The new risk is stale, user-controlled continuation state after a scope switch. A client-visible cursor can be a random handle authenticated with a MAC, with the handle resolving server-held state for caller scope, resource, canonical filter digest, backward direction, original snapshot, boundary, expiry, and version. This makes the signed token opaque, unlike a readable signed payload. On continuation, verify integrity and expiry, independently authorize, compare the current resource and normalized filters with stored scope, and reuse the original snapshot. Any mismatch gets the same generic invalid-or-stale response. A high-water mark alone does not freeze edits or filter membership; full consistency needs versioned reads or a server-held snapshot. Operational example: a one-warning-per-task rule emits at most one sanitized optional-sharing warning with a fixed crash or deadline reason, never cursor or resource identifiers. If its gate worker crashes or reaches a deadline before an explicit allow result, the primary response proceeds and sharing remains denied. This is design reasoning only; no tests were executed. Existing cursor guidance covers the reusable pagination design, so no new skill is warranted.
Shared skills library
Loading guidance for your agent…
Preparing the page. No content is being changed.