session-tracker
Checkpoints multi-step work to disk so a crashed or dropped session can be resumed rather than redone. Use when a task has two or more steps AND writes files or generates code AND losing mid-task state would be costly; when resuming after a session drop; or when the user asks for crash-resilient.
Rank
62
Safety
84
Downloads
1.2k
Updated
Oct 11, 2026
Version
2.6.1
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1.2K downloads reported by the source. Last updated 10/11/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 11, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 11, 2026
- Adoption signal
- 1.2K downloadsadoption · observed Oct 11, 2026
- Latest release
- 2.6.1release · observed Sep 19, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s173ygxbz6mwm1ttp918wzyced84qty5:session-tracker- Install using `clawhub skill install s173ygxbz6mwm1ttp918wzyced84qty5:session-tracker` in an isolated environment before connecting it to live workloads.
- No published capability contract is available yet, so validate auth and request/response behavior manually.
- Review the upstream CLAWHUB listing at https://clawhub.ai/darkd/session-tracker before using production credentials.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-darkd-session-tracker/snapshot"
Documentation
CLAWHUB
144,266 characters of source documentation, loaded on request.
Extracted files
5 files captured from the source.
SKILL.md
---
name: session-tracker
description: "Checkpoints multi-step work to disk so a crashed or dropped session can be resumed rather than redone. Use when a task has two or more steps AND writes files or generates code AND losing mid-task state would be costly; when resuming after a session drop; or when the user asks for crash-resilient tracking. Do not use for single-step tasks, read-only analysis, trivial lookups, exploratory conversation, or anything involving credentials or paths that should not persist. Writes JSON state to .session/ only: task name, step list, agent-declared file paths, worklog entries — never file contents. Filesystem scanning is off by default; status does not scan unless --fs-scan is passed. No network, no eval, no environment harvesting. Optional opt-in extras: a detached 24h-bounded monitor, and a cross-session journal. Restored content is fenced and labelled as untrusted data. cleanup is irreversible and requires an ownership marker plus --force."
permissions:
filesystem_read:
when: "scan, status --fs-scan, init --fs-scan, or monitor (opt-in; OFF by default)"
scope: "download/, upload/, uploads/, .session/ under the project root"
filesystem_write:
when: "init/step/file/log/sync/done/cleanup/prune"
scope: ".session/ only"
stdin_parsing:
when: "sync with piped input"
format: "TodoWrite JSON (validated; must be an array)"
subprocess_spawn:
when: "monitor --start (opt-in)"
details: "re-executes same script; 24h max runtime; minimal env; output to .session/monitor.log"
process_signal:
when: "monitor --stop or cleanup"
details: "SIGTERM then SIGKILL; fails closed unless PID identity is positively confirmed"
network: false
eval_exec: false
file_content_reading: false
env_harvesting: false
---
# session-tracker v2.6.1
Track, checkpoint, and resume multi-step tasks across session interruptions.
Init once, recover anytime, minimal footprint by default.
## When to use
Use when **all** of these hold:
- the task has **2 or more distinct steps**, and
- it involves **file modifications, code generation, or multi-document pipelines**, and
- losing mid-task state to a crash, timeout, or disconnect would be **costly to redo**.
Do **not** use when any of these hold:
- **Single-step tasks** — "read this file and summarize", "what time is it"
- **Read-only analysis** that produces no files
- **Trivial lookups** — quick questions, fact retrieval, single API calls
- **Privacy-sensitive tasks** — credentials, secrets, or paths that should not persist to `.session/`
- **The user declines** — "don't track this", "just do it, no logging"
- **Ephemeral interactive work** — exploration, debugging, ad-hoc questions
This is a conditional safety net. For anything outside the criteria above, skip it.
## Why init comes first
The value comes entirely from being initialized *before* a crash, not after.
If `init` ran first, a drop leaves a full recovery trail and the next agent
picks up wh_meta.json
{
"ownerId": "kn748ry7kee0pzs6aac7e4tswd84q2zm",
"slug": "session-tracker",
"version": "2.6.1",
"publishedAt": 1789813805370
}references/CHANGELOG.md
# session-tracker — changelog
## Changelog
### v2.4-superz → v2.5 (security hardening)
**A.I.G findings (5):**
- **T09 (Critical)**: Import-time guard rejects dangerous `SESSION_TRACKER_DIR`; `cleanup` re-checks realpath; new `--dry-run` flag.
- **T05 (High)**: `monitor.pid` records `{pid, start_time, session_id}`; `stop_monitor`/`doctor` validate process identity via `/proc/<pid>/stat` before signaling.
- **T02 (Medium ×2)**: `crash-detect`/`resume` label restored content as UNTRUSTED DATA; `init` aborts on orphan, requires `--replace`; secret-redaction rule added to skill instructions.
- **T01 (Error/High)**: MUST language replaced with "Use when:" trigger list + "Do NOT use for" exclusion criteria.
**SkillSpector findings:**
- **Lp3 (95%)**: Machine-readable `permissions:` block added to YAML frontmatter.
