Scope snapshot checkpoints to sessions with no file changes, under the session lock
Commit

Sessions that change no files (research, planning, review) never get a
checkpoint: turn end skips SaveStep when nothing changed, so session end
finds no steps and writes nothing. That is what checkpoint create is
for, so it now refuses sessions with pending FilesTouched (their next
commit checkpoints that work, with attribution).
The snapshot now condenses inside MutateSessionState and returns ErrMutationSkip. The per-session redaction prefix cache writes payload and entry in two steps, and an unlocked writer racing a commit's condensation could leave the entry pointing at the other writer's payload, splicing duplicated or dropped lines into every later checkpoint of the session. State is still never saved back.
Also: the caller refusal no longer prints the guessed session ID (an agent would pass it straight back); a disabled repo reports on stderr and fails instead of printing prose to stdout with exit 0; docs updated for snapshots and for IsCaller() now guarding this command.
Co-Authored-By: Claude Opus 5.5 noreply@anthropic.com Entire-Checkpoint: 01M41J9NBGYG9ERA5M8R8NGAPS