PDF page images and several caches now read through a shared storage layer instead of raw files.
What's wrong with this entry?
Extracted PDF page images are now listed and read back through the shared storage abstraction rather than direct filesystem calls, with a guard that fails if the extraction directory sits outside the session's tool-results store. Model-capability caches and the closed-issues cache gained the same storage-backed paths; all of them fall back to the previous filesystem path when no storage handle is supplied.
PDF extraction directory is outside the session tool-results store
Strings lifted out of the shipped bundle, so the claim above can be checked against them.