Follow-up on the salvaged #110698 (which scoped `_dispatch_skill` alone):
- One `_session_home_scope(session)` binding around the whole stage loop in
`command.dispatch`, so quick commands (`_load_cfg` → `_active_config_path`
honours the override), bundles (`skill-bundles/` is home-relative) and skills
all resolve against the SAME profile the routing guard used.
- `slash.exec` resolves `_bundle_key_for(base)` under the same scope, so a
bundle that exists only in the secondary profile is routed to dispatch at all.
- `_dispatch_skill` uses the home-keyed `get_skill_commands()` (the guard's
reader) instead of an unconditional `scan_skill_commands()`.
- Test (red on origin/main): a bundle only under profile B's `skill-bundles/`
is dispatched for a session bound to B.