Managed AgentCAUTION
π The original agent harness. Deploy intelligent multi-player swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory, self-learning intelligence, federation, vector RAG integration, and native Claude Code / Codex / Hermes and many more Integrated
Overview
π The original agent harness. Deploy intelligent multi-player swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory, self-learning intelligence, federation, vector RAG integration, and native Claude Code / Codex / Hermes and many more Integrated
ef7d4f0535e5OBSERVED Β· 2026-09-26What it tells the agent
The instruction file, verbatim from the audited commit β this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
---
name: managed-agent
description: Run an Anthropic Claude Managed Agent β a cloud agent harness (container + filesystem + tools), the cloud counterpart of the local wasm-agent runtime
argument-hint: "<create|prompt|status|events|list|terminate> [options]"
allowed-tools: mcp__plugin_ruflo-core_ruflo__managed_agent_create mcp__plugin_ruflo-core_ruflo__managed_agent_prompt mcp__plugin_ruflo-core_ruflo__managed_agent_status mcp__plugin_ruflo-core_ruflo__managed_agent_events mcp__plugin_ruflo-core_ruflo__managed_agent_list mcp__plugin_ruflo-core_ruflo__managed_agent_terminate mcp__plugin_ruflo-core_ruflo__wasm_agent_create Bash
---
# Managed Agent (Anthropic cloud runtime)
`ruflo-agent` has two agent runtimes behind one mental model:
| Runtime | Tools | Use it when |
|---|---|---|
| **WASM** (local, `rvagent`) | `wasm_agent_*` / `wasm_gallery_*` | fast, free, ephemeral, offline, untrusted code in a sandbox |
| **Managed** (Anthropic cloud) | `managed_agent_*` (this skill) | long-running / async work (minutesβhours), a real cloud container with pre-installed packages + network, persistent filesystem + transcript across turns |
This skill drives the **managed** runtime β Anthropic's [Claude Managed Agents](https://platform.claude.com/docs/en/managed-agents/overview) (beta). The model: **Agent** (model + system + tools + MCP servers + skills) β **Environment** (container template) β **Session** (running instance) β **Events** (turns / tool-use / status, persisted server-side). See `docs/adr/0001-wasm-contract.md` and project ADR-115.
## Prerequisites
- `ANTHROPIC_API_KEY` (or `CLAUDE_API_KEY`) in the environment, with Claude Managed Agents beta access.
- If absent, every `managed_agent_*` tool returns a structured "use `wasm_agent_create` for a local no-key runtime" error β fall back to the WASM skill.
## Steps
1. **Create** β `mcp__plugin_ruflo-core_ruflo__managed_agent_create`
`{ model?, system?, name?, networking?, packages?, initScript?, mcpServers?, skills? }`
β `{ sessionId, agentId, environmentId, status }`. Provisions Agent + Environment + Session. Save the three ids.
- `mcpServers`: `[{type:"url", url, name, authorization_token?}]` β the cloud agent must be able to *reach* the URL. A local `ruflo mcp start` is **not** reachable from Anthropic's cloud; deploy/tunnel an HTTP ruflo MCP server first if you want the cloud agent to have ruflo's tools.
- `packages`: `{pip?:[], npm?:[], apt?:[], cargo?:[], gem?:[], go?:[]}` β installed in the container.
2. **Prompt** β `mcp__plugin_ruflo-core_ruflo__managed_agent_prompt`
`{ sessionId, message, maxWaitMs? }` β sends a user turn, polls the event log until the session goes idle (default 180s, capped 600s) β `{ finished, status, stopReason, assistantText, toolUses[], eventCount }`. For very long tasks, raise `maxWaitMs` or follow up with `managed_agent_events`.
3. **Inspect** β `mcp__plugin_ruflo-core_ruflo__managed_agent_status` `{ sessionId }` (idle/running/error) Β· `mcp__plugin_ruflo-core_ruflo__managed_agent_events` `{ sessionId, raw? }` (full transcript: user turns, agent thinking, tool_use, tool_result, status β the cloud counterpart of `wasm_agent_files`).
4. **List** β `mcp__plugin_ruflo-core_ruflo__managed_agent_list` `{ limit? }` β every session on the org (so you can see which are still running / billing).
5. **Terminate** β `mcp__plugin_ruflo-core_ruflo__managed_agent_terminate` `{ sessionId, environmentId? }` β **always do this when done**: a cloud session keeps billing container time + tokens until deleted. Pass `environmentId` to also delete the environment ruflo created.
## Cost & safety
- Managed Agents bill per session (LM tokens + container time) and are rate-limited per org. Estimate before a long run; record completed sessions to the `cost-tracking` namespace.
- Treat orphaned sessions like leaked resources β `managed_agent_list` then `managed_agent_terminate` anything stale.
- Beta API (`managed-agents-2026-04-01`); `multiagent` / `define-outcomes` on the agent config are research preview.
## Quick example
```
managed_agent_create { "model": "claude-haiku-4-5-20251001", "system": "Terse. Do exactly what is asked.", "name": "scratch" }
β { sessionId: "sesn_...", agentId: "agent_...", environmentId: "env_...", status: "idle" }
managed_agent_prompt { "sessionId": "sesn_...", "message": "echo hello > /tmp/x && cat /tmp/x β then stop." , "maxWaitMs": 60000 }
β { finished: true, status: "idle", stopReason: "end_turn", assistantText: "Done.", toolUses: [{name:"bash", input:{command:"echo hello > /tmp/x && cat /tmp/x"}}] }
managed_agent_terminate { "sessionId": "sesn_...", "environmentId": "env_..." }
β { sessionDeleted: true, environmentDeleted: true }
```Trust audit
CAUTIONgrade B Β· trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | NA |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (4)
crates
plugin/agents
plugin/commands
plugin/skills
Gates applied: no_behavioural_pass.
ef7d4f0535e5full audit observations/trust-audit/skill/ruvnet__managed-agent.json Β· Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-26 | ef7d4f0535e5 | CAUTION | B | 89 | first audit |
Questions
What does the Managed Agent skill do?
π The original agent harness. Deploy intelligent multi-player swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory, self-learning intelligence, federation, vector RAG integration, and native Claude Code / Codex / Hermes and many more Integrated
Is Managed Agent safe to install?
With care. The audit graded it B (89/100) and found 4 things worth knowing before you trust this skill, listed below with the exact line each was found on.
What can Managed Agent access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
How current is this page?
The grade is for one exact copy of the source (ef7d4f0535e5), read on 2026-09-26. The repository is watched, and a new audit runs when it changes β this is the first audit.