What
When you uninstall a plugin, Claude Code reads a settings file to see whether the plugin is enabled. That read now checks the file's path for links and symlinks first. A symlink is a file that points to another file somewhere else. If the path looks unsafe, Claude Code skips the file and logs a message saying it was not read, with a short reason such as suspect-link or crossing.
Before this change, the only check was for network paths, and the file was then read directly.
Why
This makes it harder for a planted symlink to make Claude Code read a file it should not read during an uninstall.
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubt
It is not clear what a user sees when a settings file is refused, beyond the logged message.