`hermes profile create --clone/--clone-all` copies the source home with
`shutil.copytree(symlinks=True)`. POSIX symlinks survive that (b7192b1cb0),
but an NTFS junction is a reparse point, not a symlink: `os.path.islink()`
is False and copytree descends into it, so a `skills/foo` junction into a
`skills.external_dirs` root became a physical copy in the clone. The clone's
copy and the external original are then two same-named candidates and
`_locate_skill()` refuses to guess ("Ambiguous skill name"), which also
aborts Kanban worker spawns carrying the name (`Unknown skill(s)`).
`_copytree_keep_junctions` wraps both clone copies: an `ignore` callback
excludes junction entries (`st_reparse_tag == IO_REPARSE_TAG_MOUNT_POINT`)
and the recorded targets are re-created with `_winapi.CreateJunction`. A
junction whose target is gone is skipped with a warning (CreateJunction
requires an existing target), so a dangling link never fails the clone.
Off Windows the predicate short-circuits and behaviour is unchanged.
The export staging copy deliberately keeps deep-copying: `_scrub_export_secrets`
rewrites staged files in place, and a preserved junction would let that
redaction write through into the user's external originals.
Co-authored-by: KoNit-K <konit.block@protonmail.com>