ruvnet/ruflo
49.4
Weak · 28 September 2026
602.9k
lines of production code
TypeScript
with JavaScript
3
measurements over time
What this system is
This system is a modular, plugin-based orchestration framework for managing autonomous AI agents and multi-agent swarms. It provides core infrastructure for agent lifecycle management, secure communication via federation protocols, and persistent memory through vector databases. The platform extends functionality through a rich ecosystem of specialized plugins covering domains such as financial trading, security auditing, code intelligence, and IoT device management.
Features
AgentDB memory backend with retrieval security and scoped storage
The memory package now includes a new AgentDB backend (agentdb-backend) that provides HNSW-based vector search with graceful fallback to WASM or in-memory storage, and a new AgentDB adapter (agentdb-adapter) that fixes same-key upserts to prevent orphaned entries and stale search results. A new AgentDbRetrievalGuard (ADR-377) filters retrieval results for injected or oversized content, controlled by the CLAUDE\_FLOW\_RETRIEVAL\_GUARD and CLAUDE\_FLOW\_RETRIEVAL\_GUARD\_STRICT environment variables. Additionally, a new agent-memory-scope module introduces project, local, and user-scoped memory directories with path sanitization and knowledge transfer capabilities.
v3/@claude-flow/memory · high confidence
Claude Flow Plugin installation and hook scripts
The plugin now ships with a set of shell and Node.js scripts in .claude-plugin/scripts to manage the user experience. The install.sh script handles prerequisites (Claude Code CLI, Node.js \>= 20), allows users to choose which components to install (commands, agents, or MCP servers), and configures the MCP server entries in settings.json. The uninstall.sh and verify.sh scripts provide corresponding cleanup and health-check capabilities. Crucially, the hook invokers (ruflo-hook.sh and ruflo-hook.cjs) have been hardened: they prefer locally installed binaries over repeated npx calls to avoid install failures and slow-downs, enforce a 15-second timeout to prevent hanging processes, and ensure hooks always exit 0 so they never block the user's turn. The .cjs shim specifically addresses Windows compatibility by bypassing shell execution for better reliability and security.
.claude-plugin/scripts · high confidence
Decentralized plugin store with IPFS discovery and search
The CLI now includes a new plugin store module that enables discovering, searching, and managing plugins via a decentralized IPFS-based registry. Users can browse official and community plugins, filter by category, tags, trust level, and permissions, and view trending or featured plugins. The store verifies registry signatures using Ed25519 to ensure integrity and supports caching for faster access.
v3/@claude-flow/cli/src/plugins/store · high confidence
Flash Attention integration and resource admission policy
The performance module now includes a Flash Attention integration that wraps the @ruvector/attention runtime, providing optimized attention classes (FlashAttention, DotProductAttention, MultiHeadAttention, LinearAttention) and a FlashAttentionOptimizer for benchmarking and metrics tracking. A comprehensive benchmarking framework has been added to validate performance targets (e.g., 2.49x-7.47x speedup) and track memory usage. Additionally, a task-conditioned resource admission policy has been implemented to decide whether to admit, defer, or reject tasks based on resource profiles, host snapshots, and configurable policies, with results exported for use by other system components.
v3/@claude-flow/performance · high confidence
Graph-intelligence plugin introduces adapters for sublinear PageRank across multiple domains
The ruflo-graph-intelligence plugin now provides a suite of adapters that export various system graphs as sparse matrices, enabling sublinear (O(log N)) PageRank queries instead of full-graph traversals. These adapters cover browser causal recovery, federation trust, cost attribution, observability spans, knowledge graphs, RAG memory, portfolio covariance, AIDefence suspicion, and Jujutsu blast radius. Additionally, a federation client and server have been added to distribute and verify signed PageRank artifacts across peers, with local fallback for stale or untrusted responses.
plugins/ruflo-graph-intelligence/src · high confidence
Initial agent configuration and skill definitions for OpenAI Codex CLI
This change introduces the \.agents\ directory structure, providing the foundational configuration and skill definitions for the OpenAI Codex CLI. It adds a \config.toml\ file that sets the default model to \gpt-5.3-codex\, configures approval policies, sandbox modes, and MCP server connections, and defines specific profiles for development, safe, and CI environments. Additionally, it populates the \skills/\ directory with a comprehensive suite of agent skills—including adaptive coordination, goal planning, code quality analysis, system architecture, and payment authorization—each defined by \SKILL.md\ files that specify triggers, capabilities, and tool integrations.
.agents · high confidence
Initial release of the GitHub clone and npm download tracking ledger
The data directory now includes a structured ledger (clone-data.ledger.json) and a proof manifest (clone-data.proof.json) that track 14-day rolling GitHub clone counts and 12-month npm download totals for the ruvnet ecosystem repositories (ruflo, agentdb, agentic-flow, ruvector, ruv-FANN). This change introduces the underlying data schema and snapshot history required for the clone tracker feature, establishing the source of truth for the '11.7M npm downloads' badge and clone metrics displayed in the project.
data · high confidence
Initial repository scaffolding with .gitignore, .npmignore, and documentation
The repository is initialized with essential configuration and documentation files. A comprehensive .gitignore is added to exclude build artifacts, local environment variables (.env), IDE settings, and runtime data (SQLite databases, logs, temporary files), while explicitly preserving plugin-contract files (plugins/\*/.mcp.json) and READMEs. An .npmignore is introduced to strip source maps, test files, development configs, and documentation from published npm packages, reducing package size. Documentation is established via AGENTS.md (defining the Codex/Ruflo orchestration workflow), CLAUDE.md (Claude Code configuration and behavioral rules), CHANGELOG.md (adhering to Keep a Changelog), CONTRIBUTING.md, and a Chinese README (README.zh-CN.md).
(repo-wide) · high confidence
Introduce @claude-flow/plugin-code-intelligence for semantic search and architecture analysis
The new \@claude-flow/plugin-code-intelligence\ plugin (v3.0.0-alpha.1) adds five MCP tools to the platform: \code/semantic-search\ for finding similar code patterns, \code/architecture-analyze\ for detecting layer violations and circular dependencies, \code/refactor-impact\ for predicting the effects of code changes, \code/split-suggest\ for recommending module boundaries, and \code/learn-patterns\ for identifying recurring code structures. The plugin leverages Graph Neural Networks (GNN) and MinCut algorithms to power these capabilities, with a fallback to pure JavaScript implementations if the WebAssembly modules are unavailable.
v3/plugins/code-intelligence · high confidence
Introduce @claude-flow/teammate-plugin for multi-agent orchestration
The new @claude-flow/teammate-plugin bridges Claude Code v2.1.19+ multi-agent capabilities with Claude Flow, enabling users to spawn and manage teams of AI teammates. It exposes 21 MCP tools for team management, messaging, and plan approval, and includes a semantic router and topology optimizer that leverage WebAssembly (via @ruvnet/bmssp) for intelligent task routing and graph-based communication optimization. The plugin also provides built-in resilience features like rate limiting, circuit breaking, health checking, and retry logic to ensure stable multi-agent execution.
v3/plugins/teammate-plugin · high confidence
Introduce AIDefence AI manipulation detection and self-learning service
The AIDefence module now provides a unified facade for detecting AI manipulation attempts (such as prompt injection, jailbreaks, and role-switching) using over 50 built-in regex patterns, alongside a self-learning service that tracks mitigation effectiveness and supports vector-based pattern search. Users can enable optional PII detection and configure a custom vector store (defaulting to an in-memory implementation) to integrate with external systems like AgentDB for faster similarity searches.
