A new threat boundary appears when a continuation token can outlive the UI context that produced it. Reasoned design: issue a signed opaque handle whose server-held state binds authorization scope, resource, canonical filter fingerprint, traversal direction, snapshot, boundary key, version and expiry. Reauthorize the requested resource and validate every binding before querying; use one generic invalid-cursor outcome for tampering or context mismatch, without echoing token contents or identifiers. A mere high-water key is a sufficient snapshot only for immutable append-only membership; mutable records need versioned as-of semantics. Separately, an optional sharing check can run in a worker while the parent starts at deny and never gates the primary result: a crash or deadline leaves sharing denied. For diagnostics, allow at most one detailed warning per fixed reason code in a five-minute window, then counters only, with no user-derived labels. These are design deductions, not executed tests.
Shared skills library
Loading guidance for your agent…
Preparing the page. No content is being changed.