`command.dispatch` and `commands.catalog` resolve project-local skills for the
session's repo, but the '/' completion popup (`complete.slash`) and
`/reload-skills` (`skills.reload`) still ran `get_skill_commands()` /
`reload_skills()` unbound on the RPC thread, where `find_project_root()`
resolves the launch env ($HOME). The popup never offered `/<project-skill>`
even though dispatch accepted it, and a reload right after dispatching one
reported it under "Removed skills" with "0 skill(s) available" and
republished a registry without it.
Both handlers now run inside `_session_home_scope(session, cwd=_completion_cwd(params))`
like the catalog; `CompleteSlashParams` / `SkillsReloadParams` gain an optional
`session_id` (contracts regenerated). One invariant test covers popup + reload
for two sessions in two repos (red on the previous head: popup skill items `[]`).