v3/@claude-flow/aidefence · high confidence
Introduce Agentic-QE plugin for AI-powered quality engineering
The new @claude-flow/plugin-agentic-qe adds a comprehensive quality engineering suite to Claude Flow, featuring 51 specialized AI agents across 12 bounded contexts. Users can now leverage AI-driven capabilities including automated test generation (unit, integration, E2E, and chaos tests), O(log n) coverage gap analysis using the Johnson-Lindenstrauss algorithm, ML-based defect prediction, and SAST/DAST security scanning with OWASP compliance checks. The plugin also introduces chaos engineering tools for resilience testing and visual regression detection, all accessible via MCP tools like aqe/generate-tests, aqe/security-scan, and aqe/chaos-inject.
v3/plugins/agentic-qe · high confidence
Introduce Cognitum IoT plugin with device lifecycle, telemetry, and fleet management
The @claude-flow/plugin-iot-cognitum package now provides a complete IoT device management layer. It introduces a CLI (cognitum-iot) for registering, pairing, and querying devices, with authentication via the COGNITUM\_SEED\_TOKEN environment variable. The plugin exposes an IoTCoordinator that orchestrates device lifecycle (registration, pairing, trust scoring), telemetry ingestion and vector-store querying, anomaly detection, and fleet topology management. It also includes a state-machine-based firmware orchestration service supporting canary, rolling, and blue-green deployment strategies with automatic rollback on anomaly thresholds.
v3/@claude-flow/plugin-iot-cognitum · high confidence
Introduce Gas Town Bridge Plugin for multi-agent orchestration
The new Gas Town Bridge Plugin integrates Steve Yegge's Gas Town multi-agent orchestrator into Claude Flow V3, providing a hybrid architecture that uses CLI wrappers for I/O and WASM-accelerated modules for high-performance compute (e.g., formula parsing and graph operations). This location contributes the core plugin implementation, including secure CLI bridges for the \gt\ and \bd\ tools with strict input validation, bidirectional synchronization between Gas Town's Beads and Claude Flow's AgentDB, and WASM build scripts for optimized performance. It also includes configuration files for specialized agent roles (architect, coder, reviewer, etc.) and size-limit constraints to ensure bundle efficiency.
v3/plugins/gastown-bridge · high confidence
Introduce OAuth 2.1 authentication and secure Nostr publishing for the ChatGPT Federation plugin
The ChatGPT Federation plugin now implements an OAuth 2.1 resource server (RFC 9728) to secure its MCP tools, replacing the legacy \x-caller-token\ mechanism. Access tokens are validated against Cognitum's authorization server, with audience claims bound to the client ID to prevent cross-app token misuse. The plugin also introduces a dedicated, authenticated WebSocket connection to the Nostr relay for publishing events, ensuring that the connector signs and publishes messages under its own verified identity without exposing secret keys to the model or external callers.
plugins/ruflo-chatgpt-federation/src · high confidence
Introduce Prime Radiant plugin for mathematical AI reliability
The new Prime Radiant plugin adds a mathematical 'sanity check' layer to Claude Flow, providing coherence checking, consensus verification, and hallucination prevention. It exposes six mathematical engines (cohomology, spectral, causal, quantum, category theory, and HOTT) and corresponding MCP tools to detect contradictions, verify multi-agent agreement, and analyze swarm stability. This location provides the plugin's core implementation, including the engine wrappers, tool definitions, and comprehensive test suites for the WASM bridge and individual engines.
v3/plugins/prime-radiant · high confidence
Introduce RuFlo Chat UI with Docker deployment and MCP bridge
Adds a new RuFlo Chat UI (a fork of ruvocal) and an accompanying MCP Bridge service, deployable via Docker Compose. The setup includes a MongoDB persistence layer, an Nginx reverse proxy, and environment configuration (.env.example) for AI provider keys (OpenAI, Google, OpenRouter) and tool-group toggles. The bridge proxies model requests and exposes MCP tool endpoints, while the UI handles chat interactions and authentication (Google OIDC).
ruflo · high confidence
Introduce RuVector WASM integration bridges for advanced AI capabilities
Added a new plugin location providing integration bridges for 15 upstream RuVector WASM packages, enabling features such as ultra-fast vector similarity search (HNSW), flash attention, graph neural networks, hyperbolic embeddings, reinforcement learning, quantum-inspired optimization, and cognitive kernels. The implementation includes a centralized WASM registry for lifecycle management and provides mock fallbacks for development environments.
v3/plugins/ruvector-upstream · high confidence
Introduce Rust-based federation peer with in-process safety gating
The new \ruflo-federation-peer\ crate replaces the previous Node-bridge path with a single Rust process that handles federation hops and in-flight safety scanning. It integrates \midstreamer-quic\ for transport and \aimds-core\ for the 3-gate safety pipeline (detection, analysis, response), allowing operators to run a peer that inspects, blocks, or redacts messages before dispatching them to the local agent via stdio. The crate exposes pluggable traits (\TransportProvider\, \SafetyGate\, \Dispatcher\) so downstream consumers can substitute their own backends, while the default \native\ feature provides a ready-to-run binary for production use.
v3/crates/ruflo-federation-peer · high confidence
Introduce Witness toolkit for cryptographically signed fix verification and temporal history
The witness scripts in \plugins/ruflo-core/scripts/witness\ now provide a complete toolkit for verifying that code fixes are present in a repository. The new \init.mjs\ bootstraps a project with a manifest and history file, while \regen.mjs\ generates a signed manifest using Ed25519 signatures and \@noble/ed25519\. The \verify.mjs\ script checks the live tree against the manifest, supporting both source-only and full-tree verification, and correctly handles missing build artifacts as a precondition failure rather than a regression. Additionally, \history.mjs\ allows querying the temporal history of fixes to identify regressions, and \perf.mjs\ benchmarks key capabilities like install time and memory load to detect performance regressions.
plugins/ruflo-core/scripts/witness · high confidence
Introduce business-pod templates and dry-run execution engine
The ruflo-business-pods plugin now ships with pod templates for Sales, Marketing, Finance, HR, Ops, Support, and Executive domains, each defining agent roles, MCP tool allowances, budget caps, and success criteria. A new \pod-tick.mjs\ runner validates these templates, resolves agent types against the registry, reserves budget via a file-based stub ledger, and executes a dry-run mode by default (refusing live execution until Phase 3). The plugin includes a smoke test suite and a skill definition for the sales pod to demonstrate the one-tick iteration flow.
plugins/ruflo-business-pods · high confidence
Introduce goal-driven research UI with GOAP planning and AI-assisted workflows
The v3/goal\_ui area now provides a complete interface for defining, planning, and reviewing research objectives using a Goal-Oriented Action Planning (GOAP) system. Users can input research goals, select from domain-specific presets (e.g., Finance, Medical, Coding), and trigger AI-generated goal optimization via Supabase functions. The interface visualizes the planning process through animated step components (AgentStep, DevelopmentStep) that track execution states (pending, active, completed) and display real-time progress. A dedicated StateAssessmentCard allows users to monitor current vs. goal states, while the ResearchReviewCard facilitates final approval or revision requests before development. The system also includes a GOAPConfigDisplay for viewing execution modes and replanning triggers, and a WidgetCustomizer for branding and embedding the research tool.
