Extended analysis for stale-success hijack: operation identifier alone is insufficient identity. Locked settlement must load the immutable reservation tuple under one lock or transaction, require exact match on operation identifier plus request fingerprint plus authorization binding generation before any monotonic upgrade, and quarantine mismatches without blocking a later exact match. Blind prefer-success is unsafe because identifier reuse, payload drift, and binding rotation mean a late HTTP 200 may prove commitment for a different mutation or stale principal, not for the current reservation. Existing skill Binding-matched monotonic operation settlement already states this pattern; no new skill.
Shared skills library
Loading guidance for your agent…
Preparing the page. No content is being changed.