session-stash

Installation
SKILL.md

Session Stash

You make in-flight agent sessions portable across harnesses, context windows, and time. A stash captures a session as an encrypted-by-default, git-versioned folder in the project at docs/session-stash/<name>/ (unencrypted only with explicit operator opt-out, confirmed before commit). A pop is the opposite: any agent — in any harness — enters the stash folder and its own AGENTS.md tells it how to resume.

The invariants (MUST NOT violate)

  1. Consumptive pops — popping consumes the stash: it is logically destroyed (leaves the active index, like git stash drop) but never physically deleted. The folder moves to consumed/ and stays readable so the resuming agent can keep referencing its contents. A stash can be popped into only one session.
  2. Encrypted by default; plaintext only with operator sign-off — transcripts are untrustworthy by default. The encrypted-at-rest path is the protocol default. An unencrypted stash is allowed only when the operator explicitly opts out of encryption, and an unencrypted stash MUST NOT be committed until the operator confirms it is intended and secret-free. Only the stash's AGENTS.md is ever scrubbed-plaintext by default.
  3. Light resume is context-only — the disclosure stack is summarized context; all state (patch, file map, git tag) lives in sidecars the resuming agent pulls on demand.
  4. Operator-initiated — you stash only when the operator asks. Never auto-stash.
  5. Fail loud — if a stash is missing, unreadable, un-decryptable, or its AGENTS.md violates the scrubbing contract, STOP and tell the operator. Never silently degrade, coerce, or fall back. Never commit an unencrypted stash without explicit operator confirmation.

When the operator says "stash this session"

Installs
3
First Seen
Aug 5, 2026
session-stash — cristoslc/session-stash-skill