_v3/goal\ui · high confidence
Introduce ruflo-adr plugin for Architecture Decision Record lifecycle management
The new ruflo-adr plugin provides tools to create, index, reconcile, and verify Architecture Decision Records (ADRs) stored as markdown files. It introduces an \adr-architect\ agent and seven CLI subcommands (\create\, \list\, \status\, \supersede\, \check\, \graph\, \search\) to manage the ADR lifecycle. ADRs are persisted in the AgentDB \adr-patterns\ and \adr-edges\ namespaces, enabling causal relationship tracking (supersedes, amends, depends-on) and compliance checks against code changes. The plugin includes a \reindex\ capability to reconcile deleted ADRs by dropping and rebuilding the namespace, and a \verify\ script to detect dangling references and supersede cycles.
plugins/ruflo-adr · high confidence
Introduce ruflo-arena plugin for competitive ruliology
The new ruflo-arena plugin enables competitive ruliology for Ruflo swarms, allowing users to run deterministic matches, round-robin tournaments, and adaptive co-evolution simulations between program strategies (FSMs). It exposes six MCP tools (arena/run, tournament/run, evolve/run, coevolve/run, run/get, run/list) that validate inputs via Zod, persist full run artifacts to \.ruflo/arena/\, and provide AgentDB payloads for semantic search. A CLI is included for direct execution of demos, tournaments, and evolution runs, with all results being reproducible via seeded PRNGs.
plugins/ruflo-arena · high confidence
Introduce ruflo-autopilot plugin for autonomous loop-driven task completion
The new ruflo-autopilot plugin (v0.2.1) enables autonomous, /loop-driven task completion with learning, prediction, and progress tracking. It exposes 10 MCP tools (status, enable, disable, config, reset, log, progress, learn, history, predict) and provides two skills (autopilot-loop, autopilot-predict) and two commands (/autopilot, /autopilot-status). The plugin integrates with Claude Code's native /loop and ScheduleWakeup, using a 270-second heartbeat to keep the prompt cache warm. It owns the autopilot-patterns AgentDB namespace for storing learned success patterns and is verified by a structural smoke test.
plugins/ruflo-autopilot · high confidence
Introduce ruflo-plugin-creator to scaffold and validate plugins with canonical contract enforcement
The new ruflo-plugin-creator plugin (v0.2.1) provides interactive scaffolding and validation for Claude Code plugins, ensuring they adhere to the canonical contract defined in ADR-0001. It generates the correct directory structure (skills, commands, agents) and plugin.json while explicitly forbidding legacy skills/commands/agents arrays that cause validation errors. The tool includes built-in MCP tool drift warnings to prevent common bugs, such as referencing the non-existent \embeddings\_embed\ tool or incorrectly passing \namespace\ arguments to AgentDB tools, and enforces structural integrity through a 10-check smoke test script.
plugins/ruflo-plugin-creator · high confidence
Introduce ruflo-ruvector plugin with pinned ruvector@0.2.25 and verified CLI surface
The new ruflo-ruvector plugin wraps the ruvector npm package, pinning it to version 0.2.25 to ensure a stable and verified CLI interface. This release corrects previous documentation drift by removing references to non-existent or aspirational commands (such as \compare\, \midstream\, and \embed --file\) and clarifying that certain features like hyperbolic embeddings and code clustering require specific workarounds or add-on packages (e.g., \ruvector-onnx-embeddings-wasm\, \@ruvector/pi-brain\). The plugin includes a \vector-setup\ skill for first-run installation of these optional dependencies, a smoke test script to validate the contracted surface, and updated agent descriptions that accurately reflect the 91 available MCP tools and the actual capabilities of the pinned version.
plugins/ruflo-ruvector · high confidence
Introduce ruflo-rvf plugin for portable agent memory and session persistence
The new ruflo-rvf plugin (v0.2.1) enables portable agent memory and session persistence using the RVF (RuVector Format). It provides skills to save, restore, and transfer agent sessions and memory entries across projects and platforms, including importing Claude Code auto-memories. The plugin claims the \rvf-sessions\ namespace and integrates with \ruflo-ruvector\ for underlying tooling and \ruflo-browser\ for browser session artifacts. It supports encryption at rest (AES-256-GCM) when the \CLAUDE\_FLOW\_ENCRYPT\_AT\_REST\ gate is enabled, and includes a smoke test suite to verify its contract.
plugins/ruflo-rvf · high confidence
Introduce ruflo-security-audit plugin for static security scanning and CVE monitoring
The new ruflo-security-audit plugin (v0.2.1) provides static security analysis, dependency scanning, and CVE monitoring to complement the runtime gates of the ruflo-aidefence plugin. It introduces a dedicated security-auditor agent (using the sonnet model), two skills (security-scan and dependency-check), and an /audit command that leverage the @claude-flow/cli v3.6 security commands. The plugin claims the security-findings namespace in AgentDB for storing scan results and includes a smoke test suite to enforce its plugin contract, including specific regression checks for shell-injection patterns.
plugins/ruflo-security-audit · high confidence
Introduce ruflo-swarm plugin for multi-agent coordination
The new ruflo-swarm plugin (v0.2.1) enables multi-agent swarm coordination, providing 12 MCP tools (4 swarm lifecycle and 8 agent management tools) and six supported topologies (hierarchical, mesh, hierarchical-mesh, ring, star, and adaptive). It includes built-in skills for initializing swarms with anti-drift defaults and streaming real-time status via the Monitor tool, alongside agent definitions for coordinators and architects. The plugin claims the 'swarm-state' namespace for state management and requires the ruflo-core plugin and @claude-flow/cli v3.6+.
plugins/ruflo-swarm · high confidence
Introduce ruflo-testgen plugin with Test-Driven Repair and coverage gap detection
The new ruflo-testgen plugin (v0.2.1) provides automated test generation, coverage gap detection, and a new Test-Driven Repair capability. Users can now identify untested code paths using the \coverage-gaps\, \coverage-route\, and \coverage-suggest\ CLI commands, or dispatch the \testgaps\ background worker via MCP. The plugin also introduces the \tdd-repair\ skill, which automatically fixes failing tests by spawning a bounded, headless \claude -p\ agent that modifies only the source code to make the test pass, enforcing safety via cost caps and tool restrictions. This plugin serves as the canonical owner for the SPARC Refinement phase, coordinating with ruflo-jujutsu to enforce coverage gates.
plugins/ruflo-testgen · high confidence
Introduce ruflo-workflows plugin with GAIA benchmarking and dual-surface workflow automation
The new ruflo-workflows plugin (v0.5.1) provides two complementary workflow automation surfaces: a 10-tool MCP interface for declarative, stateful pipelines with a full lifecycle (create, run, pause, resume, cancel, delete) and a native Claude Code JavaScript orchestration surface for deterministic subagent fan-out via agent, parallel, pipeline, and phase hooks. It also includes a comprehensive GAIA benchmarking component with commands to run evaluations, track history and costs, view leaderboard standings, and package signed, exploit-audited submissions for the Princeton HAL leaderboard.
