fn is_safe_provider_id(s: &str) -> bool
Provider ids feed into the install dir path; reject anything that could escape ~/.agentmux/<version>/cli/<provider>/.
~/.agentmux/<version>/cli/<provider>/