ClaudeMods
☰
KO
● 0 명 접속 중 · 조회 0 회
후원프로젝트 제출
GitHub 저장소 · 작성자 ruvnet

ruflo-iot-cognitum

Cognitum Seed 하드웨어의 IoT 장치 수명 주기, 텔레메트리 이상 탐지, 플릿 관리 및 증인 체인 검증

ruvnet@ruvnet

ruvnet/ruflo/tree/main/plugins/ruflo-iot-cognitum

번역 완료

이 mod 소개

ruflo-iot-cognitum

Cognitum Seed 하드웨어를 위한 IoT 장치 수명 주기, 텔레메트리 이상 탐지, 플릿 관리 및 증인 체인 검증입니다.

하드웨어

Cognitum Seed 장치가 필요하며 https://cognitum.one에서 받을 수 있습니다. Seed는 장치 내 벡터 저장소, Ed25519 신원, OTA 펌웨어, 메시 네트워크와 증인 체인을 갖춘 엣지 장치입니다. USB-C 연결 시 기본 주소는 http://169.254.42.1⟧(링크 로컬, 인증 없음)또는 https://169.254.42.1:8443⟧(LAN, 상태 변경 작업에는 bearer 인증 필요)입니다.

개요

모든 Cognitum Seed 장치를 하드웨어 기능이 있는 Ruflo agent로 다룹니다. 장치는 5단계 신뢰 모델을 거치고 이상 탐지용 텔레메트리 벡터를 내보내며 메시 네트워크에 참여하고 출처 확인용 Ed25519 증인 체인을 유지합니다.

`@claude-flow/plugin-iot-cognitum⟧ 기반(테스트 239개, 소스 파일 39개)입니다.

설치

claude --plugin-dir plugins/ruflo-iot-cognitum

Agents

| Agent | Model | Role | |-------|-------|------| | device-coordinator⟧ | sonnet | 장치 수명 주기, 5단계 신뢰 점수, 메시 조정 | | telemetry-analyzer⟧ | sonnet | Z-score 이상 탐지, SONA 학습, AgentDB 영속화 | | fleet-manager⟧ | sonnet | 플릿 CRUD, 펌웨어 롤아웃 상태 머신, 플릿 정책 | | witness-auditor⟧ | haiku | 증인 체인 epoch 검증, 간격 탐지 |

Skills

| Skill | Usage | Description | |-------|-------|-------------| | iot-register⟧ | /iot-register <endpoint>⟧ | Seed 장치 등록 | | iot-fleet⟧ | /iot-fleet <create|list|add|remove|delete>⟧ | 플릿 관리 | | iot-anomalies⟧ | /iot-anomalies <device-id>⟧ | 텔레메트리 이상 탐지 | | iot-firmware⟧ | /iot-firmware <deploy|advance|rollback|status|list>⟧ | 펌웨어 롤아웃 | | iot-witness-verify⟧ | /iot-witness-verify <device-id>⟧ | 증인 체인 무결성 검증 |

명령(하위 명령 25개)

# Device lifecycle
# `endpoint⟧ defaults to http://169.254.42.1/ (the Seed link-local USB Ethernet address)
iot register [endpoint] [--token TOKEN]
iot list
iot status <device-id>
iot pair <device-id>
iot unpair <device-id>
iot remove <device-id>
# Telemetry
iot ingest <device-id>
iot baseline <device-id> [--compute]
iot anomalies <device-id>
iot query <device-id> --vector "[1,2,3]" --k 10
# Fleet management
iot fleet create --name "my-fleet"
iot fleet list
iot fleet add <fleet-id> <device-id>
iot fleet remove <fleet-id> <device-id>
iot fleet delete <fleet-id>
# Firmware rollouts
iot firmware deploy <fleet-id> --version "2.0.0"
iot firmware advance <rollout-id>
iot firmware rollback <rollout-id>
iot firmware status <rollout-id>
iot firmware list
# Mesh & witness
iot mesh <device-id>
iot witness <device-id>
iot witness verify <device-id>
iot health <device-id>
iot trust <device-id>

신뢰 모델(5단계)

| Level | Name | Score Range | Capabilities | |-------------|-------------|-------------|-------------| | 0 | UNKNOWN | 0.0–0.19 | 검색만 가능 | | 1 | REGISTERED | 0.2–0.39 | 상태, 신원 조회 | | 2 | PROVISIONED | 0.4–0.59 | 텔레메트리 수집, 벡터 저장소 | | 3 | CERTIFIED | 0.6–0.79 | 메시 참여, 펌웨어 배포 | | 4 | FLEET_TRUSTED | 0.8–1.0 | 전체 플릿 작업, 증인 서명 |

신뢰 점수 공식:

0.3×pairingIntegrity + 0.15×firmwareCurrency + 0.2×uptimeStability
+ 0.15×witnessIntegrity + 0.1×anomalyHistory + 0.1×meshParticipation

이상 탐지

Z-score 종합 점수: `min(1, meanZ/3)⟧

| Type | Detection Rule | Typical Cause | |------|----------------|---------------| | spike | maxZ > 5 | 갑작스러운 센서 고장 | | flatline | all zero + low Z | 센서 연결 해제 | | drift | 1-2 dimensions high Z | 점진적 보정 손실 | | oscillation | alternating high/low | 피드백 루프 | | pattern-break | moderate Z, multiple dims | 환경 변화 | | cluster-outlier | >50% dimensions high Z | 다중 센서 고장 |

펌웨어 롤아웃 상태 머신

pending → canary → rolling → complete
                ↘ rolled-back ↙
  • canary: `ceil(deviceCount × canaryPercentage/100)⟧개 장치에 배포
  • rolling: canary 이상 점수 < 롤백 임계값이면 나머지에 배포
  • rolled-back: 이상 임계값 초과로 강제 롤백

백그라운드 워커

| Worker | Interval | Event | |--------|----------|-------| | HealthProbeWorker | 30s | iot:device-offline⟧ | | TelemetryIngestWorker | 60s | — | | AnomalyScanWorker | 120s | iot:anomaly-detected⟧ | | MeshSyncWorker | 120s | iot:mesh-partition⟧ | | FirmwareWatchWorker | 300s | iot:firmware-mismatch⟧ | | WitnessAuditWorker | 600s | `iot:witness-gap⟧ |

통합

  • AgentDB HNSW: 텔레메트리 벡터를 `iot-telemetry⟧ 네임스페이스에 저장하고 HNSW 색인(M=16, efConstruction=200)을 사용합니다.
  • SONA Neural: 이상 패턴을 SONA에 공급해 장치 간 상관관계와 예측 유지 보수를 수행합니다.
  • Cognitum SDK: `@cognitum-one/sdk/seed⟧의 SeedClient, 12개 타입 지정 엔드포인트.

호환성

  • CLI: `@claude-flow/cli⟧ v3.6 major+minor에 고정됩니다.
  • 하드웨어: Cognitum Seed 장치 필요. SDK: `@cognitum-one/sdk/seed⟧
  • 검증: `bash plugins/ruflo-iot-cognitum/scripts/smoke.sh⟧가 계약입니다.

네임스페이스 조정

5개의 AgentDB 네임스페이스를 소유하며 ruflo-agentdb ADR-0001 §"Namespace convention"(`<plugin-stem>-<intent>⟧ kebab-case)을 준수합니다.

| Namespace | Purpose | |-----------|---------| | iot-devices⟧ | Cognitum Seed별 장치 신뢰 이력 | | iot-telemetry⟧ | 텔레메트리 벡터(HNSW: M=16, efConstruction=200) | | iot-telemetry-anomalies⟧ | 유형 + 복구 작업으로 태그된 이상 | | iot-anomalies⟧ | 스킬 수준 이상 색인(위 항목의 별칭) | | `iot-audit⟧ | 증인 체인 간격 기록 |

예약된 네임스페이스(pattern⟧, claude-memories⟧, `default⟧)를 가로채면 안 됩니다.

mod로 사용(0.3.2)

function-hook mod가 skills와 함께 제공됩니다(ADR-445 패턴). mods를 지원하는 Claude Code(2.1.287+)가 필요하며 이전 빌드는 무시합니다. 네트워크나 프로세스 생성은 하지 않고 이 플러그인의 도구 호출만 강화하며 연결된 도구로 읽습니다.

| Piece | Default | What it does | |---|---|---| | Write guard | on | iot-*⟧ memory record 또는 cognitum-iot⟧ 명령줄의 secret을 거부 | | Destructive confirm | on | --confirm⟧/--yes⟧ 또는 COGNITUM_IOT_CONFIRM=1⟧ 접두사가 없으면 fleet/device 삭제 계열을 거부 | | **/iot-mod⟧** | — | status⟧, scan <text>⟧, devices⟧를 로컬에서 응답하고 연결된 memory 도구로 iot-devices⟧를 읽음 | | Status file | — | .claude-flow/iot-mod/status.json⟧(version⟧, `updatedMs⟧, 모드 플래그와 카운터)를 세션 시작 및 변경 시 기록 |

옵션(userConfig⟧): guard⟧ on|off, `confirmDestructive⟧ on|off. 거부한 값은 표시하지 않습니다.

claude plugin test plugins/ruflo-iot-cognitum   # 10 tests

federation과의 신뢰 모델 병렬 구조

이 플러그인의 5단계 장치 신뢰 모델(UNKNOWN → REGISTERED → PROVISIONED → CERTIFIED → FLEET_TRUSTED)은 ruflo-federation 5-tier trust model(UNTRUSTED → VERIFIED → ATTESTED → TRUSTED → PRIVILEGED)과 같은 형태입니다. 표면(IoT 장치와 federation 피어)과 이름은 다르지만 점수 기반 진행과 기능 게이팅 원칙은 같습니다.