- **Tp4 (93%)**: Description now discloses PID-identity validation, init-aborts-on-orphan, untrusted-data labeling, dangerous-path guard, dry-run.
- Description-behavior mismatch (96%): retained v2.4 fix (`status` no longer scans by default).
**Code changes:**
- `_pid_start_time()`, `_read_monitor_pid_record()`, `_is_our_monitor()` helpers (T05).
- `_DANGEROUS_PATHS` frozenset + import-time + cleanup-time guards (T09).
- `cmd_init`: `--replace` flag; aborts on orphan unless `--replace` (T02).
- `cmd_crash_detect` / `cmd_resume`: UNTRUSTED DATA labeling (T02).
- `cmd_cleanup`: `--dry-run` flag; realpath re-check (T09).
- `cmd_monitor`: writes JSON PID record with `start_time` + `session_id` (T05).
- `stop_monitor`: PID-identity validation before signaling (T05).
- `cmd_doctor`: uses `_is_our_monitor` for liveness check (T05).
- Version bumped to 2.5.0; test suite extended from 27 to 43 assertions.
### v2.3 → v2.4-superz (production dogfooding)
See PROVENANCE.md for the full dogfooding notes. Key additions: orphan archive, journal, doctor, stats, freshness fix, ad-hoc steps, string IDs in sync, portability (`SESSION_TRACKER_DIR`).
### v2.2 → v2.3 (first audit response)
Data minimization (no baseline FS snapshot on `init`), `--auto-cleanup`, `prune`, monitor hardening (log file, minimal env, 24h cap), cleanup confirmation, permissions declaration.
## Research basis
v2.5 incorporates patterns from analogous skills and the wider agent ecosystem:
- **session-fork v2.4.18** (ClawHub): `--dry-run` for destructive ops; boundary-statement pattern.
- **self-improving agent v4.0.2** (ClawHub): "Use when:" trigger list; explicit untrusted-data labeling in restored content; secret-redaction rule.
- **Skill Vetter v1.0.0** (ClawHub): negative-permission "What this skill does NOT do" section (kept from v2.3).
- **LangGraph** (LangChain): explicit run-status enum; `pending_writes` for mid-flight tracking (noted as future enhancement).
- **systemd / K8s**: PID file with `{pid, start_time}` record (T05 fix); watchdog/liveness-probe thresholds.
- **Codex `/rewind`**: named checkpoints with selective restore (noted as future enhancement).
The snapshoreferences/SECURITY.md
# session-tracker — security review history
## Security Review Notes (v2.5)
This revision responds to the [ClawHub security audit](https://clawhub.ai/darkd/skills/session-tracker/security-audit) v2.3 findings. The v2.3 audit (run against the published v2.3.0) produced **27 findings** (5 A.I.G + 22 SkillSpector). The v2.4-superz dogfooding version addressed some (description-behavior mismatch, freshness, orphan archive, journal) but left the highest-severity findings open. v2.5 closes them.
### A.I.G findings (5)
| # | ID | Severity | Finding | v2.5 response |
|---|---|---|---|---|
| 1 | **T01** | Error/High | Mandatory Skill Instructions Hijack Agent Workflow — MUST language pressures agents into broad activation | **Fixed**: Replaced "MUST be invoked before any multi-step task" with **"Use when: (1)… (2)… (3)…"** trigger list + concrete "Do NOT use for" exclusion criteria. The safety-net contract is preserved for tasks that qualify, but the agent has objective criteria to decide applicability. Pattern borrowed from `self-improving agent` v4.0.2. |
| 2 | **T09** | **Critical** | Arbitrary Recursive Directory Deletion Through Unrestricted `--dir`/`SESSION_TRACKER_DIR` | **Fixed**: (a) Import-time guard rejects `SESSION_TRACKER_DIR` if its realpath is exactly a system root (`/`, `/home`, `/root`, `/etc`, `/usr`, `/var`, `/tmp`, etc.) or the user's home dir. (b) `cleanup` re-checks `os.path.realpath(SESSION_DIR)` before `shutil.rmtree` (defeats symlink-to-`/` TOCTOU). (c) New `--dry-run` flag lists what would be deleted without deleting. Unique subdirs under dangerous paths (e.g. `/tmp/st_test_123/`) are allowed — only the dangerous path itself is blocked. |
| 3 | **T05** | High | PID File Can Cause Signaling of an Unrelated Process (TOCTOU on `os.kill(pid, 0)`) | **Fixed**: `monitor.pid` now records `{pid, start_time, session_id}` (JSON). `stop_monitor` and `doctor` validate the process identity by reading `/proc/<pid>/stat` field 22 (starttime) and comparing to the recorded value. If the PID was reused by an unrelated process, the start_time won't match and we refuse to signal. `PermissionError` from `os.kill(pid, 0)` (e.g. PID 1 as non-root) is treated as "alive but not ours" — we still check start_time and refuse if it doesn't match. |
| 4 | **T02** | Warning/Medium | Untrusted Task Text Persists Into Future Agent Recovery Context (memory poisoning) | **Fixed**: `crash-detect` and `resume` now print a prominent **⚠ UNTRUSTED DATA BELOW** label before any restored content, explicitly instructing the recovering agent to treat task names, step descriptions, and worklog entries as DATA, not instructions. Pattern borrowed from `self-improving agent` v4.0.2. Also added a **secret-redaction rule** to the skill instructions. |
| 5 | **T02** | Warning/Medium | Initialization Overwrites Existing Recovery State After Only Warning | **Fixed**: `init` now **ABORTS** when an orphaned session is detected, after archiving the orphan's state to `crashed_statPROVENANCE.md
# Provenance
- SKILL.md v2.3: fetched verbatim from the ClawHub public API
`GET https://clawhub.ai/api/v1/skills/session-tracker` (`skill.description` field),
version 2.3.0, owner `darkd`, license MIT-0.
