Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Preserve authoritative task requirements, acceptance criteria, bounded native-plan state, delegated-agent results, and verified evidence across Codex context compaction. Use for long or complex tasks, Goal work, resumed sessions, subagent workflows, explicit context-guard controls, redacted or successor handoff exports, or whenever completion must be checked against an immutable local requirement ledger.
.claude/skills/hashgraph-online-context-guard/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-08 | ✗→✓ | ▲ Improved | 70% | 0% |
| case-09 | ✗→✓ | ▲ Improved | 124% | 0% |
| case-11 | ✗→✓ | ▲ Improved | 312% | 0% |
| case-15 | ✗→✓ | ▲ Improved | 501% | 0% |
| case-05 | ✓→✗ | ▼ Worse | 143% | 0% |
Keep task correctness grounded in the plugin's private local ledger instead of relying on conversational memory.
CONTEXT-GUARD RECOVERY PACKET as authoritative recovery context.returns all reconstructed requirements to pending and requires fresh evidence.
paths, or requirement maps in the user-facing response.
a completion checkpoint.
stage-disposition command only when one of these typed boundaries is true:
user_wait: the next required action belongs to the user;external_wait: progress depends on an external actor or system;deferred: the remaining action is explicitly denied or outside thecurrent bounded scope. Continue authorized assistant work by calling tools before ending the turn. The legacy continue disposition remains wire-compatible but is advisory only: it cannot force a Stop continuation or override a terminal reply. The command performs a read-only precheck; the PostToolUse Hook writes the authenticated, turn-bound control. A different staged control requires the explicit --replace flag. If no disposition is staged, Stop yields safely and every unverified item remains pending.
checkpoint-status command injected for the current turn.verification.mode. legacy_fallback intentionallyuses the compatible successful-evidence rule and remains visible as a degradation. For enforced, satisfy every listed obligation.
E#### evidence printed by that command. Plain-texttool output without a structured success status or an exact authoritative completion marker is recorded as unknown and cannot close an item. For string-only shell tools, make the verification command fail on any unmet condition and print a final standalone Script completed or Command completed line only after every check passes. The marker is exact and must not have trailing punctuation.
injected register-proof --manifest /path/to/proof.json command. A proof binds the item, obligation, successful evidence, surface, and subjects. Visual inspection records immutable asset-bound facts; result readback uses a distinct hashed asset and resolves every fact. Scope proofs provide normalized expected and observed identifiers; the runtime computes counts and hashes, requires the expected set to match the prompt-derived cardinality/digest, and rejects a proper subset. Qualitative uses of all/完整 without a constructible expected scope remain visibly legacy_fallback rather than becoming an enforced contract.
stage-checkpoint command with one--requirement ID=E####[,E####] flag for each pending requirement and one --acceptance ID=E####[,E####] flag for each pending acceptance item. The command performs a read-only precheck; the PostToolUse Hook commits the request to private plugin data outside the workspace sandbox.
complete is not a stage-disposition value; it is derived only from a validated private checkpoint.
checkpoint or disposition footer. The Stop Hook validates the private turn-bound record.
Previously passed items carry their authenticated evidence forward. A new user turn invalidates any unstaged or unused completion attempt from the prior turn.
update_plan, Goal mode, compaction, subagentorchestration, permissions, worktrees, transcripts, and memories.
update_plan call. Continue to update the native plan through Codex tools.
always apply.
AGENTS.md or checked-in documentation. Donot copy them into the private ledger unless the current user prompt makes them task-specific requirements.
subagent_delegation prompt as delegated scope, not as a root-userrequirement or supersession.
currently running subagent corroborates it. The wrapper alone is not an authority boundary.
result labeled Outcome, Evidence, Validation, Limitations, and Next.
integration, requirement-to-evidence mapping, and the final completion gate.
Return only evidence-bearing conclusions and artifact references.
$context-guard or context-guard on: activate full protection.context-guard off: stop recovery and completion gating; prompt journaling continues.context-guard status: show protected state without exposing raw prompts.context-guard diagnose: show bounded protocol/control sources, declareddispositions, diagnostic outcomes, reason codes, and hashes without raw prompts or replies.
context-guard export <path>: write a redacted handoff document inside the current project..codex/context-guard/CONTEXT_HANDOFF.md.context-guard rollover <directory>: after the user explicitly requests asuccessor pack, validate .codex/context-guard/SUCCESSOR_INPUT.json and write a bounded handoff plus hash manifest. Read references/successor-pack.md before preparing that input.