plugins/ruflo-workflows · high confidence
Introduce v3 MCP server with connection pooling, OAuth 2.1, and protocol compliance
The v3/@claude-flow/mcp package now provides a standalone, high-performance Model Context Protocol (MCP) server implementation. This release adds a connection pool to manage and reuse transport connections, an OAuth 2.1 manager with PKCE support for secure authentication, and a rate limiter to protect against excessive usage. It also introduces registries for managing MCP resources and prompts, a task manager for asynchronous operations, and a sampling manager for server-initiated LLM calls. To ensure protocol compliance, the server now strictly adheres to the MCP 2025-11-25 specification, including a fixed protocol version string and a JSON schema validator for tool inputs.
v3/@claude-flow/mcp · high confidence
Introduce v3 core architecture with type-safe configuration and event-driven orchestration
The shared library now provides the foundational v3 architecture, starting with a new, type-safe configuration system in \src/core/config\ that uses Zod schemas for validation, default presets for agents and swarms, and a loader that merges file, environment variable, and default settings. It also introduces a core event bus (\src/core/event-bus\) supporting synchronous and asynchronous pub/sub with secure ID generation, alongside a comprehensive set of Domain-Driven Design interfaces (\src/core/interfaces\) for agents, tasks, memory, and coordination. These interfaces are wired together by decomposed orchestrator components, including an event coordinator for routing and a health monitor for periodic system checks.
v3/@claude-flow/shared · high confidence
Introduces A2A Agent Card federation and hardened federation policy controls
The plugin now supports discovery and registration of external peers via the Linux Foundation A2A (Agent2Agent) protocol by mapping ruflo federation manifests to A2A Agent Cards and consuming remote cards into the federation registry. This includes a read-only HTTP endpoint at \/.well-known/agent-card.json\ that binds to localhost by default for security. Additionally, the federation layer now enforces stricter authorization policies: inbound messages are validated against a defined set of claims (e.g., \federation:write\, \federation:spawn\) and trust levels, and a circuit breaker service monitors peer spend and failure rates to automatically suspend or evict untrusted or costly peers.
v3/@claude-flow/plugin-agent-federation · high confidence
Introduces comprehensive multi-agent security, governance, and policy analysis primitives
The guidance package now includes a suite of new modules for securing and managing multi-agent systems. The \adversarial\ module provides threat detection, collusion identification, and memory quorum consensus. The \authority\ module enforces human and institutional oversight with cryptographic audit trails for interventions. The \capabilities\ module introduces a typed permission algebra for granular, delegatable, and revocable access control. The \coherence\ module monitors agent behavior drift and enforces economic budgets (tokens, time, cost). The \compiler\ parses CLAUDE.md into structured policy bundles, while the \analyzer\ scores and auto-optimizes these files. Additionally, the \artifacts\ module provides a tamper-evident ledger for production outputs, and the \continue-gate\ prevents runaway agent loops by evaluating step-level context.
v3/@claude-flow/guidance · high confidence
Introduces v3 swarm architecture with agent pooling, CQRS task/agent commands, and pluggable consensus transports
The swarm package now provides a new v3 architecture centered on an AgentPool for lifecycle and auto-scaling, and an application layer using CQRS command handlers (SpawnAgent, TerminateAgent, CreateTask, CancelTask) orchestrated by SwarmApplicationService. Consensus protocols (Raft, Byzantine, Gossip) are unified under ConsensusEngine and now support ADR-095 G2 pluggable transports (LocalTransport and FederationTransport) with optional Ed25519 message signing, enabling secure multi-host consensus wiring.
v3/@claude-flow/swarm · high confidence
Introducing the RuFlo Federation Gateway for swarm coordination
The new ruflo-x-gateway (v0.7.1) provides an MCP server at x.ruv.io that enables AI agents to coordinate within a membership-gated, signed Nostr relay. It exposes tools for managing federation identity, publishing and syncing swarm messages, and handling work claims with time-to-live (TTL) expiration. The gateway supports both public and private swarm channels (ADR-386), where private channel content is end-to-end encrypted (NIP-44) and remains unreadable by the service. It also includes a guidance tool for agent decision-making, OAuth 2.1 authentication for secure publishing, and a set of default channels to help new members discover active coordination spaces.
plugins/ruflo-x-gateway · high confidence
Neural Trader benchmark suite for backtest, signal, memory, and portfolio performance
The \plugins/ruflo-neural-trader/benchmarks\ directory now includes a reproducible benchmark suite to establish performance baselines and regression gates for the neural trader plugin. This suite adds three executable benchmarks—\backtest-throughput.bench.mjs\ (measuring SMA crossover backtest speed), \signal-generation.bench.mjs\ (measuring anomaly detection latency across multiple symbols), and \memory-recall.bench.mjs\ (measuring vector search latency and recall)—alongside \portfolio-cg.bench.mjs\ (comparing local JavaScript conjugate gradient performance against the legacy Neumann series solver). The entry also includes the initial markdown result files for these benchmarks, capturing metrics like throughput, latency percentiles, and solver parity to track the performance impact of upcoming sublinear native dispatch integrations.
plugins/ruflo-neural-trader/benchmarks · high confidence
Neural-trader plugin introduces typed pipeline messaging, Ed25519-signed artifacts, and high-performance portfolio optimization
The neural-trader plugin now enforces a structured risk-gate pipeline where live trading strategies require explicit approval from a risk-analyst agent before execution, defined by typed message schemas for regime verdicts, signal proposals, and risk decisions. To ensure regulatory compliance and tamper evidence, backtest results and feature-attribution rankings are now wrapped in Ed25519-signed envelopes that pin verification to a trusted public key, preventing signature bypass attacks. Additionally, portfolio optimization performance has been significantly improved by introducing a native Conjugate Gradient solver that dispatches to a sublinear-time MCP tool when available, delivering a 40-60x speedup over the legacy Neumann series fallback.
plugins/ruflo-neural-trader/src · high confidence
New AI-driven workflow definitions for system testing and hardening
Added three new workflow scripts in .claude/workflows that define automated, agent-driven processes for the platform. The 'full-system-test' workflow orchestrates parallel checks for CLI builds, unit tests, runtime smoke tests, and plugin contracts, synthesizing a single pass/fail report. The 'intelligence-system-hardening' workflow guides agents through implementing specific audit fixes (such as CLI flag parsing and metric fabrication), validating builds, running performance benchmarks, and updating documentation with measured values. The 'plugin-contract-audit' workflow sweeps all plugin smoke contracts, diagnoses failures, and reports a punch list of issues.
.claude/workflows · high confidence
New Claude Code configuration with hooks, permissions, and statusline tools
The .claude directory now includes a complete configuration set for the Claude Code CLI. settings.json defines the default model (claude-sonnet-5), enables v3 agent teams and hooks, sets specific bash/MCP permissions, and registers PreToolUse, PostToolUse, and other lifecycle hooks via a hook-handler script. A new mcp.json file configures the 'flow-nexus' MCP server pointing to a Supabase SSE endpoint. Additionally, three new statusline scripts (statusline.sh, statusline.mjs, statusline-command.sh) are added to display real-time metrics like swarm status, memory usage, and task progress in the terminal.
