* fix: validate bootstrap agent names before filesystem writes * fix: tighten bootstrap agent-name validation