The `catalog list` subcommands for workflows, workflow steps, presets,
and integrations printed user-editable catalog fields (name/url/
description from the `*-catalogs.yml` files) through `console.print`
with Rich markup enabled. Any bracketed content such as a description
`Does [stuff] nicely` was parsed as a style tag and silently swallowed,
and a malformed tag could raise while rendering.
Route each untrusted field through the module's already-imported
`escape` helper, matching the pattern already used by
`extension catalog list`.
Adds regression tests for all four commands that inject bracketed
name/url/description and assert the brackets survive verbatim in the
output.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>