Skip to content

v3.52.0: safer mods — guard holes 788 to 0, new optional abilities, Mods view in the console

Latest

Choose a tag to compare

@ruvnet ruvnet released this 05 Oct 12:26
· 8 commits to main since this release
e6267f3

In plain words

This release is about making the plugin "mods" safer and easier to see. Mods are the small background helpers that watch what Claude does (for example, refusing to save a password into memory). Overnight we tested every one of them hard, fixed the weak spots, and added a few optional new abilities.

Now on npm too. ruflo, claude-flow and @claude-flow/cli are published as 3.52.0 (all three tags: latest, alpha, v3alpha). The plugin changes below ship inside them and as marketplace plugin updates. @claude-flow/codex@3.0.3 was published first to fix bun add ruflo (see below).

Install fix: bun

bun add ruflo failed with "@claude-flow/codex missing version 3.0.3" (#3736). ruflo 3.51.1 asks for exactly codex 3.0.3, but only 3.0.2 existed on npm. npm hid this because it uses a bundled copy; bun does not. We published @claude-flow/codex@3.0.3, then installed ruflo with bun in a clean folder: it now installs and runs (ruflo v3.51.1).

What got safer

  • Secret guards no longer give up on big inputs. Before, 32 guards could be skipped by sending a very large or deeply nested message. They now refuse such input instead. In our test run (3,182 attempts) the number of ways around a guard went from 788 to 0.
  • Console: at the "write" level Claude could run a shell command through the console. That is closed. "Always allow" can no longer skip your chosen control level, and auto-confirm never answers questions about network, spending or deleting.
  • Memory guard (agentdb): it now catches secrets hidden with look-alike characters, and also checks the file you point memory_import at.
  • More secret-carrying tools are guarded, and a status file that is really a link or folder is never read.

What is new (all off by default)

Turn these on in ruflo-mods options if you want them:

  • agentTrim — hides agent types you never use. Measured saving: 4,236 tokens per session.
  • toolHints, deliveryScreen, capabilityProbe, sessionRollup, compactCarry — extra hints, message screening, a self-check, a counts-only history, and carrying swarm/claims state through /compact.
  • Console: a Mods section on the Room screen, clearer "waiting for you" banners, and a drive.sh script that lets a headless Claude click through the console for testing.

Numbers

  • Guard test holes: 788 → 0
  • Plugin smoke checks: 47 of 47 pass
  • Console tests: 1,106 pass
  • Cost of all mod hooks on an unrelated tool call: about 19 microseconds

What is NOT included

  • No dependency pin changes. No leaf package source changed since 3.51.1.
  • Draft PR #3751 (guard overlap) is not merged: it would make some guards weaker and needs a human decision.
  • Still open: see the follow-up issue.

How to update

npm: npx ruflo@latest or bun add ruflo. Plugins:

claude plugin marketplace update ruflo
claude plugin update ruflo-mods@ruflo --scope user
claude plugin update ruflo-console@ruflo --scope user
claude plugin update ruflo-agentdb@ruflo --scope user

(44 plugins changed in total; do the others the same way.) Then restart Claude Code.

72 pull requests, #3706 to #3784.