{"version":"2.1.284","anchor":"symlinked-clauderules-that-point-outside-the-project-now-n","canonical_anchor":"symlinked-clauderules-that-point-outside-the-project-now-n","heading":".claude\/rules from outside the project now need external-include approval","tier":"notice","area":"Permissions","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.284\/e\/symlinked-clauderules-that-point-outside-the-project-now-n","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.284","markdown":"### `.claude\/rules` from outside the project now need external-include approval\n\nA symlinked `.claude\/rules` pointing outside the project is skipped unless external includes are approved, and the warning now names `.claude\/rules`\n\n**Unclear.** The exact set of cases in which a symlinked rules folder is now skipped is not fully clear.\n\n**What**\n\n`.claude\/rules` is a project folder of instruction files that Claude Code loads alongside `CLAUDE.md`. A symlink is a shortcut that points to another location on disk.\n\n- If a project's `.claude\/rules` is a symlink to somewhere outside the project, it is now skipped when external includes are off. The exception is a location inside a directory loaded through `CLAUDE_CODE_ADDITIONAL_DIRECTORIES_CLAUDE_MD`. It is also loaded if the project already has external includes approved (`hasClaudeMdExternalIncludesApproved`).\n\n- Before, only entries inside the rules folder were checked this way, not a symlinked rules folder itself.\n\n- Loaded rule files now record where they were linked from.\n\n- Loading from additional directories has been reorganised, with the same behaviour as before.\n\n- The warning about project memory importing files from outside the current folder now reads: 'This project's CLAUDE.md or .claude\/rules imports files outside the current working directory. Never allow this for third-party repositories.'\n\n**Why**\n\nA repository could otherwise pull instructions into Claude from anywhere on your machine through a symlinked rules folder. That now needs the same approval as other outside imports, so be careful before allowing it for repositories you did not write.\n\n- Area: Permissions\n- Tier: You'll notice\n- Useful: 2\/5\n- Signal: 1\/5"}