--- name: session-binding description: Nucleus V2 approved-write session binding collector. Use when a workflow must bind the current Claude Code or Codex native session before building a result package. --- # Session Binding 本 Skill 为 Nucleus V2 workflow 生成固定路径的 session binding report: `.nucleus/runs//session-binding/session-binding-report.json` 它只记录原生会话 ID、显式 transcript 路径和 hash,不复制 Claude/Codex transcript 或 JSONL 正文。 ## 子命令 ```bash python3 skills/session-binding/scripts/session_binding.py collect \ --repo-root \ --context /.nucleus/context/.json \ --provider-policy auto \ --codex-json-event ``` ```bash python3 skills/session-binding/scripts/session_binding.py freeze \ --repo-root \ --context /.nucleus/context/.json \ --session-binding-report /.nucleus/runs//session-binding/session-binding-report.json \ --reason completed ``` ```bash python3 skills/session-binding/scripts/session_binding.py validate-report \ --report /.nucleus/runs//session-binding/session-binding-report.json ``` ## 证据规则 - explicit context / CLI metadata 优先。 - Codex JSON event 和 Claude hook JSON 是可靠 event evidence。 - `CODEX_THREAD_ID` 只能作为 `local-verified-env-candidate`;strict/PMS 模式不接受单独 env candidate。 - Claude transcriptPath 只接受 hook JSON、explicit metadata、CLI 参数或 PMS connector 明确输出。 - 禁止 `discoveryMethod=latest|mtime|only-file`。 - 禁止 transcript 正文、message array、JSONL event array 进入 report。 - strict/PMS 或 `constraints.sessionBindingRequired=true` 缺可靠绑定时必须输出 blocker。 ## 边界 - 不 import 根 `harness/`。 - 不写 `docs/requirement/**`。 - `.nucleus/runs//session-binding` 若是 symlink,runtime 输出 stdout blocked payload,不写仓库文件。 - transcript hash 只在 `completed`、`cancelled`、`pms-freeze-requested` freeze reason 下计算。