diff --git a/website/docs/reference/cli-commands.md b/website/docs/reference/cli-commands.md index f91f098ea6..a4373c18c5 100644 --- a/website/docs/reference/cli-commands.md +++ b/website/docs/reference/cli-commands.md @@ -1760,7 +1760,7 @@ Subcommands: | `optimize-storage` | Migrate the full-text search index to the compact v23 external-content layout; on large databases this reclaims a large fraction of `state.db`. | | `repair` | Repair a malformed `state.db` schema (e.g. `table messages_fts already exists`) so hidden sessions reappear; a backup is made first. | | `repair-routing` | Re-attach gateway conversations stranded in session rows that lost their routing identity (a chat "jumping back in time" after a restart). Dry-run by default; `--apply` performs the adoptions (stop the gateway first); `--max-gap-seconds N` tunes the contiguity window. Only unambiguous cases are repaired. See [Sessions → Repair Stranded Gateway Sessions](../user-guide/sessions.md#repair-stranded-gateway-sessions). | -| `repair-prompts` | Report stored system prompts provably degraded by the pre-#122822 maintenance-compaction bug. Report-only by default; `--apply` clears verified rows so the next turn rebuilds them, `--json` is machine-readable (and non-interactive when combined with `--apply`), and an explicit `session_id` is a destructive override that can clear even a healthy prompt. Rows without a readable tools[] pin, or with a memory-only pin, are reported as unverifiable and never auto-repaired. Restart a running gateway after `--apply` so repaired rows take effect. See [Sessions → Repair Degraded Stored Prompts](../user-guide/sessions.md#repair-degraded-stored-prompts). | +| `repair-prompts` | Report stored system prompts provably degraded by the pre-#122822 maintenance-compaction bug. Report-only by default; `--apply` clears verified rows so the next turn rebuilds them, `--json` is machine-readable (and non-interactive when combined with `--apply`), and an explicit `session_id` is a destructive override that can clear even a healthy prompt. Rows without a readable tools[] pin, or with a memory-only pin, are reported as unverifiable and left unchanged by the scan (a resumed memory-only session re-pins its full tool surface, after which a scan can clear it). Restart a running gateway after `--apply` so repaired rows take effect. See [Sessions → Repair Degraded Stored Prompts](../user-guide/sessions.md#repair-degraded-stored-prompts). | | `repair-profiles` | Settle session, routing, Telegram-topic and voice-mode state that landed under the wrong profile (rows in another profile's store, labels disagreeing with the session key, parent links crossing profiles, index rows for deleted profiles). Dry-run by default; `--apply` performs the repairs after snapshotting every store (stop the gateway first); `--legacy-main rekey\|move` decides what `agent:main` rows inside a named profile's store are; `--json` for automation. See [Sessions → Repair State Crossed Between Profiles](../user-guide/sessions.md#repair-state-crossed-between-profiles). | | `recover` | Offline, non-destructive recovery of a damaged `state.db` into a separate clean database. | | `retitle-skills` | Regenerate titles for sessions opened with a `/skill`, using what the user actually typed; lists changes unless `--apply` is passed. | diff --git a/website/docs/user-guide/sessions.md b/website/docs/user-guide/sessions.md index 050e95a0e0..5299d38533 100644 --- a/website/docs/user-guide/sessions.md +++ b/website/docs/user-guide/sessions.md @@ -669,8 +669,11 @@ The scan is conservative: it only proposes a repair when the stored prompt is missing the `## Skill Safety` guidance **and** the persisted `tools[]` pin contains `skill_manage` (which always emits that guidance). Rows with no readable pin, or with a `memory`-only pin (which is also a legitimate -`toolsets: [memory]` setup), are reported as **unverifiable** and are never -changed automatically; clear them explicitly by `SESSION_ID` if needed. +`toolsets: [memory]` setup), are reported as **unverifiable** and are not +changed by this scan; clear them explicitly by `SESSION_ID` if needed. A +memory-only row also heals on its own: once the session is resumed, its +`tools[]` pin re-pins the full tool surface, after which a scan sees +`skill_manage` without the Skill Safety guidance and clears it. ```bash # Report verified candidates and unverifiable rows; writes nothing