You'll notice
Artifact reads now specifically catch symlinks that escape the scratchpad sandbox.
The Artifact read-tool permission check now separately detects when a published path is a symlink that resolves outside the scratchpad carve-out, rather than treating it the same as a screened/dangerous name. This case requires user approval too, with its own distinct explanatory message.