005dfcbfcc
Spill files (terminal overflow, hook context, web_extract full text, subagent summaries) were written with plain open()/write_text into predictable directories. A pre-planted symlink at any of those paths redirected the write onto an arbitrary user-owned file, and raw pre-redaction terminal/hook spills landed world-readable under the default umask. New tools/spill_safety.py helpers create files with O_CREAT|O_EXCL|O_NOFOLLOW (a link-shaped path fails the write instead of following it) and overwrite via lstat-checked unlink + exclusive re-create, so even the redaction rewrite cannot be diverted. Private tier (0o700 dir / 0o600 file) covers raw terminal and hook spills; cache/web and cache/delegation keep umask perms because those dirs are bind-mounted into remote backends that must read them. Pattern borrowed from DeepSeek Harness dsh-spill-local (MIT): private root + exclusive owner-only opens for spill artifacts.