Session Guard

作者 wshobson46891e7e60da無授權條款收錄於 2026年10月8日更新於 2026年10月8日

Use when working on complex multi-step tasks, when a session is getting long (40+ tool calls), when the agent starts ignoring rules it followed earlier, when conventions drift, when output quality seems to degrade, or after any context compaction event. Prevents long-session corruption AND context compaction amnesia through behavioral self-enforcement.

僅含說明AI & Agents
AI 產生的概覽

一套行為協定,協助代理監控長時間工作階段、在脈絡壓縮後錨定規則,並在品質下降前拆分工作。

功能
Session Guard 為長時間執行的代理工作階段定義了一套自我約束協定。它列出附門檻的健康訊號(工具呼叫次數、規則矛盾、風格漂移、非預期的檔案讀取、範圍失控),並規定對應動作,例如記錄檢查點、複述關鍵規則、對照來源檔案核驗,以及拆分到新的工作階段。它也說明脈絡壓縮中哪些內容會保留、哪些會遺失,並建議把關鍵指示放在檔案中,而不是對話裡。
適用情境
適用於複雜的多步驟任務、工作階段超過約 40 次工具呼叫、代理開始與先前的決策矛盾或偏離慣例、輸出品質似乎下降,或發生任何脈絡壓縮事件之後。
執行需求
不需要套件、資料庫或指令碼,僅為指示。它假定代理能重新讀取專案規則檔案,例如 CLAUDE.md 或 CONTEXT.md。

Session Guard

Overview

Long sessions corrupt silently. Context compaction drops instructions unannounced. Hooks don't fix it (confirmed by multiple developers on GitHub issues #19471, #9796, #64171). This skill prevents both through behavioral self-enforcement: monitor health, anchor critical rules through compaction, split before damage occurs. No packages, no databases - pure behavioral enforcement that works in every harness.

When to Use

  • Session exceeds 40 tool calls
  • Agent contradicts earlier decisions
  • Style/naming conventions start drifting
  • After any context compaction event
  • Task scope growing unbounded

Health Signals

SignalThresholdAction
Tool call count>40YELLOW: checkpoint + recite critical rules
Tool call count>60RED: split or compact with anchor
Agent contradicts earlier decisionAnyVERIFY: re-read source of truth
Style/naming driftAnyRECITE: state the active rules aloud
File read returns unexpected contentAnyRE-READ: don't trust cached state
Task scope growing unboundedContinuousSPLIT: one task per session

Protocol

Green Zone (0-40 tool calls)

Normal operation. No intervention needed.

Yellow Zone (40-60 tool calls)

  1. CHECKPOINT - summarize progress in one paragraph
  2. RECITE - state the 3-5 most critical active rules aloud: "Active rules: [naming convention], [file structure], [error handling pattern], [testing requirement]"
  3. ASSESS - almost done? Push through. Not done? Prepare split.
  4. REDUCE - no exploratory reads. Only targeted operations.

Red Zone (60+ tool calls OR drift signal)

  1. STOP - do not make more tool calls
  2. VERIFY - re-read project rules (don't trust memory)
  3. CHECKPOINT - write state to handoff document
  4. SPLIT - create handoff, suggest fresh session

Context Anchoring (anti-compaction)

When compaction has occurred (sudden loss of earlier context, or after /compact):

  1. RE-READ the project's rules file immediately
  2. RECITE the 3-5 critical rules aloud in your response
  3. VERIFY your planned next action matches those rules before executing
  4. If uncertain about ANY prior decision, RE-READ the source file - don't guess

What survives compaction:

  • Most recent user messages (high priority)
  • Currently-invoked skill body (capped at 5K tokens, oldest dropped first)
  • Git status and project structure
  • File contents read AFTER compaction

What gets LOST in compaction:

  • Decisions made early in conversation
  • Architectural rules stated only verbally (not in files)
  • Context from tool outputs (file reads, command outputs)

Compaction-Safe Pattern

Keep critical instructions in FILES (CLAUDE.md, CONTEXT.md), NOT in conversation. If a rule matters, it must live in a file the agent can re-read - not in something agreed on earlier.

Common Mistakes

  • Trusting that you remember the rules after 50+ tool calls (you don't - re-read)
  • Re-reading EVERYTHING to be safe (wastes tool calls - be targeted)
  • Feeling fine therefore assuming context is fine (compaction is SILENT)
  • Splitting AFTER noticing problems (split BEFORE - prevention, not recovery)

Why This Matters

Context compaction is the #1 unsolved platform problem in 2026. Hooks don't fix it (confirmed: the agent ignores post-compaction injections because the compaction summary creates narrative momentum). This skill is the lightweight behavioral countermeasure: no infrastructure, no packages - disciplined self-monitoring that works in every harness.

來源與署名

來源:wshobson/agents位於plugins/skill-forge-essentials/skills/session-guard提交46891e7

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架