Atlas / Skills / ruvnet / Claims

ClaimsCAUTION

skills/ruvnet/claims

🌊 The original agent harness. Deploy intelligent multi-player swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory, self-learning intelligence, federation, vector RAG integration, and native Claude Code / Codex / Hermes and many more Integrated

Verdict
CAUTION
Grade
B
Trust score
89 /100
Version
—
Hosts
—
License
MIT
Stars
73,410
01

Overview

🌊 The original agent harness. Deploy intelligent multi-player swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory, self-learning intelligence, federation, vector RAG integration, and native Claude Code / Codex / Hermes and many more Integrated

Read from source at commit 3e0c089e8335OBSERVED · 2026-09-28
02

What it tells the agent

The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: claims
description: >
  Claims-based authorization for agents and operations. Grant, revoke, and verify permissions for secure multi-agent coordination.
  Use when: permission management, access control, secure operations, authorization checks.
  Skip when: open access, no security requirements, single-agent local work.
---

# Claims Authorization Skill

## Purpose
Claims-based authorization for secure agent operations and access control.

## Claim Types

| Claim | Description |
|-------|-------------|
| `read` | Read file access |
| `write` | Write file access |
| `execute` | Command execution |
| `spawn` | Agent spawning |
| `memory` | Memory access |
| `network` | Network access |
| `admin` | Administrative operations |

## Commands

### Check Claim
```bash
npx claude-flow claims check --agent agent-123 --claim write
```

### Grant Claim
```bash
npx claude-flow claims grant --agent agent-123 --claim write --scope "/src/**"
```

### Revoke Claim
```bash
npx claude-flow claims revoke --agent agent-123 --claim write
```

### List Claims
```bash
npx claude-flow claims list --agent agent-123
```

## Scope Patterns

| Pattern | Description |
|---------|-------------|
| `*` | All resources |
| `/src/**` | All files in src |
| `/config/*.toml` | TOML files in config |
| `memory:patterns` | Patterns namespace |

## Security Levels

| Level | Claims |
|-------|--------|
| `minimal` | read only |
| `standard` | read, write, execute |
| `elevated` | + spawn, memory |
| `admin` | all claims |

## Best Practices
1. Follow principle of least privilege
2. Scope claims to specific resources
3. Audit claim usage regularly
4. Revoke claims when no longer needed

## Cross-Host Work Claims (federation, v3.40.0+)

Distinct from the *authorization* claims above: **work claims** coordinate *ownership of a task or
resource* across agents, and now propagate across a cross-host federation so a claim made on one node
is visible to the whole swarm.

### Runtime tools (local ledger)

| Tool | Purpose |
|------|---------|
| `claims_claim` | Take ownership of an issue/resource (with optional TTL). |
| `claims_release` | Give up a claim you hold. |
| `claims_handoff` / `claims_accept-handoff` | Transfer a claim to another agent. |
| `claims_steal` / `claims_mark-stealable` | Work-stealing for stalled claims. |
| `claims_status` / `claims_list` | Inspect current ownership. |

### Federated (cross-host)

Publish claim events into a federation room (`federation_bbs_publish`) so ownership converges across
hosts. Message types: `ClaimIssued` / `ClaimReleased` / `ClaimHandoff` / `ClaimAck`.

Rules: one owner per `resourceId`; first valid `ClaimIssued` wins (ties → earliest ts, then smallest
`from`); `ClaimReleased` or expired TTL frees it; `ClaimHandoff` only from the current owner; a
coordinator posts `ClaimAck` naming the authoritative owner.

**Before shared work: claim, sync, and proceed only if you are the acknowledged owner.** When a claim
must be both cross-host visible and runtime-enforced, mirror the two — publish the federation claim
message *and* call `claims_claim`. See the `cross-host-federation` skill (ruflo-bbs-federation plugin)
for the transport.

### Scoping a claim stream to a channel (ADR-386)

By default every claim event lands in the shared swarm stream, where any relay member reads it. To
keep a team's ownership ledger separate — or unreadable by the rest of the relay — publish claim
messages into a channel instead:

```
npx ruflo federation channel --action create --name platform-team --visibility private
npx ruflo federation channel --action grant --channel prv:<hex> --pubkey <teammate 64-hex>
npx ruflo federation channel --action publish --channel prv:<hex> \
  --type ClaimIssued --payload '{"resourceId":"repo/foo","ttlSeconds":7200}'
npx ruflo federation channel --action read --channel prv:<hex>
```

Reduction rules are unchanged; only the audience changes. Two caveats before relying on it: a private
channel hides content but **not metadata** (the relay still sees who published and when), and a claim
nobody outside the channel can read cannot arbitrate against a claim made outside it. If ownership
must be swarm-wide, keep it on the open stream. See the `open-federation` skill for channel mechanics.
03

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeNA
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (4)

MEDIUMInventory / provenance · inv.symlink · CWE-1104
crates
crates
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
plugin/agents
plugin/agents
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
plugin/commands
plugin/commands
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
plugin/skills
plugin/skills
Why it matters. link not followed

Gates applied: no_behavioural_pass.

Audited 2026-09-28 · audit v0.4.1 · source sha 3e0c089e8335full audit observations/trust-audit/skill/ruvnet__claims.json · Report an issue / request a re-scan
04

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-09-283e0c089e8335CAUTIONB89first audit
05

Questions

What does the Claims skill do?

🌊 The original agent harness. Deploy intelligent multi-player swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory, self-learning intelligence, federation, vector RAG integration, and native Claude Code / Codex / Hermes and many more Integrated

Is Claims safe to install?

With care. The audit graded it B (89/100) and found 4 things worth knowing before you trust this skill, listed below with the exact line each was found on.

What can Claims access on my machine?

The audit observed no filesystem, network or shell use at all in its source.

How current is this page?

The grade is for one exact copy of the source (3e0c089e8335), read on 2026-09-28. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement