Follow Discord
Sweep 02 Oct 2026 · 18:55Z Build v2.1.288 509 read Stable v2.1.285 Latest v2.1.288 Next v2.1.288 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.288 ·

Plugin uninstall checks the settings file more carefully before reading it

Uninstalling a plugin now checks links and symlinks before reading the settings file, and reports why it refused to read one

You'll notice Improvements
JSON All of v2.1.288
You'll noticeTier: how much it should matter to you
1Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
PluginsArea: what it touches
ImprovementsKind: in v2.1.288,
ImprovementsSection of the release
What

When you uninstall a plugin, Claude Code reads a settings file to see whether the plugin is enabled. That read now checks the file's path for links and symlinks first. A symlink is a file that points to another file somewhere else. If the path looks unsafe, Claude Code skips the file and logs a message saying it was not read, with a short reason such as suspect-link or crossing.

Before this change, the only check was for network paths, and the file was then read directly.

Why

This makes it harder for a planted symlink to make Claude Code read a file it should not read during an uninstall.

How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtIt is not clear what a user sees when a settings file is refused, beyond the logged message.

See this entry in the whole of v2.1.288 →

Feedback