped across three releases with its inputs described only in the CHANGELOG
and the workflow header; the README still announced three badge kinds. Now
documented: the three inputs, what the badge measures (blast radius, not
adoption), the self-checking scrape, and how to refresh it on a schedule without
deleting your other badges.

The release script now fails when a workflow input is missing from the README —
doc drift breaks nothing and reddens no test, so only a gate that reads both
catches it.