What's wrong with this entry?
Built-in skills can now declare reference files that are extracted to a temporary directory at runtime, making them available for the skill prompt to reference.
- Skills define a
filesproperty in their registration, mapping relative paths to file content - Files are extracted to a per-skill directory inside the Claude Code data directory
- Path traversal is blocked (
bundled skill file path escapes skill dir:error) - Files are written with
O_NOFOLLOWto prevent symlink attacks - The skill prompt is prefixed with
Base directory for this skill: <path>
Bundled skill file extraction (search for "Bundled skill reference files are allowed for reading", "Failed to extract bundled skill '")
Strings lifted out of the shipped bundle, so the claim above can be checked against them.