v3.51.1: security fixes for the pre-bash hook and MCP service destinations
Security patch for @claude-flow/cli, claude-flow and ruflo (latest, alpha, v3alpha → 3.51.1). Upgrading is recommended.
PreToolUse pre-bash denials now block (#3623). When the hook handler recognised a denied command, it exited with status 1. Claude Code treats that as a non-blocking hook error, so the command could still run. Denials now exit 2, the status Claude Code's PreToolUse uses to block. The fix covers both shipped hook-handler.cjs copies and the handler ruflo init generates. Existing projects pick it up with npx ruflo@latest init upgrade (or a helper refresh).
MCP tools send credentials only to configured services (#3624). x_federation_* and seraphina_guidance read env-only credentials (RUFLO_X_ADMIN_TOKEN, SERAPHINA_METALLM_KEY). Their destinations are now pinned to the server-configured HTTPS base (RUFLO_X_GATEWAY_URL, SERAPHINA_METALLM_URL). A URL tool argument is only an assertion that must match that base; an absent, null or empty argument means no assertion. Every credential-bearing request rejects redirects. Operator configuration may name a loopback HTTP service for local or self-hosted gateways.
Verified: signed helper manifest at 3.51.1, witness manifests 117/117 on linux, macOS and Windows. A fresh npx ruflo@3.51.1 init writes the exit-2 handler.