검증

bash plugins/ruflo-iot-cognitum/scripts/smoke.sh
# Expected: "12 passed, 0 failed"

아키텍처 결정

관련 플러그인

  • `ruflo-agentdb⟧ — HNSW 색인 텔레메트리 저장 백엔드; 네임스페이스 규약 소유자
  • `ruflo-federation⟧ — 5단계 신뢰 모델 병렬
  • `ruflo-intelligence⟧ — SONA 신경 패턴 학습
  • `ruflo-observability⟧ — 텔레메트리 상관관계 및 추적

라이선스

MIT

Endpoint references: http://169.254.42.1 and https://169.254.42.1:8443

설치

먼저 작성자의 README에서 marketplace와 플러그인 이름을 확인하세요. 저장소 구조에 따라 명령어가 달라질 수 있습니다.

claude plugin marketplace add ruvnet/ruflo
claude plugin install ruflo-iot-cognitum
원문 / README

ruflo-iot-cognitum

IoT device lifecycle, telemetry anomaly detection, fleet management, and witness chain verification for Cognitum Seed hardware.

Hardware

This plugin requires a Cognitum Seed device. Get one at https://cognitum.one — the Seed is an edge appliance with on-device vector store, Ed25519 identity, OTA firmware, mesh networking, and a witness chain. Default address when attached via USB-C is http://169.254.42.1 (link-local, no auth) or https://169.254.42.1:8443 (LAN, bearer auth required for state-mutating operations).

Overview

Treats every Cognitum Seed device as a Ruflo agent with hardware capabilities. Devices progress through a 5-tier trust model, emit telemetry vectors for anomaly detection, participate in mesh networks, and maintain Ed25519 witness chains for provenance.

Backed by @claude-flow/plugin-iot-cognitum (239 tests, 39 source files).

Installation

claude --plugin-dir plugins/ruflo-iot-cognitum

Agents

| Agent | Model | Role | |-------|-------|------| | device-coordinator | sonnet | Device lifecycle, 5-tier trust scoring, mesh coordination | | telemetry-analyzer | sonnet | Z-score anomaly detection, SONA learning, AgentDB persistence | | fleet-manager | sonnet | Fleet CRUD, firmware rollout state machine, fleet policies | | witness-auditor | haiku | Witness chain epoch verification, gap detection |

Skills

| Skill | Usage | Description | |-------|-------|-------------| | iot-register | /iot-register <endpoint> | Register a Seed device | | iot-fleet | /iot-fleet <create\|list\|add\|remove\|delete> | Fleet management | | iot-anomalies | /iot-anomalies <device-id> | Detect telemetry anomalies | | iot-firmware | /iot-firmware <deploy\|advance\|rollback\|status\|list> | Firmware rollouts | | iot-witness-verify | /iot-witness-verify <device-id> | Verify witness chain integrity |

Commands (25 subcommands)

# Device lifecycle
# `endpoint` defaults to http://169.254.42.1/ (the Seed link-local USB Ethernet address)
iot register [endpoint] [--token TOKEN]
iot list
iot status <device-id>
iot pair <device-id>
iot unpair <device-id>
iot remove <device-id>

# Telemetry
iot ingest <device-id>
iot baseline <device-id> [--compute]
iot anomalies <device-id>
iot query <device-id> --vector "[1,2,3]" --k 10

# Fleet management
iot fleet create --name "my-fleet"
iot fleet list
iot fleet add <fleet-id> <device-id>
iot fleet remove <fleet-id> <device-id>
iot fleet delete <fleet-id>

# Firmware rollouts
iot firmware deploy <fleet-id> --version "2.0.0"
iot firmware advance <rollout-id>
iot firmware rollback <rollout-id>
iot firmware status <rollout-id>
iot firmware list

# Mesh & witness
iot mesh <device-id>
iot witness <device-id>
iot witness verify <device-id>
iot health <device-id>
iot trust <device-id>

Trust Model (5 Tiers)

| Level | Name | Score Range | Capabilities | |-------|------|-------------|-------------| | 0 | UNKNOWN | 0.0–0.19 | Discovery only | | 1 | REGISTERED | 0.2–0.39 | Status, identity queries | | 2 | PROVISIONED | 0.4–0.59 | Telemetry ingest, vector store | | 3 | CERTIFIED | 0.6–0.79 | Mesh participation, firmware deploy | | 4 | FLEET_TRUSTED | 0.8–1.0 | Full fleet operations, witness signing |

Trust Score Formula:

