ruvnet/ruflo agent hook server skill
agent orchestration
Ruflo is an execution harness that extends Claude Code and Codex with agent orchestration, memory, and coordination capabilities. It provides 100+ specialized agents, swarm coordination, self-learning memory across sessions, federated communication between machines, and enterprise guardrails—available as either Claude Code plugins (slash commands) or a full CLI install with MCP server integration.
Install plugins to add slash commands and agent definitions for specific Ruflo capabilities Run the full CLI install to enable the complete Ruflo loop with 98 agents, MCP server, hooks, and background daemons Coordinate multiple agents working as a swarm on complex tasks with shared memory and learning Build federated systems where agents on different machines collaborate securely without data leakage Automate testing, security scanning, documentation, code quality, and architecture decision tracking across your codebase 10 CRITICAL✓ 39 HIGH✓ 352 MEDIUM 221 LOW 14 INFO
✓ CRITICAL/HIGH reflect AI-verified findings (false positives excluded) · MEDIUM/LOW/INFO are unverified scanner output
AI-verified (CRITICAL/HIGH): 1 confirmed (2%) 48 likely real (98%) 59 false positive — excluded from CRITICAL/HIGH count above
Findings by checker · 9 high-signal, 14 mostly false-positive (hidden by default)
CHK-125 21 findings 13 likely 8 false positive
38% FP CHK-081 7 findings 7 likely
0% FP CHK-075 5 findings 3 likely 2 false positive
40% FP CHK-101 3 findings 2 likely 1 false positive
33% FP CHK-143 1 finding 1 likely
0% FP CHK-089 1 finding 1 likely
0% FP CHK-008 1 finding 1 likely
0% FP CHK-130 1 finding 1 confirmed
0% FP CHK-066 1 finding 1 likely
0% FP ▼ Show 14 checkers that are mostly false positives (67 findings) 141 findings click to expand
CHK-081 Command injection risk — exec/execSync with string interpolation in plugins/ruflo-graph-intelligence/src/adapters/knowledge-graph-adapter.ts
plugins/ruflo-graph-intelligence/src/adapters/knowledge-graph-adapter.ts
AI: likely real confirmed ▼
CHK-081 Command injection risk — exec/execSync with string interpolation in v3/@claude-flow/codex/src/loop/index.ts
v3/@claude-flow/codex/src/loop/index.ts
AI: likely real confirmed ▼
CHK-133 Real secret in example output block — Private key in example output
v3/@claude-flow/guidance/docs/guides/wasm-kernel.md
AI: likely real likely ▼
CHK-081 Command injection risk — exec/execSync with string interpolation in scripts/bench-agenticow.mjs
scripts/bench-agenticow.mjs
AI: likely real confirmed ▼
CHK-081 Command injection risk — exec/execSync with string interpolation in v3/@claude-flow/browser/src/application/session-capsule-service.ts
v3/@claude-flow/browser/src/application/session-capsule-service.ts
AI: likely real confirmed ▼
CHK-081 Command injection risk — exec/execSync with string interpolation in scripts/smoke-statusline-generator-delegation.mjs
scripts/smoke-statusline-generator-delegation.mjs
AI: likely real confirmed ▼
CHK-081 Command injection risk — exec/execSync with string interpolation in v3/@claude-flow/security/src/safe-executor.ts
v3/@claude-flow/security/src/safe-executor.ts
AI: likely real confirmed ▼
CHK-143 npm scripts.postinstall executes remote code at install time — node -e inline code in postinstall
v3/@claude-flow/browser/package.json
AI: likely real likely ▼
CHK-081 Command injection risk — exec/execSync with string interpolation in v3/@claude-flow/security/src/CVE-REMEDIATION.ts
v3/@claude-flow/security/src/CVE-REMEDIATION.ts
AI: likely real confirmed ▼
CHK-089 --dangerously-skip-permissions in executable — all permission checks bypassed
