What
- File reads: a new denial reason explains when a read is withheld because the file is linked from your Claude Code configuration, instead of falling into a generic "sensitive" bucket.
- The sandbox readability check gained a
host_configclassification (via a newhostConfigparameter) alongside its existingread_denied/sensitive/sensitive_trackedoutcomes, and can reportrules_unreadablewhen the host config itself can't be read. - Repo-sync/diff logic (used for things like merges and worktree checks) now detects files that are actually the machine's own Claude Code configuration linked in under another name, and withholds them with two new reasons:
withheld_host_config(configuration linked under another name) andwithheld_config_unexamined(the configuration couldn't be fully examined). - File-scan summaries gained a
skipped_host_configcounter, alongside existing counters likeskipped_sensitive_trackedandskipped_read_denied. - Write protection recognizes the same two cases for writes: the target is the machine's own configuration under another name, or the configuration couldn't be fully examined (unreadable link/directory, or too many entries).
- File-refusal classification for restricted reads gained its own
host_configreason, previously lumped in withread_denied/not_regular_file, and it's now counted among refusal reasons treated as sensitive/blocked.
Why
This stops Claude Code from treating your own configuration files as generic unreadable or sensitive files when they're reached through a symlink or alias, giving clearer, more specific explanations across reads, writes, and file scans.