Model Checking Security Properties of AI Assistant Gateways: A TLA+ Case Study of OpenClaw | Synapse