.claude · high confidence
New Codex CLI with dual-mode swarm orchestration and policy-integrated execution
The @claude-flow/codex package now provides a dedicated CLI for OpenAI Codex integration, featuring an init command to scaffold projects with AGENTS.md, SKILL.md, and config.toml templates, alongside a new dual-mode command that orchestrates collaborative swarms of Claude Code and Codex workers. This orchestration supports parallel or chained execution, shared memory via Ruflo, and worktree isolation for concurrent writers. Worker execution is gated by ADR-324 policy preflight checks and ADR-377 caller-identity verification, ensuring that every action is authorized before the worker spawns. The package also includes a harness layer for build evidence and repository state tracking to support reproducible, auditable releases.
v3/@claude-flow/codex · high confidence
New V3 Embedding Service with Multi-Provider Support and Advanced Utilities
The \@claude-flow/embeddings\ package introduces a comprehensive V3 embedding service that supports multiple providers including OpenAI, Transformers.js (with a secure migration to \@huggingface/transformers\), Agentic-flow, and a new lightweight RVF hash-based provider. This update adds document chunking utilities with configurable strategies (sentence, paragraph, character, token), embedding normalization (L2, L1, min-max, z-score), and hyperbolic embedding conversions (Poincaré ball). It also includes a persistent SQLite-backed cache, a pure-TS binary cache for RVF embeddings, and neural substrate integration for semantic drift detection and memory management.
v3/@claude-flow/embeddings · high confidence
New agentic COW memory exploration and local GGUF inference engine
The CLI now includes two new capabilities: a speculative branch-and-promote system for agentic COW memory exploration (agenticow) that allows parallel A/B solution testing with promotion gates, and a pure Node.js GGUF inference engine that provides local model loading and token generation with optional node-llama-cpp integration.
v3/@claude-flow/cli · high confidence
New cognitive-kernel plugin adds LLM cognitive augmentation tools
The new @claude-flow/plugin-cognitive-kernel plugin introduces five MCP tools for enhancing LLM reasoning: working memory management, attention control, meta-cognitive monitoring, cognitive scaffolding, and cognitive load optimization. The plugin integrates with WASM-based cognitive and SONA (Self-Optimizing Neural Architecture) bridges for accelerated computation, providing dynamic memory slots, attention filtering, and self-reflection capabilities to improve complex reasoning tasks.
(repo-wide) · high confidence
New deployment module for release management and publishing
The v3/@claude-flow/deployment package introduces a new suite of tools for managing software releases. It includes a ReleaseManager for handling version bumping (major, minor, patch, prerelease), changelog generation, and git tagging, along with a Publisher class to handle npm package publishing with support for tags, access levels, and dry runs. A Validator component ensures release readiness by checking package.json structure, git status, dependencies, and running lint/test/build commands. The module also provides legacy compatibility functions (prepare, deploy) for existing workflows.
v3/@claude-flow/deployment · high confidence
New development helper suite and safety mechanisms for .claude/helpers
The .claude/helpers directory now contains a comprehensive set of new utility scripts and hooks to support the V3 development workflow. This includes an ADR compliance checker (adr-compliance.sh) to verify architectural decisions, a DDD progress tracker (ddd-tracker.sh), and a checkpoint manager (checkpoint-manager.sh) for Git-based session rollbacks. Operational safety is enhanced with a daemon manager (daemon-manager.sh) for background services, an auto-commit helper (auto-commit.sh), and a context persistence hook (context-persistence-hook.mjs) that archives conversation history to SQLite or JSON to prevent data loss during compaction. Security hardening is introduced via github-safe.js, which prevents shell injection in GitHub CLI commands by using temporary files for body content, and aggressive-microcompact.mjs, which optimizes context window usage. Additionally, auto-memory-hook.mjs bridges session data to the AgentDB, and a new .LOCKED file protects the directory from accidental overwrites during development.
.claude/helpers · high confidence
New example plugins for plugin creation and RuVector-powered AI capabilities
This update adds two new example plugin collections to the \@claude-flow/plugins/examples\ package. The \plugin-creator\ plugin introduces a meta-plugin that allows users to programmatically generate new plugins with various configurations, including tools, hooks, workers, and swarm integration, complete with code generation and validation. Additionally, a new suite of six RuVector plugins is introduced, leveraging \@ruvector/wasm\ for high-performance vector operations. These include a Reasoning Bank for storing and retrieving similar reasoning trajectories, Semantic Code Search for natural language code queries, a SONA Learning plugin for adaptive learning patterns, an Intent Router for smart query-to-agent mapping, an MCP Tool Optimizer for suggesting optimal tool sequences, and a Hook Pattern Library for learning and recommending effective hook configurations based on file types and operations.
v3/@claude-flow/plugins/examples · high confidence
New reinforcement learning algorithms: A2C and Curiosity-Driven Exploration
The neural module now includes two new reinforcement learning algorithms: Advantage Actor-Critic (A2C) and Curiosity-Driven Exploration. The A2C implementation provides a synchronous actor-critic network with N-step returns, entropy regularization, and advantage normalization, targeting less than 10ms per update step. The Curiosity module implements intrinsic motivation for exploration using both Intrinsic Curiosity Module (ICM) and Random Network Distillation (RND) approaches, with forward and inverse dynamics models to generate exploration bonuses, targeting less than 5ms per forward pass.
v3/@claude-flow/neural · high confidence
New ruflo-agntcy plugin scaffolding with CASA authorization enforcement and tests
The \plugins/ruflo-agntcy\ location introduces the initial scaffolding for the AGNTCY/Outshift runtime integration, including the \plugin.json\ manifest, \README.md\, and ADR-380 documentation. It adds a deterministic, rule-based CASA intent compiler (\src/casa/compile.ts\) that translates free-text objectives into bounded authority envelopes, and a strict, LLM-free enforcement gate (\src/casa/enforce.ts\) that denies-by-default and validates schema integrity to prevent bypass attempts. The change also includes comprehensive test coverage (\compile.test.ts\, \enforce.test.ts\) verifying the compiler's keyword matching, the enforcement gate's expiry and deny-wins logic, and its resilience against malformed inputs.
plugins/ruflo-agntcy · high confidence
New ruflo-ddd plugin for Domain-Driven Design scaffolding and validation
The ruflo-ddd plugin introduces Domain-Driven Design scaffolding capabilities, allowing users to create bounded contexts, scaffold aggregate roots with entities, value objects, and repositories, and validate domain boundary integrity. It includes a \domain-modeler\ agent, three skills (\ddd-context\, \ddd-aggregate\, \ddd-validate\), and a \/ddd\ command with six subcommands. The plugin stores the domain model as a navigable graph in AgentDB under the \ddd-patterns\ namespace and pins compatibility to \@claude-flow/cli\ v3.6.
plugins/ruflo-ddd · high confidence
New ruflo-deepseek-harness plugin for DeepSeek model integration
Added the ruflo-deepseek-harness plugin, which exposes DeepSeek's chat (deepseek-chat) and reasoning (deepseek-reasoner) models as ruflo skills. The plugin provides two main commands: 'deepseek chat' for single-turn completions and 'deepseek reason' for multi-step reasoning tasks that include a chain-of-thought. It follows the ADR-150 pattern for graceful degradation, ensuring ruflo remains operational even if the DeepSeek API is unreachable or the API key is missing. The plugin is designed to be removable without breaking other ruflo functionality.
plugins/ruflo-deepseek-harness · high confidence
New ruflo-music plugin for AI music generation
Users can now generate, list, and process music tracks via the Cognitum Music service using the new ruflo-music plugin. This feature adds a /music command with subcommands for connecting an account, generating tracks from creative briefs, listing productions, and post-processing existing tracks via stem separation, MIDI extraction, and mastering. The plugin integrates with the cogmusic MCP server, requiring users to provide a personal access token for authentication.