0.3×pairingIntegrity + 0.15×firmwareCurrency + 0.2×uptimeStability
+ 0.15×witnessIntegrity + 0.1×anomalyHistory + 0.1×meshParticipation

Anomaly Detection

Z-score composite scoring: min(1, meanZ/3)

| Type | Detection Rule | Typical Cause | |------|---------------|---------------| | spike | maxZ > 5 | Sudden sensor failure | | flatline | all zero + low Z | Sensor disconnected | | drift | 1-2 dimensions high Z | Gradual calibration loss | | oscillation | alternating high/low | Feedback loop | | pattern-break | moderate Z, multiple dims | Environmental change | | cluster-outlier | >50% dimensions high Z | Multi-sensor failure |

Firmware Rollout State Machine

pending → canary → rolling → complete
                ↘ rolled-back ↙
  • canary: Deploy to ceil(deviceCount × canaryPercentage/100) devices
  • rolling: If canary anomaly score < rollback threshold, deploy to remaining
  • rolled-back: Force rollback triggered by anomaly threshold breach

Background Workers

| Worker | Interval | Event | |--------|----------|-------| | HealthProbeWorker | 30s | iot:device-offline | | TelemetryIngestWorker | 60s | — | | AnomalyScanWorker | 120s | iot:anomaly-detected | | MeshSyncWorker | 120s | iot:mesh-partition | | FirmwareWatchWorker | 300s | iot:firmware-mismatch | | WitnessAuditWorker | 600s | iot:witness-gap |

Integrations

  • AgentDB HNSW: Telemetry vectors stored in iot-telemetry namespace with HNSW indexing (M=16, efConstruction=200)
  • SONA Neural: Anomaly patterns fed to SONA for cross-device correlation and predictive maintenance
  • Cognitum SDK: @cognitum-one/sdk/seed SeedClient with 12 typed endpoints

Compatibility

  • CLI: pinned to @claude-flow/cli v3.6 major+minor.
  • Hardware: requires Cognitum Seed device. SDK: @cognitum-one/sdk/seed.
  • Verification: bash plugins/ruflo-iot-cognitum/scripts/smoke.sh is the contract.

Namespace coordination

This plugin owns five AgentDB namespaces, all compliant with the ruflo-agentdb ADR-0001 §"Namespace convention" (<plugin-stem>-<intent> kebab-case):

| Namespace | Purpose | |-----------|---------| | iot-devices | Device trust history per Cognitum Seed | | iot-telemetry | Telemetry vectors (HNSW: M=16, efConstruction=200) | | iot-telemetry-anomalies | Detected anomalies tagged by type + remedial action | | iot-anomalies | Skill-level anomaly index (alias of above) | | iot-audit | Witness-chain gap records |

Reserved namespaces (pattern, claude-memories, default) MUST NOT be shadowed.

As a mod (0.3.2)

A function-hook mod ships beside the skills (ADR-445 pattern). Needs a Claude Code with mods (2.1.287+); older builds ignore it. No network, no process spawning: it only tightens calls to this plugin's own tools and reads through tools already connected.

| Piece | Default | What it does | |---|---|---| | Write guard | on | Refuses a secret in an iot-* memory record, or on a cognitum-iot command line. | | Destructive confirm | on | Refuses cognitum-iot fleet delete and device delete/remove/revoke/decommission/deregister unless the command has --confirm/--yes or the COGNITUM_IOT_CONFIRM=1 prefix (rollbacks and lists are untouched). | | /iot-mod | — | status, scan <text>, devices (reads the iot-devices namespace through the connected memory tool); answered locally, no model call. | | Status file | — | .claude-flow/iot-mod/status.json (version, updatedMs, mode flags and counters); written at session start and when a counter changes. |

Options (userConfig): guard on|off, confirmDestructive on|off. Refusals never echo the value they matched.

claude plugin test plugins/ruflo-iot-cognitum   # 10 tests

Trust model parallel with federation

This plugin's 5-tier device trust model (UNKNOWN → REGISTERED → PROVISIONED → CERTIFIED → FLEET_TRUSTED) follows the same shape as the ruflo-federation 5-tier trust model (UNTRUSTED → VERIFIED → ATTESTED → TRUSTED → PRIVILEGED). Different surface (IoT devices vs federation peers) and distinct naming, but the score-driven progression and capability-gating principle are the same.

Verification

bash plugins/ruflo-iot-cognitum/scripts/smoke.sh
# Expected: "12 passed, 0 failed"

Architecture Decisions

Related Plugins

  • ruflo-agentdb — HNSW-indexed telemetry storage backend; namespace convention owner
  • ruflo-federation — 5-tier trust model parallel (different surface, distinct naming, same shape)
  • ruflo-intelligence — SONA neural pattern learning
  • ruflo-observability — Telemetry correlation and tracing

License

MIT

비슷한 프로젝트