WHAT: `_mount_plugin_api_routes` mounts every `/api/plugins/<name>/` router behind an
async yield-dependency, `_plugin_route_secret_scope`, which enters
`hermes_cli.web_server_profiles._config_profile_scope(profile)` - the launch profile's
home + `launch_secret_scope`, or the `?profile=`-requested profile's home + secret scope -
the same seam the built-in routers (actions/analytics/mcp) already use.
WHY: plugin route dispatch bound no profile scope at all, so once multi-profile hosting
activated (`set_multiplex_active(True)`) every `get_secret` / `resolve_runtime_provider`
inside a plugin handler raised `UnscopedSecretError`. User plugins fold that into a silent
"no data" state; the bundled kanban plugin's Decompose / Specify / Estimate aux-LLM calls
fail loudly with `LLM error: UnscopedSecretError` (#123372). One mount-level bind covers
every plugin router, sync handlers included (`run_in_threadpool` copies the request context).
Test drives the real mount (discovery -> import -> `_mount_plugin_api_routes` -> live
request against `app`): launch profile A and `?profile=workerb` resolve distinct keys and B
does not leak back into A; an unknown profile is rejected before the handler runs.
Fixes#120310
(cherry picked from commit 7392500f38b4cf3f6ef3c44aeacbadd8cc9b85e4)