plugins/ruflo-music · high confidence
New unified plugin SDK with collection management and advanced vector integrations
The @claude-flow/plugins package introduces a comprehensive plugin development framework for v3, featuring a core plugin interface and builder for creating agents, MCP tools, hooks, and workers. It adds a PluginCollectionManager to group, activate, and persist plugin sets, along with several official collections (core, development, intelligence, swarm, security, utility). The SDK also integrates with external systems via an AgenticFlowBridge for swarm coordination and a RuVector PostgreSQL Bridge that exposes vector search, attention mechanisms, GNN layers, and hyperbolic embeddings as MCP tools.
v3/@claude-flow/plugins/src · high confidence
New v3 security module with CVE remediation, agent authorization, and input validation
The v3/@claude-flow/security module introduces a comprehensive security layer for the platform. It addresses critical vulnerabilities (CVE-2, CVE-3, HIGH-1, HIGH-2) by replacing weak password hashing with bcrypt, removing hardcoded credentials in favor of secure generation, preventing command injection via a safe executor, and validating file paths to stop traversal attacks. The module also implements ADR-144 P1 for agent authorization propagation, ensuring that delegated tasks respect scope boundaries and cannot escalate privileges. Additionally, it provides robust input validation using Zod schemas, threat detection for SQL injection and XSS, and an MCP composition inspector to detect malicious tool descriptions. A new security application service orchestrates these checks, allowing for context-aware validation of paths, commands, and user inputs.
v3/@claude-flow/security · high confidence
New verification system for regression protection and performance tracking
The repository now includes a \verification/\ directory that provides a cryptographically-signed witness system to attest that documented fixes remain present in the codebase, preventing silent regressions. This system generates per-OS signed manifests (macOS, Linux, Windows) and maintains a temporal history of verification results to help bisect when a regression was introduced. Additionally, it introduces a performance baseline layer that tracks key user-visible operations—such as package installation times, memory load speeds, and witness verification latency—across releases to catch performance regressions early.
verification · high confidence
Ruflo-intelligence plugin v0.3.1: complete surface documentation and IPFS transfer capability
The ruflo-intelligence plugin has been updated to v0.3.1 to fully document and operationalize its 29 MCP tools, which were previously only partially surfaced. This change introduces a new 'intelligence-transfer' skill that enables cross-project pattern sharing via IPFS (Pinata), allowing learned patterns to be published and fetched across different projects or machines. The plugin now explicitly supports the 4-step intelligence pipeline (RETRIEVE, JUDGE, DISTILL, CONSOLIDATE) and provides detailed guidance on namespace coordination with ruflo-agentdb, including the distinction between 'pattern' and 'patterns' namespaces. Additionally, it documents EWC++ consolidation mechanisms to prevent catastrophic forgetting and clarifies MoE routing modes (balanced, sona, moe, hnsw). A new smoke test script ensures documentation completeness and structural integrity.
plugins/ruflo-intelligence · high confidence
V3 Hooks system introduces pattern learning, guidance, and official bridge
The @claude-flow/hooks package now includes a complete V3 implementation featuring a ReasoningBank for vector-based pattern learning (using HNSW indexing and AgentDB persistence), a GuidanceProvider that generates Claude-visible context and pre-edit security checks (blocking sensitive files like .env), and an OfficialHooksBridge that maps internal V3 hook events to the standard Claude Code plugin API. This also adds a CLI for querying guidance and a daemon manager for background metrics and swarm monitoring.
v3/@claude-flow/hooks · high confidence
V3 introduces structured agent definitions and AIDefence security documentation
The v3 workspace now includes a set of YAML configuration files for core agent roles (architect, coder, reviewer, security-architect, tester) under \@claude-flow/agents\, each declaring version 3.0.0, specific capabilities, and optimization strategies. Additionally, an \intelligence.json\ file has been added to track routing metrics and command patterns, and the \@claude-flow/aidefence\ package now ships with comprehensive documentation detailing its AI Manipulation Defense System capabilities, including threat detection, PII scanning, and self-learning features.
v3 · high confidence
ruflo-agent plugin introduces cloud-managed runtime and nested sub-agent orchestration
The ruflo-agent plugin has been expanded from a local WASM-only runtime to support a dual-backend model: in addition to the existing sandboxed WASM agents, it now provides a cloud-managed runtime via Anthropic's Managed Agents API (exposed through \managed\agent\\*\ MCP tools and the \/managed-agent\ command). The plugin also introduces a comprehensive nested sub-agent orchestration system (up to depth 5), featuring specialized agent templates like \nested-coordinator\, \nested-researcher\, and \nested-reviewer\, along with a 'queen' tier that integrates hive-mind consensus, AIDefence content gating, and an intelligence pipeline for learning from spawn patterns. This change is reflected in the new \plugin.json\ manifest, updated README, and a suite of new agent definition files in the \agents/\ directory.
plugins/ruflo-agent · high confidence
ruflo-browser v0.2.1 introduces session-as-skill architecture with replayable RVF containers
The ruflo-browser plugin has been upgraded to version 0.2.1, shifting from ephemeral browser interactions to a session-based model where every session is captured as a first-class RVF cognitive container. This container records a full trajectory of actions via ruvector hooks, along with screenshots, accessibility snapshots, and sanitized cookies. The plugin now exposes seven new slash commands (/ruflo-browser ls, show, replay, export, fork, purge, doctor) to manage these sessions, and introduces eight new skills (browser-record, browser-replay, browser-extract, browser-login, browser-form-fill, browser-screenshot-diff, browser-auth-flow, browser-test) that compose stable Playwright primitives. To ensure safety, all scraped content and stored selectors are gated by AIDefence for PII and prompt-injection risks, and session data is indexed in AgentDB namespaces for cross-session reuse and DOM-drift resilience.
plugins/ruflo-browser · high confidence
Behavioural changes
CLI entry points updated for v3 proxying and legacy compatibility
The bin directory now uses new entry-point scripts to support the v3 architecture. bin/cli.js and bin/npx-safe-launch.js have been rewritten to dynamically proxy execution to the v3 CLI implementation (@claude-flow/cli), ensuring cross-platform compatibility. Additionally, bin/npx-repair.js has been introduced as a no-op module to maintain backwards compatibility with older versions of the CLI that may still attempt to import these cache-repair functions.
bin · high confidence
ChatGPT Federation connector now uses dedicated identity and OAuth 2.1 authentication
The ChatGPT Federation plugin is now a standalone service that holds its own Nostr signing key and opens a direct, authenticated connection to the relay, rather than relying on the gateway relay to sign events on its behalf. This change introduces OAuth 2.1 authentication for API access, replacing the previous transitional header-based mechanism, and enforces strict identity binding by pinning the signing key version and refusing to start if the derived public key does not match the expected identity. Users benefit from improved security and reliability, as the service now validates its own identity against the relay and ensures that only authorized callers can publish to public channels.
plugins/ruflo-chatgpt-federation · high confidence
Cost-tracker scripts consolidated and Windows compatibility fixed
The cost-tracker plugin scripts have been refactored to eliminate code duplication and improve cross-platform reliability. A shared session loader (\_sessions.mjs) and a single source of truth for model pricing (\_prices.mjs) replace duplicated logic across multiple analysis scripts (anomaly, budget, burn, conversation, counterfactual, projection). Additionally, a new \_npx.mjs helper ensures \npx\ commands execute correctly on Windows by invoking the Node entry point directly, resolving previous spawn failures and preserving JSON argument integrity.
