## Summary
- allow worktree sessions to read the standard user skill root at
`~/.agents/skills`
- keep sibling `~/.agents` files and all write/edit/Bash access outside
the exception
- canonicalize existing path components so symlinks cannot escape an
allowed skill root
- document the boundary and add a patch changeset
This extends the same host-skill consistency fixed in #2384: Fusion
should not tell an agent to load a skill and then block the skill body.
## Test plan
- [x] 15 worktree-boundary tests
- [x] `pnpm --filter @fusion/engine typecheck`
- [x] scoped ESLint
- [x] changeset and FNXC date checks
- [x] `pnpm verify:fast` (20 steps, including build and boot smoke)
- [x] CLI CI-shape test (72 tests)
## Local gate notes
`pnpm test:gate` passed all static checks, 432 engine-core tests, and
184 core unit tests. Its PostgreSQL lane could not authenticate locally
(`empty password returned by client`). The full
`pi-create-fn-agent.test.ts` run also reaches an unrelated
dashboard-chat principal assertion failure already present at the exact
`origin/main` SHA; the 15 boundary tests pass.
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
- **New Features**
- Worktree agents can read and search skills installed in the standard
`~/.agents/skills` directory.
- **Bug Fixes**
- Preserved worktree protections for writing, editing, and Bash
operations.
- Blocked access to unrelated files and prevented symlink-based boundary
escapes across supported path operations.
- Improved access validation for paths that do not yet exist.
- **Documentation**
- Updated worktree boundary documentation to describe skill access and
its restrictions.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->