6e22d26583
Completes the project-local skills epic's remaining skill items (#48974, #48975) on top of the discovery/trust work in #88566. Quarantine (#48974): trust is a repo-level decision made once, but repo skill content changes with every pull — the hub install path scans, a checkout didn't. Every project SKILL.md dir now runs through the same skills_guard scanner as hub installs (content-hash cached under ~/.hermes/cache/project_skill_scans/, never inside the repo). Verdict 'dangerous' quarantines the skill: excluded from the index, skills_list, and slash commands via the single iteration chokepoint iter_project_skill_files(), and skill_view refuses by name with an explanatory error. Scanner failure fails closed. Verified against a real injection fixture (6 findings: prompt_injection_ignore, deception_hide, invisible_unicode, credential exfil patterns). Non-interactive inheritance (#48975): find_project_root() now resolves from TERMINAL_CWD (the per-surface workdir cron jobs and the terminal tool already use) before falling back to process cwd. Cron/API/ACP surfaces inherit a prior interactive trust decision by project identity: job workdir inside a trusted repo => project skills load; untrusted or no workdir => nothing loads; no surface ever prompts. Tests: +10 cases in tests/agent/test_project_skills.py (real malicious fixture, fail-closed, rescan-on-change, cache location, TERMINAL_CWD inheritance matrix). Docs: quarantine + non-interactive sections in skills.md.