plugins/ruflo-cost-tracker/scripts · high confidence
MetaHarness scripts consolidated and hardened with strict version pinning and graceful degradation
The MetaHarness plugin scripts have been refactored to replace per-call \npx\ invocations with a shared, version-pinned resolution strategy that searches for locally installed binaries first and falls back to a one-time cached install, significantly improving startup performance and eliminating security risks from uncontrolled \@latest\ resolution. This change introduces a unified invocation layer (\\_invoke.mjs\) that enforces graceful degradation—returning structured failure states instead of throwing errors when upstream tools are unavailable—while adding strict CLI argument validation and new capabilities such as audit-list, audit-trend, and genome similarity search.
plugins/ruflo-metaharness/scripts · high confidence
Plugin directories now point to .claude configuration
The plugin's agents, commands, and skills directories have been converted into symbolic links that point to the corresponding folders within the .claude directory. This change reorganizes where the plugin loads its agent definitions, command structures, and skill files from, ensuring they are sourced directly from the .claude configuration location.
plugin · high confidence
ruflo-agentdb plugin v0.3.1: accurate documentation, RaBitQ quantization, and namespace contract
The ruflo-agentdb substrate plugin has been updated to v0.3.1 to replace unverified performance claims with measured data (\~1.9x–4.7x speedup for HNSW search) and to formally document the RaBitQ 1-bit quantization workflow, which offers 32x memory reduction for large corpora. The plugin now enforces a strict namespace convention for downstream consumers, clarifies that the WASM HNSW router is capped at \~11 patterns (distinct from the large-scale embeddings path), and introduces a smoke test script to verify the structural integrity of the 15 agentdb, 10 embeddings, and 3 ruvllm\_hnsw MCP tools against the runtime controller registry.
plugins/ruflo-agentdb · high confidence
Fixes
Fixes namespace routing and tool-name bugs in market data plugin
The ruflo-market-data plugin (v0.2.1) resolves three functional bugs that prevented correct data storage and retrieval. It switches from the tier-based \agentdb\hierarchical-\\ tools to the namespace-routed \memory\\\ family for storing OHLCV data and searching patterns, ensuring data is correctly isolated in the \market-data\ and \market-patterns\ namespaces. It also corrects a non-existent tool reference, replacing \embeddings\_embed\ with the valid \embeddings\_generate\ tool. These fixes are verified by a new smoke test suite and documented in ADR-0001.
plugins/ruflo-market-data · high confidence
Introduce ruflo-migrations plugin with namespace-routing fix
The new ruflo-migrations plugin (v0.2.1) enables users to generate, validate, dry-run, and rollback database migrations with sequential up/down SQL pairs. This release fixes a critical namespace-routing bug by switching storage from the tier-routed \agentdb\hierarchical-\\ tools to the namespace-routed \memory\\\ tools, ensuring migration metadata is correctly stored and retrieved. The plugin includes six migration commands, comprehensive validation checks (foreign keys, NOT NULL defaults, idempotency), and a smoke-test contract to verify structural integrity.
plugins/ruflo-migrations · high confidence
Pre-commit hook blocks commits containing API keys
A new pre-commit hook has been added to automatically scan staged changes for sensitive data like API keys before allowing a commit. The hook executes a redaction validator script; if sensitive data is detected, the commit is blocked with an error message instructing the user to remove secrets. If the validator script is not yet built, the check is skipped with a reminder to run the build process.
.githooks · high confidence
Windows hook stability and MCP launch reliability
The ruflo-core plugin now uses a native Node.js shim (ruflo-hook.cjs) instead of a bash wrapper, ensuring PreToolUse and PostToolUse hooks run reliably on Windows without crashing. This shim includes argument escaping to prevent shell injection risks and ensures hooks always exit cleanly. Additionally, a new launcher script (mcp-launch.cjs) intelligently resolves the local CLI binary before falling back to npx, preventing version drift and ensuring the correct MCP server is started.
plugins/ruflo-core/scripts · high confidence
Windows-compatible plugin hook shims
Added a Node.js-based shim (ruflo-hook.cjs) to replace the shell-based hook invoker on Windows, resolving the 'cannot execute binary file' error that previously blocked hook execution on native Windows environments. The new shim mirrors the behavior of the existing shell script (ruflo-hook.sh) by reading hook payloads from stdin, preferring locally installed binaries over npx, and ensuring hooks always exit successfully to avoid blocking user turns. It also implements robust argument escaping and path resolution to handle Windows-specific command-line parsing and npm shim layouts securely.
plugin/scripts · high confidence
ruflo-observability plugin v0.2.1: namespace-routing fix and observability capabilities
The ruflo-observability plugin (v0.2.1) introduces structured logging, distributed tracing, and metrics collection to correlate agent swarm activity with application telemetry. This release fixes a critical namespace-routing bug where skills previously used \agentdb\_hierarchical-recall\ (which ignores namespace arguments) by switching to \memory\_search\ and \memory\_list\ for correct namespaced reads. The plugin provides an \observability-engineer\ agent, two skills (\observe-trace\ and \observe-metrics\), and five CLI commands (\observe trace\, \observe metrics\, \observe logs\, \observe dashboard\, \observe correlate\) to query spans, aggregate metrics with anomaly detection, filter logs, and correlate telemetry. It owns the \observability\ AgentDB namespace and includes a smoke test script to verify the plugin contract.
plugins/ruflo-observability · high confidence
Test coverage
Add smoke test script for ruflo-federation plugin contract; Add smoke test script to validate plugin contract and documentation; Added V3 test fixtures and helper utilities; Added post-deployment end-to-end test for the ChatGPT Federation connector; Added runtime and structural smoke tests for the neural-trader plugin; Added smoke test script for plugin contract validation; Added smoke test script to validate plugin contract and structure; Added smoke test to validate ruflo-aidefence plugin contract; Added test coverage for plugin management and RuVector integration; Added test scripts for the IPFS-based plugin store; Added tests for OAuth 2.1 federation authentication and publisher security; Added tests for the ruflo-graph-intelligence plugin's adapter registry, MCP tools, and graph adapters; New CI and static-analysis guard scripts for supply-chain, security, and regression prevention; New Docker-based deep regression test suite for comprehensive capability verification; New integration test suite for agent lifecycle, SONA mode resolution, and token optimization metrics; Smoke test validates plugin contract and documentation consistency; Smoke test validates plugin contract and tool naming fixes.
Dependencies
Introduces root Cargo workspace and adds ruflo-arena plugin
The repository now includes a root \Cargo.toml\ that defines a Rust workspace containing the \ruflo-federation-peer\ and \ruflo-agntcy\ crates, enabling Rust tooling to resolve these components. Additionally, a new \ruflo-arena\ plugin package is added, providing a CLI and library for competitive swarm evaluation (arenas and tournaments).
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 38 → 49 (+11.1)
- Rubric changed (rubric-2026.08.15 → rubric-2026.09.16) — scores are not directly comparable.
