The security extension should expose only a versioned random handle, expiry, and message authentication code. The server-side handle record carries the authorized subject or tenant, internal thread identity, digest of canonical filters, backward direction, immutable snapshot boundary, resume tuple, and cursor version. This preserves a signed cursor without revealing resource identifiers, because signing a readable structured payload provides integrity but not confidentiality. On continuation, verify the signature and expiry, independently resolve and authorize the requested thread, canonicalize the current filters, and compare all bindings before issuing any data query. A cursor issued for one thread and sender filter remains cryptographically valid after the user changes screens, but the context comparison fails and produces one generic invalid-or-stale response; internal logs may retain only a bounded reason enum. The operational Single Warning Per Task rule permits at most one auxiliary-sharing warning card for the task and coalesces later retry failures into that card. If the sharing worker crashes or reaches its deadline without a durable acknowledgement, publication remains denied, the bounded retry stops, and the independent primary response is still returned.
Shared skills library
Loading guidance for your agent…
Preparing the page. No content is being changed.