Project releases

Ruflo security fixes: blocked shell commands now stay blocked, credentials go only where configured

Ruflo 3.51.1 on October 2 fixes a hook that recognised a denied shell command but exited with a code Claude Code treats as non-blocking, so the command could still run. The same release pins credential-bearing MCP tools to their configured HTTPS destination. Two days earlier, @claude-flow/plugins 3.0.1 fixed SQL injection in the RuVector graph SQL builders.

GitHub activity: · Published:

What this is about

Ruflo sits between Claude Code and your machine. One of its jobs is to refuse things: dangerous shell commands, secrets leaving for the wrong place, unsafe database queries. This week brought three fixes where that refusal did not hold. Upgrading is recommended.

What changed

Ruflo 3.51.1, October 2 (commit 09a1cb02):

  • Denied shell commands now block (#3623). The pre-bash hook recognised a denied command but exited with status 1. Claude Code treats that as a non-blocking hook error, so the command could still run. Denials now exit with status 2, which Claude Code's PreToolUse step uses to block. The fix covers both shipped hook handlers and the one ruflo init generates.
  • Credentials go only to configured services (#3624). The federation and guidance MCP tools read credentials from the environment. Their destination is now pinned to the HTTPS base configured on the server. A URL passed as a tool argument is only checked against that base, never used instead of it, and every credential-bearing request rejects redirects. A loopback HTTP service is allowed for local gateways.
  • The release reports a fresh npx ruflo@3.51.1 init writing the exit-2 handler, and signed release manifests verifying 117 of 117 on Linux, macOS and Windows.

@claude-flow/plugins 3.0.1, September 30 (commit 3bcf7e96):

  • SQL injection in the RuVector graph SQL builders (#3531). Node ids and other strings were placed inside quotes without escaping, table names were quoted in a way a double quote could break, and numbers and JSON config were interpolated unchecked.
  • Every value now goes through a validator; unsafe input throws a TypeError instead of producing SQL. Version 3.0.0 and earlier are affected, but only for code that imports the GNN builder file by path, since it is not in the package's exports map.
  • The release reports a 25-test injection suite that fails 22 tests on the old code, an exploit smoke test passing 8 of 8 on the published 3.0.1 against 7 of 8 failing on 3.0.0, and a registry tarball identical to a clean build at 3bcf7e96.

Related reliability work in 3.49.0 (October 1) fixed eleven reported issues, including detection and repair of tampered helper files after install and a routing hook that used to report 70 percent confidence when nothing matched.

Get started

Prerequisites: an existing Ruflo project and Node.js. No new settings are needed.

npx ruflo@latest init upgrade
npm install @claude-flow/plugins@3.0.1

Expected result: after the upgrade, the generated hook handler exits with status 2 on a denied command, and Claude Code refuses to run it. For the plugins package, plain table and column names produce the same SQL as before; names such as my-table or schema.table are now rejected and need mapping to plain identifiers first.

MCP: these fixes change the existing Ruflo MCP server's behaviour; setup is unchanged (claude mcp add claude-flow -- npx ruflo@latest mcp start, as documented in the README). No skills change.

Commands here were read from the release notes and repository documentation at the pinned reference; they were not executed as part of writing this article.

Use it today

Practical case: you rely on a deny list so Claude Code never runs rm -rf or a deploy command. Input is your existing deny policy. Workflow: run init upgrade, then trigger a denied command in a scratch project. Output: the command is refused instead of logged as a hook error and run.

Acceptance test: before upgrading, check the exit status your pre-bash handler returns on a denied command. It should change from 1 to 2 after init upgrade, and Claude Code should show the command as blocked.

Push it further

Experimental commentary. The pre-bash bug is a reminder that a guard is only as strong as the host's contract for what blocking means. Exit codes are an easy place to be wrong, and a test that asserts the host actually refused the command catches it, where a test that asserts the guard recognised the command does not.

Limitation: these are the project's own reports and tests; no independent audit is cited. Falsifiable test: with 3.51.0 hooks, a denied command run through Claude Code should execute; with 3.51.1 hooks it should not.

Read the original on GitHub release

Release v3.51.1 at 09a1cb02 (issues #3623, #3624), with @claude-flow/plugins@3.0.1 at 3bcf7e96 (fixes #3531)

Ruflo repository

Back to the newsroom