Lenses
- Code Health 44 → 50 (+5.8)
- Architecture 57 (new)
- Maturity 88 → 97 (+8.9)
- Readiness 29 → 46 (+16.9)
- Security 36 → 49 (+12.2)
- Domain Modelling 90 (new)
- Accessibility 52 (new)
- Performance 60 (new)
Resolved (337)
- (anonymous) (cognitive 21) (ruflo/src/nginx/static/welcome.js)
- (anonymous) (cognitive 21) (ruflo/src/ruvocal/static/chatui/welcome.js)
- (anonymous) (cognitive 22) (.claude/helpers/hook-handler.cjs)
- (anonymous) (cognitive 22) (v3/@claude-flow/cli/.claude/helpers/hook-handler.cjs)
- (anonymous) (cognitive 28) (ruflo/src/ruvocal/mcp-bridge/index.js)
- (anonymous) (cyclomatic 18) (.claude/helpers/hook-handler.cjs)
- (anonymous) (cyclomatic 18) (v3/@claude-flow/cli/.claude/helpers/hook-handler.cjs)
- (anonymous) (cyclomatic 19) (ruflo/src/ruvocal/mcp-bridge/index.js)
- ADR lacks an enforcement field (docs/dream-cycle/2026-06-15-performance-sota.md)
- ADR lacks an enforcement field (docs/dream-cycle/2026-06-21-security-sota.md)
- ADR lacks an enforcement field (docs/dream-cycle/2026-07-08-memory-sota.md)
- ADR lacks an enforcement field (docs/dream-cycles/2026-07-03-memory-sota.md)
- ADR lacks an enforcement field (docs/dream-cycles/2026-07-19-swarm-sota.md)
- ADR lacks an enforcement field (docs/dream-cycles/2026-07-20-performance-sota.md)
- ADR lacks an enforcement field (docs/dream-cycles/2026-07-21-security-sota.md)
- ADR lacks an enforcement field (docs/dream-cycles/2026-07-22-intelligence-sota.md)
- ADR lacks an enforcement field (docs/dream-cycles/2026-07-23-memory-sota.md)
- ADR lacks an enforcement field (docs/dream-cycles/2026-07-24-swarm-sota.md)
- ADR lacks an enforcement field (docs/dream-cycles/2026-07-25-performance-sota.md)
- ADR lacks an enforcement field (docs/dream-cycles/2026-07-27-intelligence-sota.md)
- …and 317 more
New (2386)
- (anonymous) (cognitive 32) (ruflo/src/nginx/static/welcome.js)
- (anonymous) (cyclomatic 20) (ruflo/src/nginx/static/welcome.js)
- ADR lacks an enforcement field (plugins/ruflo-music/docs/adrs/0001-music-contract.md)
- ADR lacks an enforcement field (v3/docs/adr/ADR-381-sequential-promotion-evidence-governance.md)
- ADR lacks an enforcement field (v3/docs/adr/ADR-383-watermarking-synthid-rust-wasm.md)
- ADR lacks an enforcement field (v3/docs/adr/ADR-384-generalized-bounded-evolution-methodology.md)
- ADR lacks an enforcement field (v3/docs/adr/ADR-385-streaming-interactive-long-horizon-swarm-execution.md)
- ADR lacks an enforcement field (v3/docs/adr/ADR-386-swarm-channels-public-and-private.md)
- ADR lacks an enforcement field (v3/docs/adr/ADR-387-chatgpt-federation-connector.md)
- ADR lacks an enforcement field (v3/docs/adr/ADR-388-oauth-on-x-ruv-io.md)
- ADR lacks an enforcement field (v3/docs/adr/ADR-389-refresh-the-keyword-router-helper.md)
- ADR lacks an enforcement field (v3/docs/adr/ADR-390-semantic-router-uses-the-real-embedder.md)
- ADR lacks an enforcement field (v3/docs/adr/ADR-391-router-benchmark-gate.md)
- ADR lacks an enforcement field (v3/docs/adr/ADR-398-planner-safe-agent-registration-descriptors.md)
- ADR lacks an enforcement field (v3/docs/adr/ADR-399-repository-local-git-execution-boundary.md)
- ADR lacks an enforcement field (v3/docs/adr/ADR-400-task-conditioned-resource-admission.md)
- APIContractValidator.compareContracts (cognitive 36) (v3/@claude-flow/testing/src/regression/api-contract.ts)
- APIContractValidator.compareContracts (cyclomatic 18) (v3/@claude-flow/testing/src/regression/api-contract.ts)
- AQEPlugin.register (cognitive 16) (v3/plugins/agentic-qe/src/plugin.ts)
- AgentDBAdapter.applyFilters (cognitive 30) (v3/@claude-flow/memory/src/agentdb-adapter.ts)
- …and 2366 more
Changes since last survey
- 300 commits — 128 feature/other, 172 fixes
By area
- v3/@claude-flow — 154 commits
- (repo) — 75 commits
- docs/dream-cycle — 11 commits
- .github/workflows — 9 commits
- plugins/ruflo-x-gateway — 8 commits
- (root) — 6 commits
- plugins/ruflo-core — 6 commits
- plugins/ruflo-adr — 5 commits
- plugins/ruflo-chatgpt-federation — 5 commits
- v3/docs — 5 commits
- verification/linux — 3 commits
- data/clone-data.ledger.json — 2 commits
- plugins/ruflo-metaharness — 2 commits
- scripts/smoke-github-safe-injection.mjs — 2 commits
- docs/protocol — 1 commit
- scripts/tests — 1 commit
- scripts/ci-test-baseline.txt — 1 commit
- scripts/fixtures — 1 commit
- scripts/prepare-root-publish.mjs — 1 commit
- scripts/smoke-trajectory-graph-edges.mjs — 1 commit
Notable commits
- fix: Merge PR #3425: fix(memory): import into the CLI-selected database
- fix: Merge PR #3428: fix(mcp): resolve installed CLI before npx fallback
- fix: Merge PR #3432: fix(adr): separate scan and database roots; fail on write errors
- fix: Merge PR #3433: fix(memory): anchor home-level helpers to the active project
- fix: Merge PR #3435: fix(memory): validate real outcomes before context synthesis
- fix: Merge PR #3437: fix(adr): fail closed on unreadable or truncated verification input
- fix: Merge PR #3440: fix(memory): reject mock embeddings before AgentDB rescue
- fix: Merge PR #3442: fix(memory): scope bridge failures to canonical database paths
- fix: Merge PR #3453: fix(mcp): report unsupported memory consolidation honestly
- fix: Merge PR #3454: fix(memory): decrypt images before initialization checks
- fix: Merge PR #3455: fix(config): make CLI daemon settings take effect
- fix: Merge PR #3456: fix(hooks): expire command history and preserve failed outcomes
- fix: Merge PR #3457: fix(memory): isolate backup rotation and restore by store
- fix: Merge PR #3458: fix(config): preserve existing files when loading fails
- fix: Merge PR #3459: fix(config): prevent prototype traversal through dotted keys
- fix: Merge PR #3460: fix(memory): preserve user notes when generated indexes grow
- fix: Merge PR #3461: fix(memory): confirm cleanup before dispatching deletion
- fix: Merge PR #3462: fix(learning): create skills from validated task patterns
- fix: Merge PR #3463: fix(memory): honor the selected database in memory stats
- fix: Merge PR #3464: fix(adr): retain qualified relations without inventing narrative edges
- …and 280 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
ruvnet/ruflo was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 28 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit b14c79e6f7793a358f13b7e3f9b5eb27317b4988 — the exact code this score is about.
- Scored under rubric-2026.09.16 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-eb9197011364.