Plugin symlinks pointing outside the plugin directory are refused, each case with its own message.
What's wrong with this entry?
When loading a plugin or skill, Claude Code now checks each part of a symlink's target and refuses links that leave the plugin's own directory tree, route above it, point back at the plugin directory itself, or land in repository metadata. Each case gets its own message.
- Eval case discovery separately refuses
mocks/as a case directory name.
is a symlink that leaves the plugin tree
Strings lifted out of the shipped bundle, so the claim above can be checked against them.