Review follow-up on the identity predicate:
- create_profile: the rmtree guard is back to "tombstoned AND no identity
marker". A live profiles/<name>/ without a marker is invisible to
`profile list` but may still hold user files (skills/, memories/,
cron/jobs.json) — main refused it with FileExistsError; the widened guard
silently rmtree'd it. Now fails closed with an error naming the stray dir.
- named_profile_has_identity: `is_file()` follows symlinks, so a legacy
profile whose only marker is a dangling symlinked config.yaml/.env
(clone/migration leftover) vanished from list/serve/-p. A symlink is an
identity claim: accept `is_symlink()` too.
- Docs: faq.md still said "each profile is just a directory under
profiles/"; faq.md + user-guide/profiles.md + hermes_cli/AGENTS.md now
state the identity-file contract.