fa915784cb
The per-root merge in _copy_dist_payload treated the first level under skills/ as the replace unit, but skills live at skills/<category>/<skill>. A distribution shipping one skill inside a category rmtree'd the whole category directory, wiping every skill the user (or hermes update) had placed there — the exact scenario of issue #25120 that this PR claims to fix. A shipped directory with no files of its own is now a container: its children are merged one level down, and the replace unit becomes the nearest directory that holds a file (a skill dir always holds SKILL.md). A symlinked category (skills/devops -> shared dir) is a container too, so the pre-write symlink check now covers it instead of silently unlinking the link and dropping the shipped copy in its place. Review finding: categorised skill payload rmtree'd skills/<category>/, destroying sibling user and bundled skills; symlinked category was unlinked rather than refused.