v3/@claude-flow/codex/src/migrations/index.ts
AI: likely real confirmed ▼
CHK-101 Admin/privileged operation without role check
v3/@claude-flow/cli/src/mcp-tools/system-tools.ts
AI: likely real likely ▼
CHK-125 execSync() — synchronous shell execution — no scope constraint in agent-swarm-pr/SKILL.md
.agents/skills/agent-swarm-pr/SKILL.md
AI: likely real likely ▼
CHK-008 Stop governance hook captures broad tool output
.claude/settings.json
AI: likely real likely ▼
CHK-125 execSync() — synchronous shell execution — no scope constraint in github/swarm-pr.md
v3/@claude-flow/mcp/.claude/agents/github/swarm-pr.md
AI: likely real likely ▼
CHK-075 Agent with active penetration testing capability: v3/@claude-flow/cli/.claude/skills/swarm-advanced/SKILL.md
v3/@claude-flow/cli/.claude/skills/swarm-advanced/SKILL.md
AI: likely real likely ▼
CHK-129 Sensitive field in return type/schema — Secret: str
v3/@claude-flow/security/src/index.ts
AI: likely real likely ▼
CHK-125 execSync() — synchronous shell execution — no scope constraint in github/swarm-pr.md
v3/@claude-flow/cli/.claude/commands/github/swarm-pr.md
AI: likely real likely ▼
CHK-129 Sensitive field in return type/schema — Token: str
v3/@claude-flow/plugin-agent-federation/src/domain/entities/federation-session.ts
AI: likely real likely ▼
CHK-129 Sensitive field in return type/schema — Secret: str
v3/mcp/types.ts
AI: likely real likely ▼
CHK-125 execSync() — synchronous shell execution — no scope constraint in github-code-review/SKILL.md
v3/@claude-flow/cli/.claude/skills/github-code-review/SKILL.md
AI: likely real likely ▼
CHK-029 Dynamic MCP server instantiation in skill
v3/@claude-flow/cli/.claude/skills/reasoningbank-agentdb/SKILL.md
AI: likely real likely ▼
CHK-029 Dynamic MCP server instantiation in skill
.claude/skills/agentdb-memory-patterns/SKILL.md
AI: likely real likely ▼
CHK-129 Sensitive field in return type/schema — Secret: str
v3/@claude-flow/shared/src/mcp/types.ts
AI: likely real likely ▼
CHK-125 execSync() — synchronous shell execution — no scope constraint in github-code-review/SKILL.md
.claude/skills/github-code-review/SKILL.md
AI: likely real likely ▼
CHK-125 execSync() — synchronous shell execution — no scope constraint in github-code-review/SKILL.md
.agents/skills/github-code-review/SKILL.md
AI: likely real likely ▼
CHK-101 Admin/privileged operation without role check
v3/@claude-flow/cli/src/commands/ruvector/setup.ts
AI: likely real likely ▼
CHK-129 Sensitive field in return type/schema — password: str
v3/@claude-flow/plugins/src/integrations/ruvector/ruvector-bridge.ts
AI: likely real likely ▼
CHK-029 Dynamic MCP server instantiation in skill
plugins/ruflo-agentdb/skills/agentdb-query/SKILL.md
AI: likely real likely ▼
CHK-029 Dynamic MCP server instantiation in skill
plugins/ruflo-ruvllm/skills/llm-config/SKILL.md
AI: likely real likely ▼
CHK-029 Dynamic MCP server instantiation in skill
plugins/ruflo-agent/skills/managed-agent/SKILL.md
AI: likely real likely ▼
CHK-130 [postinstall] Code execution at install time — node -e with inline code — arbitrary JS execution at install
v3/@claude-flow/browser/package.json
AI: confirmed likely ▼
CHK-029 Dynamic MCP server instantiation in skill
plugins/ruflo-agent/skills/wasm-gallery/SKILL.md
AI: likely real likely ▼
CHK-125 exec() — arbitrary code execution — no scope constraint in infrastructure/agent-browser-adapter.ts
v3/@claude-flow/browser/src/infrastructure/agent-browser-adapter.ts
AI: likely real likely ▼
CHK-125 execSync() — synchronous shell execution — no scope constraint in github/swarm-pr.md
v3/@claude-flow/mcp/.claude/commands/github/swarm-pr.md
