fn sanitize_for_dialog(s: &str, max_chars: usize) -> String
Same control-character / bidi sanitisation as the hooks dialog, so a hostile manifest can’t spoof or scramble the consent prompt.