The rollover command never creates, activates, retires, archives, or authorizes a task. Creating a successor remains a separate user-authorized action.
The immutable raw prompt ledger is the fact source. Recovery summaries and private completion checkpoints are derived indexes. Never commit plugin runtime data, proof manifests, raw prompts, transcripts, credentials, tokens, or plugin caches. Multimodal contracts retain only bounded metadata, hashes, dimensions, availability, and redacted visual facts; they do not retain image bytes. Export only when the user explicitly requests it; exported handoffs are redacted by default. Transcript attachment recovery is incremental during tool use and retried at compaction/resume; bounded recovery clipping always preserves the completion rule.
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-01 | fail→fail | 10,887 | 14,259 | +31% | 1 | 1 | 0% | 1,716 | 1,933 | +13% | 0 | 0 | — |
case-02 | fail→fail | 10,423 | 13,885 | +33% | 1 | 1 | 0% | 699 | 2,200 | +215% | 0 | 0 | — |
case-03 | fail→fail | 13,591 | 6,963 | -49% | 1 | 1 | 0% | 1,512 | 2,102 | +39% | 0 | 0 | — |
case-04 | fail→fail | 7,893 | 24,998 | +217% | 1 | 1 | 0% | 1,265 | 4,338 | +243% | 0 | 0 | — |
case-05 | pass→fail | 8,047 | 10,931 | +36% | 1 | 1 | 0% | 761 | 1,847 | +143% | 0 | 0 | — |
case-06 | fail→fail | 3,239 | 15,880 | +390% | 1 | 1 | 0% | 455 | 2,617 | +475% | 0 | 0 | — |
case-07 | pass→pass | 10,567 | 14,065 | +33% | 1 | 1 | 0% | 1,015 | 3,221 | +217% | 0 | 0 | — |
case-08 | fail→pass | 18,055 | 11,468 | -36% | 1 | 1 | 0% | 2,239 | 3,809 | +70% | 0 | 0 | — |
case-09 | fail→pass | 11,744 | 16,412 | +40% | 1 | 1 | 0% | 1,770 | 3,968 | +124% | 0 | 0 | — |
case-10 | pass→pass | 6,146 | 4,875 | -21% | 1 | 1 | 0% | 809 | 2,545 | +215% | 0 | 0 | — |
case-11 | fail→pass | 4,338 | 6,286 | +45% | 1 | 1 | 0% | 633 | 2,610 | +312% | 0 | 0 | — |
case-12 | fail→fail | 7,929 | 7,505 | -5% | 1 | 1 | 0% | 1,072 | 2,970 | +177% | 0 | 0 | — |
case-13 | fail→fail | 7,244 | 51,584 | +612% | 1 | 1 | 0% | 1,071 | 2,184 | +104% | 0 | 0 | — |
case-14 | fail→fail | 12,220 | 11,155 | -9% | 1 | 1 | 0% | 1,697 | 2,052 | +21% | 0 | 0 | — |
case-15 | fail→pass | 8,146 | 31,991 | +293% | 1 | 1 | 0% | 1,091 | 6,555 | +501% | 0 | 0 | — |
case-16 | fail→fail | 7,822 | 10,527 | +35% | 1 | 1 | 0% | 685 | 3,201 | +367% | 0 | 0 | — |
case-17 | fail→fail | 5,464 | 9,617 | +76% | 1 | 1 | 0% | 839 | 3,304 | +294% | 0 | 0 | — |
case-18 | pass→pass | 9,128 | 13,835 | +52% | 1 | 1 | 0% | 1,257 | 4,105 | +227% | 0 | 0 | — |
case-19 | pass→pass | 6,692 | 14,676 | +119% | 1 | 1 | 0% | 776 | 4,221 | +444% | 0 | 0 | — |
case-20 | pass→pass | 12,206 | 5,371 | -56% | 1 | 1 | 0% | 1,632 | 2,546 | +56% | 0 | 0 | — |
case-21 | fail→fail | 9,751 | 9,825 | +1% | 1 | 1 | 0% | 1,315 | 2,122 | +61% | 0 | 0 | — |
case-22 | fail→fail | 13,729 | 2,876 | -79% | 1 | 1 | 0% | 1,820 | 2,161 | +19% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 22 cases were attempted, and 13 counted toward the lift figure. The other 9 produced results that are not comparable between the two arms, so they are excluded from the headline rather than averaged into it. The headline lift of +14 percentage points is the difference between those two pass rates over the 13 comparable cases. 4 cases got worse with the skill loaded, and they are included in that figure.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.