Session Guard

作者 wshobson46891e7e60da无许可证收录于 2026年10月8日更新于 2026年10月8日

Use when working on complex multi-step tasks, when a session is getting long (40+ tool calls), when the agent starts ignoring rules it followed earlier, when conventions drift, when output quality seems to degrade, or after any context compaction event. Prevents long-session corruption AND context compaction amnesia through behavioral self-enforcement.

仅含说明AI & Agents
AI 生成的概览

一套行为协议,帮助智能体监控长会话、在上下文压缩后锚定规则,并在质量下降前拆分任务。

功能
Session Guard 为长时间运行的智能体会话定义了一套自我约束协议。它列出带阈值的健康信号(工具调用次数、规则矛盾、风格漂移、意外的文件读取、范围失控),并规定相应动作,如记录检查点、复述关键规则、对照源文件核验,以及拆分到新会话。它还说明上下文压缩中哪些内容会保留、哪些会丢失,并建议把关键指令放在文件中而不是对话里。
适用场景
适用于复杂的多步骤任务、会话超过约 40 次工具调用、智能体开始与先前决策矛盾或偏离约定、输出质量似乎下降,或发生任何上下文压缩事件之后。
运行要求
无需软件包、数据库或脚本,仅为指令。它假定智能体能够重新读取项目规则文件,例如 CLAUDE.md 或 CONTEXT.md。

Session Guard

Overview

Long sessions corrupt silently. Context compaction drops instructions unannounced. Hooks don't fix it (confirmed by multiple developers on GitHub issues #19471, #9796, #64171). This skill prevents both through behavioral self-enforcement: monitor health, anchor critical rules through compaction, split before damage occurs. No packages, no databases - pure behavioral enforcement that works in every harness.

When to Use

  • Session exceeds 40 tool calls
  • Agent contradicts earlier decisions
  • Style/naming conventions start drifting
  • After any context compaction event
  • Task scope growing unbounded

Health Signals

SignalThresholdAction
Tool call count>40YELLOW: checkpoint + recite critical rules
Tool call count>60RED: split or compact with anchor
Agent contradicts earlier decisionAnyVERIFY: re-read source of truth
Style/naming driftAnyRECITE: state the active rules aloud
File read returns unexpected contentAnyRE-READ: don't trust cached state
Task scope growing unboundedContinuousSPLIT: one task per session

Protocol

Green Zone (0-40 tool calls)

Normal operation. No intervention needed.

Yellow Zone (40-60 tool calls)

  1. CHECKPOINT - summarize progress in one paragraph
  2. RECITE - state the 3-5 most critical active rules aloud: "Active rules: [naming convention], [file structure], [error handling pattern], [testing requirement]"
  3. ASSESS - almost done? Push through. Not done? Prepare split.
  4. REDUCE - no exploratory reads. Only targeted operations.

Red Zone (60+ tool calls OR drift signal)

  1. STOP - do not make more tool calls
  2. VERIFY - re-read project rules (don't trust memory)
  3. CHECKPOINT - write state to handoff document
  4. SPLIT - create handoff, suggest fresh session

Context Anchoring (anti-compaction)

When compaction has occurred (sudden loss of earlier context, or after /compact):

  1. RE-READ the project's rules file immediately
  2. RECITE the 3-5 critical rules aloud in your response
  3. VERIFY your planned next action matches those rules before executing
  4. If uncertain about ANY prior decision, RE-READ the source file - don't guess

What survives compaction:

  • Most recent user messages (high priority)
  • Currently-invoked skill body (capped at 5K tokens, oldest dropped first)
  • Git status and project structure
  • File contents read AFTER compaction

What gets LOST in compaction:

  • Decisions made early in conversation
  • Architectural rules stated only verbally (not in files)
  • Context from tool outputs (file reads, command outputs)

Compaction-Safe Pattern

Keep critical instructions in FILES (CLAUDE.md, CONTEXT.md), NOT in conversation. If a rule matters, it must live in a file the agent can re-read - not in something agreed on earlier.

Common Mistakes

  • Trusting that you remember the rules after 50+ tool calls (you don't - re-read)
  • Re-reading EVERYTHING to be safe (wastes tool calls - be targeted)
  • Feeling fine therefore assuming context is fine (compaction is SILENT)
  • Splitting AFTER noticing problems (split BEFORE - prevention, not recovery)

Why This Matters

Context compaction is the #1 unsolved platform problem in 2026. Hooks don't fix it (confirmed: the agent ignores post-compaction injections because the compaction summary creates narrative momentum). This skill is the lightweight behavioral countermeasure: no infrastructure, no packages - disciplined self-monitoring that works in every harness.

来源与署名

来源:wshobson/agents位于plugins/skill-forge-essentials/skills/session-guard提交46891e7

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架