ClaudeMods
☰
EN
● 0 online · Views 0 times
SponsorsSubmit a project
GitHub repositories · by ruvnet

ruflo-bbs-federation

AgentBBS cross-host agent federation for ruflo (ADR-164). Phase 1 exposes room coordination — federation_bbs_register / federation_bbs_publish / federation_bbs_watch / federation_bbs_human_join. Phase 2 (v3.40.0) adds signed cross-host federation — federation_bbs_identity (persistent Ed25519 node identity), federation_bbs_peer_add (pin a peer by nodeId + public key), federation_bbs_peers (audit/unpin), federation_bbs_serve (read-only pull endpoint), and federation_bbs_sync (pull pinned peers and union-merge what verifies). Every merged envelope is Ed25519-verified against a pinned key; unsigned/misattributed/oversize/over-hop envelopes are dropped and counted. Transport is HTTP pull and works on any network (Tailscale, LAN, VPN, loopback) — no tailnet required. Coordinates work ownership via claim messages (ClaimIssued/Released/Handoff/Ack). agentbbs lives in optionalDependencies; every handler gracefully degrades to {degraded:true} when the package is missing (ADR-150 pattern). As a mod (ADR-445 pattern): a tighten-only tool guard, a local slash command, and a status file the console shows.

ruvnet@ruvnet

ruvnet/ruflo/tree/main/plugins/ruflo-bbs-federation

Translated

About this mod

As a mod

Function hooks (ADR-445 pattern, hooks/register.ts) that need no model call, no network and no process:

  • Tool guard (default on, tighten-only: it can only deny). Refuses federation_bbs_* calls that carry a secret in a published message or a credential-named field, a peer URL with embedded credentials or a non-http(s) scheme, and (unless allowed) a serve bind on every interface. A refusal never echoes the offending value.
  • /bbs-mod answers locally: status, scan <text> (would the guard refuse publishing this?) and peer <url> (would it accept this peer URL?). (A distinct name from the plugin's own commands/skills, which no hook can answer.)
  • Status file .claude-flow/bbs-mod/status.json (version, updatedMs, checked, blocked, byRule) is written at session start and after each refusal; the console reads it.

Options (userConfig): guard (on/off, default on), allowWildcardBind (default off).

Test: claude plugin validate plugins/ruflo-bbs-federation && claude plugin test plugins/ruflo-bbs-federation && bash plugins/ruflo-bbs-federation/scripts/smoke.sh.

Installation

Check the author's README for the marketplace and plugin name first. Commands may change as the repository evolves.

claude plugin marketplace add ruvnet/ruflo
claude plugin install ruflo-bbs-federation
Original text / README

As a mod

Function hooks (ADR-445 pattern, hooks/register.ts) that need no model call, no network and no process:

  • Tool guard (default on, tighten-only: it can only deny). Refuses federation_bbs_* calls that carry a secret in a published message or a credential-named field, a peer URL with embedded credentials or a non-http(s) scheme, and (unless allowed) a serve bind on every interface. A refusal never echoes the offending value.
  • /bbs-mod answers locally: status, scan <text> (would the guard refuse publishing this?) and peer <url> (would it accept this peer URL?). (A distinct name from the plugin's own commands/skills, which no hook can answer.)
  • Status file .claude-flow/bbs-mod/status.json (version, updatedMs, checked, blocked, byRule) is written at session start and after each refusal; the console reads it.

Options (userConfig): guard (on/off, default on), allowWildcardBind (default off).

Test: claude plugin validate plugins/ruflo-bbs-federation && claude plugin test plugins/ruflo-bbs-federation && bash plugins/ruflo-bbs-federation/scripts/smoke.sh.

Similar projects