## Why
Plugin imports persist user-global enabled state. Repository-controlled settings
must not be allowed to select executable plugin content for installation.
## What changed
- Detect plugin migrations only from home-scoped external agent settings.
- Reject plugin imports with a non-empty project `cwd` before loading Codex
configuration, while continuing to treat an empty `cwd` as home scope.
## Testing
- Cover repository-scoped detection with remote, installed, and project-relative
marketplaces.
- Verify that forged project-scoped imports fail without writing `config.toml`.
GitOrigin-RevId: 53cb46ae049cb49283187312d475d40cf42e35ab