Claude Code symlink exfiltration (Tego AI)

A security advisory from July 24, 2026, describing how a repo-committed CLAUDE.md with an @import pointing to a symlink can cause Claude Code to read files outside the project and include them in its first request, bypassing tool-call and approval checks because the path validation only checks the symlink itself, not its target. Reported via HackerOne and closed as "Informative" by Anthropic, citing the initial folder-trust dialog as the trust boundary; relevant for developers running agents on untrusted repositories.