0e378e59aa
paperclip#10978 made destructive replacement an explicit caller choice in their skill-sync and package-import paths: a rerun must never remove operator edits by default. Our hub-skill updater had the same hazard -- 'hermes skills update' calls do_install(force=True), which rmtree-replaces the skill directory even when the user edited it after install. do_update now compares the on-disk content hash against the hash the lockfile recorded at install time; drifted skills are skipped with a notice and only overwritten with the new --force flag (CLI + /skills slash path). Bundled skills already had this protection via the user-modified manifest in hermes update; this brings hub-installed skills to parity. Sabotage-verified: disabling the drift check makes the new skip test fail.