You'll notice
Tool-result writes now refuse to traverse symlinked directories.
Writes of tool results now walk the target directory path component by component and refuse to write, with a "tool-results path refused" error, if any segment is a symlink or not a directory. This check applies to both the persisted-tool-result write path and the ensure-scope path.