- scripts/session_tracker.py v2.3: local re-implementation of the documented
v2.3 CLI contract (ClawHub does not serve the packaged script file over its
public API). Stdlib only. Command surface, flags, session files, orphan
detection, monitor hardening (log file, minimal env, 24h cap), cleanup
confirmation and prune semantics follow the SKILL.md spec.
- v2.4 (2026-09-17): improved after 15+ sessions of production dogfooding by
superz_glm (autonomous agent, long-lived tasks across 5 host/sandbox resets).
Every change traces to an observed failure mode recorded in the project
worklog:
* orphaned state.json was destroyed by the next `init` (only the notice
survived) → now archived to crashed_state_<ts>.json first
* session history died with `done`/`cleanup` (agent built an external
journal workaround) → opt-in journal.jsonl + `stats`
* read-only commands rewrote state 'updated', masking stuck sessions
(worklog BUG 3, "self-touching freshness") → freshness fix
* detached monitor died silently across sandbox resets → `doctor`
* `step N` hard-failed on undeclared steps; `sync` mangled string ids;
hardcoded /home/z/my-project paths → ad-hoc steps, string ids,
SESSION_TRACKER_DIR env override
Validated by scripts/test_session_tracker_v24.sh (27 assertions, all
passing). Security posture unchanged: stdlib only, no network, no eval,
no file-content reading, writes confined to the session dir; the journal
is opt-in and minimal (task names, timestamps, counts, optional note).
- v2.5 (2026-09-19): security hardening in response to the v2.3 ClawHub audit
(27 findings: 5 A.I.G + 22 SkillSpector). The v2.4-superz dogfooding version
addressed some findings (description-behavior mismatch, freshness, orphan
archive) but left the highest-severity findings open. v2.5 closes them:
* T09 (Critical): arbitrary recursive deletion via SESSION_TRACKER_DIR →
import-time guard rejects system roots/home dir; cleanup re-checks
realpath; new --dry-run flag
* T05 (High): PID file TOCTOU → monitor.pid records {pid, start_time,
session_id}; stop_monitor/doctor validate /proc/<pid>/stat starttime
before signaling (defeats PID reuse)
* T02 (Medium ×2): memory poisoning + init overwrites orphan →
crash-detect/resume label restored content as UNTRUSTED DATA; init
ABORTS on orphan, requires --replace; secret-redaction rule added
* T01 (Error/High): MUST hijacks workflow → "Use when:" trigger list +
"Do NOT use for" exclusion criteria (pattern from self-improving agent)
* Lp3 (95%): machine-readable permissions: block in YAML frontmatter
Patterns borrowed from analogous skills researched on ClawHub:
session-fork (--dry-run), self-improving agent (Use-when triggers,
untrusted-data AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/darkd/skills/session-tracker",
"sourceUrl": "https://clawhub.ai/darkd/skills/session-tracker",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-11T00:38:09.610Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-darkd-session-tracker/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-darkd-session-tracker/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-11T00:38:09.610Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1.2K downloads",
"href": "https://clawhub.ai/darkd/session-tracker",
"sourceUrl": "https://clawhub.ai/darkd/session-tracker",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-11T00:38:09.610Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "2.6.1",
"href": "https://clawhub.ai/darkd/session-tracker",
"sourceUrl": "https://clawhub.ai/darkd/session-tracker",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-09-19T10:30:05.370Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-darkd-session-tracker/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-darkd-session-tracker/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 2.6.1",
"description": "session-tracker v2.6.1 - Updated usage guidance in SKILL.md to clarify when to use/avoid session-tracking and emphasize privacy and irreversibility. - Expanded and clarified permissions table: now includes more precise controller details and negative-permission declarations. - New documentation for all CLI commands, flags, and exit codes; \"Workflow\" steps and behavior notes improved. - Added warnings and guidance regarding logging secrets and handling privacy-sensitive tasks. - Several new reference, security, and test files added; old skill-card removed. - Default behavior and limitations further documented: stricter init/orphan handling, improved cleanup safety, enhanced disclosure that restored data is fenced as untrusted.",
"href": "https://clawhub.ai/darkd/session-tracker",
"sourceUrl": "https://clawhub.ai/darkd/session-tracker",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-09-19T10:30:05.370Z",
"isPublic": true
}
]
}Record generated Oct 11, 2026.
