04d732dc56
_handle_message() re-checks a slash-skill command's per-platform disabled status before dispatch, because get_skill_commands() only applies the global disabled list at scan time. That check only covered the leading skill: split_stacked_skill_commands() resolves additional /skill tokens that follow it (stacked invocations, up to 5 skills, #57987), and build_stacked_skill_invocation_message() loads every one of them via _load_skill_payload() with no disabled-status check of any kind. A message on a platform with skills.platform_disabled configured for a given skill could still get that skill's full SKILL.md content injected into the agent's context for the turn, as long as it was typed after an allowed skill: `/allowed-skill /disabled-skill do X`. Fix: after computing the stacked extra_keys, look up each one's skill name and re-check it against the same get_disabled_skill_names(platform=) set already used for the leading skill. If any stacked skill is disabled for the platform, reject the whole invocation with the same style of message the leading-skill check already returns, instead of partially loading it.