# Session- and auth-bound task context cache

Key and lifecycle in-process task-context caches by session id and live auth generation so shared-process sessions and mid-session auth replace cannot leak or reuse stale context.

Exact reference: {"kind":"skill_version","skill_id":"skl_wCKU3ytdp9mfmqZocBWzrA","version_id":"skv_s3oNWCXsWJw0GFwHtHTqhA"}

Applicability: []

# Session- and auth-bound task context cache

## When to use
Use when an agent plugin caches task context before a system-message transform, multiple root or child sessions share one process, and authorization may be revoked or replaced while that process and root session stay alive.

## Steps
1. Key every entry as the pair sessionId plus authGeneration. Carry only sessionId in request scope such as AsyncLocalStorage. Resolve authGeneration from the live authorization handle for that auth lineage at write, read, and inject time—never from a module-level current pointer and never from an ALS-cached generation alone.
2. Look up by the full composite key. Do not select by sessionId alone. Missing or generation mismatch injects empty or default. Never fall back to parent, sibling, last-writer, or a prior generation.
3. Default-isolate child sessions. If inheritance is required, copy-on-create a snapshot into the child key; never share a mutable object with the parent. Children must read the live parent auth handle for generation checks. Maintain a parent-to-child or auth-lineage index so revoke sweeps every tied key, including children created during the bump.
4. On write commit and on inject or read, require entry.authGeneration equals live.authGeneration. Reject publishes whose sampled generation is no longer live at commit time.
5. On revoke or replace, in one critical section: bump generation, delete or tombstone older lineage entries, then publish the new credential only if live.authGeneration still equals the bumped value.
6. Treat injected context as prompt data only—never as a network credential. Every outbound network or tool call must present a capability bound to the current generation; mismatch fails closed. Cancel work that will take another hop; do not assume already-gated single-shot I/O is recalled.
7. Bound memory: cap entry count, bytes per entry, and total bytes; prefer delete-on-bump and session dispose; use LRU plus TTL for orphans; store slim summaries. Do not recycle a sessionId while an orphaned composite entry for that id may remain, or else use a process-wide epoch or otherwise unique generation space so restarted counters cannot collide.

## Limits
- Does not scrub prompt text already injected into an in-flight model turn before a bump.
- Cannot recall bytes already on the wire; re-check live generation before applying response side effects.
- Support for this guidance is reasoned analysis and independent design review, not executed tests.

## Failure prevented
Prevents cross-session context injection, late-writer reinstall of a revoked generation, child snapshot races across parent auth replace, and same-session auth-rotate paths where stale cache entries authorize network activity or reappear under a recycled session identity.

## Supporting basis and limitations

Update grounded in reasoned design analysis from the cited native conversation: session-scoped isolation, composite sessionId plus authGeneration keys, bump-first invalidation, network fail-closed checks, plus independent subagent review findings on late writers after bump, child-create versus parent-revoke races, session-id reuse against orphaned generation keys, session-id-only lookup contradicting composite keys, and next-hop network windows. No repository inspection and no executed tests were performed.

## Change and rationale

Tighten child auth-lineage binding, require composite lookup on every read path, and block session-id reuse collisions with orphaned generation keys after independent design review.

Session-only keys and global current-context slots leak under concurrency. Auth replace without write-time generation compare-and-set, live parent binding for children, and non-reuse of session identities leaves stale or colliding entries that can inject or authorize after revoke.
