Project releases

Ruflo 3.50 to 3.52: Claude Code mods, the /ruflo console and hardened guards

Over four days Ruflo moved onto Claude Code's new mods API. Version 3.50 made it an opt-in mod with in-process routing and a live swarm pane, 3.51 added a one-command /ruflo console and turned the mods on by default in new projects, and the 3.52 plugin release on October 5 closed the guard bypasses found in an overnight test run.

GitHub activity: · Published:

What this is about

Ruflo is an agent orchestration layer for Claude Code: it routes tasks to agents, runs swarms, keeps memory and enforces policy. Until now it plugged into Claude Code through shell hooks, small commands Claude Code runs before and after each step.

Claude Code now offers mods: plugins whose hooks run as functions inside Claude Code instead of separate processes. Three releases between October 2 and October 5 move Ruflo onto that API, add a live console, and then harden the guards the mods rely on. This story covers them together because they are one piece of work.

What changed

Version 3.50.0, October 2 (commit 27982983): Ruflo as an opt-in mod.

  • New commands: ruflo mods install, uninstall, status, doctor and sync-policy, plus ruflo init --mods. Install writes only project-scoped files.
  • The ruflo-mods plugin does prompt routing in-process. The release reports 0.045 ms median against 18.2 ms for a spawned hook, with byte-identical routing. It also adds a tool check fed by Ruflo policy that can only tighten a verdict, edit learning signals, a cost budget ladder and a status bar.
  • A mod trust gate observes mods loaded mid-session, including ones Claude writes. Refusing risky mods is opt-in.
  • A ruflo-swarm pane shows one tile per agent, the task and claims board, cost and the router's pick.
  • A ruflo-ruos plugin can run swarm agents on ruOS cloud desktops through the tenant-authenticated fleet MCP only.
  • Classic hooks stay the default and the automatic fallback.

Version 3.51.0, October 2 (commit 9e4fd175): the /ruflo console.

  • A ruflo-console mod gives one command, /ruflo, with views for overview, swarm topology, claims, federation, plugin health, learning, memory, cost, agents, approvals, events and missions.
  • Every action from the console shows the exact command it will run and asks for confirmation first. /ruflo dump <view> prints a view as text for scripts.
  • ruflo init now enables the three mods by default; --no-mods opts out and ruflo init upgrade --mods adds them to an existing project.
  • A catalog of 243 Ruflo commands (ruflo catalog) and an observation-only mission view.

Version 3.52.0, October 5 (commit 0c1da453): safer mods.

  • An overnight run of 3,182 bypass attempts found 32 secret guards that could be skipped with very large or deeply nested input. They now refuse such input; the release reports guard holes going from 788 to 0.
  • At the console's write level Claude could run a shell command; that path is closed. Always-allow can no longer skip the chosen control level, and auto-confirm never answers questions about network, spending or deleting.
  • The memory guard now catches secrets hidden with look-alike characters and checks the file given to memory import.
  • New optional abilities, all off by default, including agentTrim, which the release measured as saving 4,236 tokens per session.
  • Separately, @claude-flow/codex 3.0.3 was published so that bun add ruflo installs again.

Package versions: the 3.52.0 release notes describe a plugin-only release with the npm packages left at 3.51.1. When this story was checked on October 5, the npm registry already listed ruflo and @claude-flow/cli 3.52.0 as latest, published shortly after the release notes, while claude-flow was still 3.51.1. Check npm view ruflo version before relying on either number.

Get started

Prerequisites: Node.js and Claude Code. Mods need Claude Code 2.1.287 or newer; versions 2.1.277 to 2.1.286 need function hooks switched on with an environment variable. The release notes also say Anthropic's rollout switch must be on for your account, and that the mods API is early access and may change. Without function hooks, the classic hooks keep working unchanged.

npx ruflo@latest init wizard
ruflo mods doctor

Expected result: doctor reports whether the mods are installed, whether the marketplace copy is current and whether the rollout switch is on, and prints the exact repair if not. Inside Claude Code, /ruflo opens the console; on a narrow terminal the bar above the prompt says /ruflo to open.

claude plugin marketplace update ruflo
claude plugin update ruflo-mods@ruflo --scope user
claude plugin update ruflo-console@ruflo --scope user
claude mcp add claude-flow -- npx ruflo@latest mcp start

Skills: the README says the full Ruflo install includes about 30 skills alongside agents and commands. There is no separate npx skills package for the mods.

Commands here were read from the release notes and repository documentation at the pinned reference; they were not executed as part of writing this article.

Use it today

Practical case: you run a five-agent swarm on a refactor and want to see what each agent is doing without reading logs. Input is a Ruflo project and a task. Workflow: open /ruflo, switch to the swarm view, watch the tiles light up as agents read and write, and approve claims from the approvals view. Output is the same work, with every console action confirmed before it runs.

Acceptance test: in a fresh project, run init, then ruflo mods doctor. It should pass, or name the exact fix. Then run /ruflo dump overview inside Claude Code and confirm it prints a text view. If /ruflo is unknown, doctor should identify a stale marketplace copy.

Push it further

Experimental commentary. Moving routing into the host process removes most of the per-step overhead of an orchestration layer, which makes it practical to route every prompt rather than only some. The trust gate for mods that Claude writes during a session is the more interesting idea: it treats generated plugins as untrusted by default.

Limitation: it all depends on an early-access Claude Code API and a per-account rollout switch, and the 788-to-0 figure comes from the project's own test run. Falsifiable test: run the project's guard test suite against 3.51.1 and 3.52.0 plugins; the bypass count should fall to zero on 3.52.0 only.

Read the original on GitHub release

Release v3.52.0 at 0c1da453, consolidating v3.50.0 (27982983) and v3.51.0 (9e4fd175)

Ruflo repository

Back to the newsroom