AI: likely real likely ▼
CHK-029 Dynamic MCP server instantiation in skill
plugins/ruflo-market-data/skills/market-ingest/SKILL.md
AI: likely real likely ▼
CHK-066 PermissionRequest hook configured — fires when Claude requests permissions
plugin/hooks/hooks.json
AI: likely real likely ▼
CHK-029 Dynamic MCP server instantiation in skill
plugins/ruflo-agent/skills/wasm-agent/SKILL.md
AI: likely real likely ▼
CHK-029 Dynamic MCP server instantiation in skill
plugins/ruflo-neural-trader/skills/trader-cloud-backtest/SKILL.md
AI: likely real likely ▼
CHK-075 Agent with active penetration testing capability: .claude/agents/v3/v3-security-architect.md
.claude/agents/v3/v3-security-architect.md
AI: likely real likely ▼
CHK-129 Sensitive field in return type/schema — Password: str
v3/@claude-flow/security/src/credential-generator.ts
AI: likely real likely ▼
CHK-129 Sensitive field in return type/schema — Secret: str
v3/@claude-flow/mcp/src/types.ts
AI: likely real likely ▼
CHK-125 execSync() — synchronous shell execution — no scope constraint in github/swarm-pr.md
v3/@claude-flow/cli/.claude/agents/github/swarm-pr.md
AI: likely real likely ▼
CHK-075 Agent with active penetration testing capability: .claude/agents/consensus/security-manager.md
.claude/agents/consensus/security-manager.md
AI: likely real likely ▼
CHK-125 execSync() — synchronous shell execution — no scope constraint in github/swarm-pr.md
.claude/agents/github/swarm-pr.md
AI: likely real likely ▼
CHK-125 execSync() — synchronous shell execution — no scope constraint in scripts/bench-agenticow.mjs
scripts/bench-agenticow.mjs
AI: likely real likely ▼
CHK-029 Dynamic MCP server instantiation in skill
v3/@claude-flow/cli/.claude/skills/agentdb-memory-patterns/SKILL.md
AI: likely real likely ▼
CHK-125 execSync() — synchronous shell execution — no scope constraint in scripts/smoke-statusline-generator-delegation.mjs
scripts/smoke-statusline-generator-delegation.mjs
AI: likely real likely ▼
CHK-125 execSync() — synchronous shell execution — no scope constraint in github/swarm-pr.md
.claude/commands/github/swarm-pr.md
AI: likely real likely ▼
CHK-029 Dynamic MCP server instantiation in skill
.claude/skills/reasoningbank-agentdb/SKILL.md
AI: likely real likely ▼
CHK-054 Tool 'list_files' — generic name without namespace prefix (shadow risk)
ruflo/src/ruvocal/src/lib/wasm/wasm.worker.ts
possible ▼
CHK-054 Tool 'delete_file' — generic name without namespace prefix (shadow risk)
ruflo/src/ruvocal/src/lib/wasm/index.ts
possible ▼
CHK-054 Tool 'list_files' — generic name without namespace prefix (shadow risk)
ruflo/src/ruvocal/src/lib/wasm/tests/wasm-capabilities.test.ts
possible ▼
CHK-054 Tool 'search' — generic name without namespace prefix (shadow risk)
ruflo/src/ruvocal/static/wasm/rvagent_wasm.js
possible ▼
CHK-125 execSync() — synchronous shell execution — no scope constraint in benchmarks/gaia-loader.ts
v3/@claude-flow/cli/src/benchmarks/gaia-loader.ts
possible ▼
CHK-054 Tool 'list_files' — generic name without namespace prefix (shadow risk)
ruflo/src/ruvocal/src/lib/wasm/index.ts
possible ▼
CHK-054 Tool 'delete_file' — generic name without namespace prefix (shadow risk)
ruflo/src/ruvocal/src/lib/wasm/tests/wasm-capabilities.test.ts
possible ▼
CHK-054 Tool 'search' — generic name without namespace prefix (shadow risk)
v3/@claude-flow/cli/src/commands/agent-wasm.ts
possible ▼
CHK-125b sudo invocation — privilege escalation — no scope constraint in mcp/index.ts
v3/@claude-flow/hooks/src/mcp/index.ts
possible ▼
CHK-054 Tool 'search' — generic name without namespace prefix (shadow risk)
v3/@claude-flow/cli/src/commands/plugins.ts
