Sk Public Key Decoder
Parses OpenSSH SK public-key wire blobs into an SkPublicKey.
This is the inverse of SkPublicKeyEncoder.encode. Callers that already have raw key bytes can skip this; the decoder is provided so callers that parse authorized_keys or ssh-keygen -t *-sk files (which embed the pubkey blob inside an OpenSSH private-key envelope) don't have to write SSH-string framing logic themselves.
Strict: the entire input must be consumed.