DisguiseManager
Single source of truth for active player disguises. Keyed by the disguised player's UUID. All disguise creation / removal must go through this class so lifecycle is consistent regardless of trigger (command, API, listener).