possible ▼
CHK-125a fs.writeFile — unrestricted file write — no scope constraint in workers/index.ts
v3/@claude-flow/hooks/src/workers/index.ts
possible ▼
CHK-125 eval() — arbitrary code execution — no scope constraint in commands/neural.ts
v3/@claude-flow/cli/src/commands/neural.ts
possible ▼
CHK-125 spawnSync() — synchronous process spawn — no scope constraint in scripts/migrate-plugin-call-sites.mjs
v3/@claude-flow/cli-core/scripts/migrate-plugin-call-sites.mjs
possible ▼
CHK-054 Tool 'search' — generic name without namespace prefix (shadow risk)
ruflo/src/ruvocal/mcp-bridge/index.js
possible ▼
CHK-125a fs.readFile — filesystem read access — no scope constraint in src/index.ts
v3/@claude-flow/cli-core/src/index.ts
possible ▼
CHK-125b sudo invocation — privilege escalation — no scope constraint in commands/neural.ts
v3/@claude-flow/cli/src/commands/neural.ts
possible ▼
CHK-125 eval() — arbitrary code execution — no scope constraint in quantum-optimizer/README.md
v3/plugins/quantum-optimizer/README.md
possible ▼
CHK-054 Tool 'execute' — generic name without namespace prefix (shadow risk)
ruflo/src/ruvocal/src/lib/wasm/index.ts
possible ▼
CHK-125 subprocess module — arbitrary shell execution — no scope constraint in commands/metaharness.ts
v3/@claude-flow/cli/src/commands/metaharness.ts
possible ▼
CHK-125 execSync() — synchronous shell execution — no scope constraint in statusline/index.ts
v3/@claude-flow/hooks/src/statusline/index.ts
possible ▼
CHK-054 Tool 'search' — generic name without namespace prefix (shadow risk)
v3/@claude-flow/cli/src/commands/transfer-store.ts
possible ▼
CHK-054 Tool 'update' — generic name without namespace prefix (shadow risk)
v3/@claude-flow/cli/src/commands/update.ts
possible ▼
CHK-027 Outbound network call in skill — external network call (verify direction — could be benign API fetch)
.claude/skills/verification-quality/SKILL.md
possible ▼
CHK-115 Credential file path referenced in skill content: .env"
.claude/skills/hooks-automation/SKILL.md
possible ▼
CHK-125 kubectl invocation — cluster command execution — no scope constraint in reasoningbank/guidance-provider.ts
v3/@claude-flow/hooks/src/reasoningbank/guidance-provider.ts
possible ▼
CHK-125a fs.writeFile — unrestricted file write — no scope constraint in commands/route.ts
v3/@claude-flow/cli/src/commands/route.ts
possible ▼
CHK-125 execSync() — synchronous shell execution — no scope constraint in src/validator.ts
v3/@claude-flow/deployment/src/validator.ts
possible ▼
CHK-125 execSync() — synchronous shell execution — no scope constraint in mcp-tools/github-tools.ts
v3/@claude-flow/cli/src/mcp-tools/github-tools.ts
possible ▼
CHK-125 exec() — arbitrary code execution — no scope constraint in benchmarks/gaia-convergence.ts
v3/@claude-flow/cli/src/benchmarks/gaia-convergence.ts
possible ▼
CHK-054 Tool 'search' — generic name without namespace prefix (shadow risk)
ruflo/src/mcp-bridge/index.js
possible ▼
CHK-125 execSync() — synchronous shell execution — no scope constraint in src/release-manager.ts
v3/@claude-flow/deployment/src/release-manager.ts
possible ▼
CHK-125 exec() — arbitrary code execution — no scope constraint in supply-chain/accepted-findings.json
.github/supply-chain/accepted-findings.json
possible ▼
CHK-125 execSync() — synchronous shell execution — no scope constraint in commands/hive-mind.ts
v3/@claude-flow/cli/src/commands/hive-mind.ts
possible ▼
CHK-125b sudo invocation — privilege escalation — no scope constraint in workflows/neural-trader-smoke.yml
.github/workflows/neural-trader-smoke.yml
possible ▼
CHK-125 execSync() — synchronous shell execution — no scope constraint in scripts/ruflo-hook.cjs
