ruvnet/ruflo/tree/main/plugins/ruflo-business-pods
ruflo-business-pods
Claude Code plugin (ADR-445 pattern) that ships a tighten-only tool guard hook denying business_pod_validate / business_pod_route_backend calls with secret-bearing, credential-path, or non-.json templates, plus a local /pods-mod command and a status file.
About this mod
Hooks-based Claude Code plugin from the ruflo repository providing function hooks that require no model call, no network and no process. The tool guard (default on, tighten-only, can only deny) refuses business_pod_validate / business_pod_route_backend calls whose template holds a secret or credential-named field, or whose template path climbs with .., points at a credentials location (.env, .ssh, .aws, ...) or is not a .json file; refusals never echo the offending value. The /pods-mod command answers locally with status, scan <text>, and path <template.json>. A status file .claude-flow/pods-mod/status.json (version, updatedMs, checked, blocked, byRule) is written at session start and after each refusal. Options via userConfig: guard (on/off, default on). Test with: claude plugin validate plugins/ruflo-business-pods && claude plugin test plugins/ruflo-business-pods && bash plugins/ruflo-business-pods/scripts/smoke.sh.
Installation
Check the author's README for the marketplace and plugin name first. Commands may change as the repository evolves.
claude plugin marketplace add ruvnet/ruflo claude plugin install ruflo-business-pods
Original text / README
As a mod
Function hooks (ADR-445 pattern, hooks/register.ts) that need no model call, no network and no process:
- Tool guard (default on, tighten-only: it can only deny). Refuses business_pod_validate / business_pod_route_backend calls whose template holds a secret or a credential-named field, or whose template path climbs with
.., points at a credentials location (.env,.ssh,.aws, ...) or is not a.jsonfile. A refusal never echoes the offending value. /pods-modanswers locally:status,scan <text>andpath <template.json>(would the guard let this path be read?). (A distinct name from the plugin's own commands/skills, which no hook can answer.)- Status file
.claude-flow/pods-mod/status.json(version,updatedMs,checked,blocked,byRule) is written at session start and after each refusal; the console reads it.
Options (userConfig): guard (on/off, default on).
Test: claude plugin validate plugins/ruflo-business-pods && claude plugin test plugins/ruflo-business-pods && bash plugins/ruflo-business-pods/scripts/smoke.sh.
