Validate that builtin servers and external MCP managers maintain proper session isolation. Use when auditing session isolation, checking for cross-session state leakage, or verifying per-session MCPServiceProxy instantiation.
Scanned 9/28/2026
Install to Claude Code
npx -y skills add fritzprix/libr-agent --skill session-isolation-validator --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Session Isolation Validator?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/fritzprix-session-isolation-validator)More formats (shields.io, HTML) on the badges page.
---
name: session-isolation-validator
description: Validate that builtin servers and external MCP managers maintain proper session isolation. Use when auditing session isolation, checking for cross-session state leakage, or verifying per-session MCPServiceProxy instantiation.
---
# Session Isolation Validator
Validate that LibrAgent maintains proper session isolation across all MCP servers and managers.
## Validation Rules
### Builtin Servers
- [ ] Each builtin server implements `BuiltinMCPServer` trait
- [ ] Server state is keyed by session ID
- [ ] No `lazy_static!`, `once_cell!`, or global `Mutex` for shared state
- [ ] `get_service_context()` returns session-specific data
### External MCP Managers
- [ ] `HttpSessionManager` creates isolated sessions per agent session
- [ ] `SessionMCPManager` maintains per-session `MCPServiceProxy` instances
- [ ] No singleton patterns that share state across sessions
- [ ] Stdio server processes are session-scoped
### Frontend
- [ ] `AgentSessionContext` isolates state per session
- [ ] No global React state that mixes sessions
- [ ] Event listeners for `agent:event` are session-scoped
## Audit Commands
```bash
# Find potential global state anti-patterns
grep -r "lazy_static\|once_cell\|global\|GLOBAL" src-tauri/src/mcp/
grep -r "static mut\|unsafe" src-tauri/src/mcp/
# Find session ID usage patterns
grep -r "session_id\|sessionId" src-tauri/src/mcp/ | head -50
# Verify MCPServiceProxy instantiation
grep -r "MCPServiceProxy" src-tauri/src/
```
## Key Invariants
1. **No Global State**: Complete isolation prevents cross-session interference
2. **Stateful Tools**: Planning todos, Knowledge items, Browser sessions scoped to session ID
3. **Session-Specific Workspace**: Each agent operates in isolated directory
4. **Tool State Isolation**: Each session gets isolated tool instances
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!