.claude-plugin/scripts/ruflo-hook.cjs
possible ▼
CHK-125 execSync() — synchronous shell execution — no scope constraint in src/publisher.ts
v3/@claude-flow/deployment/src/publisher.ts
possible ▼
CHK-125a fs.unlinkSync — file deletion — no scope constraint in update/rate-limiter.ts
v3/@claude-flow/cli/src/update/rate-limiter.ts
possible ▼
CHK-125 eval() — arbitrary code execution — no scope constraint in mcp-tools/browser-tools.ts
v3/@claude-flow/browser/src/mcp-tools/browser-tools.ts
possible ▼
CHK-125 exec() — arbitrary code execution — no scope constraint in mcp/clientPool.ts
ruflo/src/ruvocal/src/lib/server/mcp/clientPool.ts
possible ▼
CHK-125a fs.unlinkSync — file deletion — no scope constraint in commands/start.ts
v3/@claude-flow/cli/src/commands/start.ts
possible ▼
CHK-125 exec() — arbitrary code execution — no scope constraint in textGeneration/generate.ts
ruflo/src/ruvocal/src/lib/server/textGeneration/generate.ts
possible ▼
CHK-125 exec() — arbitrary code execution — no scope constraint in utils/messageUpdates.spec.ts
ruflo/src/ruvocal/src/lib/utils/messageUpdates.spec.ts
possible ▼
CHK-125 eval() — arbitrary code execution — no scope constraint in regression/security-regression.ts
v3/@claude-flow/testing/src/regression/security-regression.ts
possible ▼
CHK-125 execSync() — synchronous shell execution — no scope constraint in mcp-tools/terminal-tools.ts
v3/@claude-flow/cli/src/mcp-tools/terminal-tools.ts
possible ▼
CHK-054 Tool 'write' — generic name without namespace prefix (shadow risk)
v3/@claude-flow/cli/src/commands/neural.ts
likely ▼
CHK-125 exec() — arbitrary code execution — no scope constraint in utils/messageUpdates.ts
ruflo/src/ruvocal/src/lib/utils/messageUpdates.ts
possible ▼
CHK-125 exec() — arbitrary code execution — no scope constraint in utils/marked.ts
ruflo/src/ruvocal/src/lib/utils/marked.ts
possible ▼
CHK-125a fs.unlinkSync — file deletion — no scope constraint in ruvector/import.ts
v3/@claude-flow/cli/src/commands/ruvector/import.ts
possible ▼
CHK-125 exec() — arbitrary code execution — no scope constraint in gaia-hardness/features.ts
v3/@claude-flow/cli/src/benchmarks/gaia-hardness/features.ts
possible ▼
CHK-125a fs.unlinkSync — file deletion — no scope constraint in commands/embeddings.ts
v3/@claude-flow/cli/src/commands/embeddings.ts
possible ▼
CHK-125 subprocess module — arbitrary shell execution — no scope constraint in mcp-tools/testgen-tools.ts
v3/@claude-flow/cli/src/mcp-tools/testgen-tools.ts
possible ▼
▼ Show 59 false positives (30% of this view) Last scanned: Jul 11, 2026
More servers
google-gemini/gemini-cli 85
An open-source AI agent that brings the power of Gemini directly into your terminal.
106k★
skypilot-org/skypilot 85
obra/superpowers 85
Foundational skill pack by Jesse Vincent now in anthropics/claude-plugins-official. Includes ffuf web-fuzzing/pentest skill. Partial analysis done — full hook and plugin inspection pending. tier=T2
191k★
Significant-Gravitas/AutoGPT 85
AutoGPT is the vision of accessible AI for everyone, to use and to build on. Our mission is to provide the tools, so that you can focus on what matters.
186k★
nanocoai/nanoclaw 85
A lightweight alternative to OpenClaw that runs in containers for security. Connects to WhatsApp, Telegram, Slack, Discord, Gmail and other messaging apps,, has memory, scheduled jobs, and runs directly on Anthropic's Agents SDK
30k★
google-gemini/gemini-cli 85
An open-source AI agent that brings the power of Gemini directly into your terminal.
106k★
Scan your entire org's MCP deployment
2,500+ repos pre-scored. 22% carry CRITICAL findings.