_safe_skills_path() is the sibling of iter_skills_files(): when a symlink in skills/ forces a sanitized copy for mount-based backends (Docker/Singularity), it rglob-copied the whole tree — .hub, .curator_backups, node_modules and all. Prune EXCLUDED_SKILL_DIRS before descending, same rule as the sync generator, so the mounted copy never carries (or walks) the bookkeeping trees either.