ruvnet/ruflo/tree/main/plugins/ruflo-iot-cognitum
关于这个 mod
ruflo-iot-cognitum
面向 Cognitum Seed 硬件的 IoT 设备生命周期、遥测异常检测、机群管理和见证链验证。
硬件
此插件需要 Cognitum Seed 设备,可在 https://cognitum.one 获取。Seed 是边缘设备,具备设备端向量存储、Ed25519 身份、OTA 固件、网状网络和见证链。通过 USB-C 连接时,默认地址是 http://169.254.42.1⟧(链路本地、无认证)或 https://169.254.42.1:8443⟧(LAN;改变状态的操作需要 bearer 认证)。
概述
每台 Cognitum Seed 都是具备硬件能力的 Ruflo agent。设备经过 5 层信任模型,发出用于异常检测的遥测向量,参与网状网络,并维护用于溯源的 Ed25519 见证链。
由 `@claude-flow/plugin-iot-cognitum⟧ 支持(239 个测试、39 个源文件)。
安装
claude --plugin-dir plugins/ruflo-iot-cognitum
Agents
| Agent | Model | Role |
|-------|-------|------|
| device-coordinator⟧ | sonnet | 设备生命周期、5 层信任评分、网状协调 | | telemetry-analyzer⟧ | sonnet | Z-score 异常检测、SONA 学习、AgentDB 持久化 |
| fleet-manager⟧ | sonnet | 机群 CRUD、固件发布状态机、机群策略 | | witness-auditor⟧ | haiku | 见证链 epoch 验证、间隙检测 |
Skills
| Skill | Usage | Description |
|-------|-------|-------------|
| iot-register⟧ | /iot-register <endpoint>⟧ | 注册 Seed 设备 |
| iot-fleet⟧ | /iot-fleet <create|list|add|remove|delete>⟧ | 机群管理 |
| iot-anomalies⟧ | /iot-anomalies <device-id>⟧ | 检测遥测异常 |
| iot-firmware⟧ | /iot-firmware <deploy|advance|rollback|status|list>⟧ | 固件发布 |
| iot-witness-verify⟧ | /iot-witness-verify <device-id>⟧ | 验证见证链完整性 |
命令(25 个子命令)
# Device lifecycle
# `endpoint⟧ defaults to http://169.254.42.1/ (the Seed link-local USB Ethernet address)
iot register [endpoint] [--token TOKEN]
iot list
iot status <device-id>
iot pair <device-id>
iot unpair <device-id>
iot remove <device-id>
# Telemetry
iot ingest <device-id>
iot baseline <device-id> [--compute]
iot anomalies <device-id>
iot query <device-id> --vector "[1,2,3]" --k 10
# Fleet management
iot fleet create --name "my-fleet"
iot fleet list
iot fleet add <fleet-id> <device-id>
iot fleet remove <fleet-id> <device-id>
iot fleet delete <fleet-id>
# Firmware rollouts
iot firmware deploy <fleet-id> --version "2.0.0"
iot firmware advance <rollout-id>
iot firmware rollback <rollout-id>
iot firmware status <rollout-id>
iot firmware list
# Mesh & witness
iot mesh <device-id>
iot witness <device-id>
iot witness verify <device-id>
iot health <device-id>
iot trust <device-id>
信任模型(5 层)
| Level | Name | Score Range | Capabilities | |-------------|-------------|-------------|-------------| | 0 | UNKNOWN | 0.0–0.19 | 仅限发现 | | 1 | REGISTERED | 0.2–0.39 | 状态、身份查询 | | 2 | PROVISIONED | 0.4–0.59 | 遥测摄取、向量存储 | | 3 | CERTIFIED | 0.6–0.79 | 参与网状网络、发布固件 | | 4 | FLEET_TRUSTED | 0.8–1.0 | 完整机群操作、见证签名 |
信任分数公式:
0.3×pairingIntegrity + 0.15×firmwareCurrency + 0.2×uptimeStability
+ 0.15×witnessIntegrity + 0.1×anomalyHistory + 0.1×meshParticipation
异常检测
Z-score 综合评分:`min(1, meanZ/3)⟧
| Type | Detection Rule | Typical Cause | |------|----------------|---------------| | spike | maxZ > 5 | 传感器突然故障 | | flatline | all zero + low Z | 传感器断开 | | drift | 1-2 dimensions high Z | 校准逐渐丢失 | | oscillation | alternating high/low | 反馈循环 | | pattern-break | moderate Z, multiple dims | 环境变化 | | cluster-outlier | >50% dimensions high Z | 多传感器故障 |
固件发布状态机
pending → canary → rolling → complete
↘ rolled-back ↙
- canary:发布到 `ceil(deviceCount × canaryPercentage/100)⟧ 台设备。
- rolling:如果 canary 异常分数 < 回滚阈值,则发布到剩余设备。
- rolled-back:异常阈值被突破时触发强制回滚。
后台工作器
| Worker | Interval | Event |
|--------|----------|-------|
| HealthProbeWorker | 30s | iot:device-offline⟧ | | TelemetryIngestWorker | 60s | — | | AnomalyScanWorker | 120s | iot:anomaly-detected⟧ |
| MeshSyncWorker | 120s | iot:mesh-partition⟧ | | FirmwareWatchWorker | 300s | iot:firmware-mismatch⟧ |
| WitnessAuditWorker | 600s | `iot:witness-gap⟧ |
集成
- AgentDB HNSW:遥测向量存储在 `iot-telemetry⟧ 命名空间,使用 HNSW 索引(M=16,efConstruction=200)。
- SONA Neural:将异常模式交给 SONA,进行跨设备关联和预测性维护。
- Cognitum SDK:`@cognitum-one/sdk/seed⟧ 的 SeedClient,提供 12 个类型化端点。
兼容性
- **CLI:**固定到 `@claude-flow/cli⟧ v3.6 major+minor。
- **硬件:**需要 Cognitum Seed 设备。SDK:`@cognitum-one/sdk/seed⟧。
- 验证:`bash plugins/ruflo-iot-cognitum/scripts/smoke.sh⟧ 是契约。
命名空间协调
插件拥有五个 AgentDB 命名空间,全部符合 ruflo-agentdb ADR-0001 §"Namespace convention"(`<plugin-stem>-<intent>⟧ 的 kebab-case):
| Namespace | Purpose |
|-----------|---------|
| iot-devices⟧ | Cognitum Seed 的设备信任历史 | | iot-telemetry⟧ | 遥测向量(HNSW:M=16、efConstruction=200) |
| iot-telemetry-anomalies⟧ | 按类型 + 补救操作标记的已检测异常 | | iot-anomalies⟧ | 技能级异常索引(上方索引的别名) |
| `iot-audit⟧ | 见证链间隙记录 |
保留命名空间(pattern⟧、claude-memories⟧、`default⟧)不得被覆盖。
作为 mod(0.3.2)
一个 function-hook mod 与 skills 一起提供(ADR-445 模式)。需要支持 mods 的 Claude Code(2.1.287+),旧版本会忽略它。没有网络,也不启动进程;它只收紧对此插件工具的调用,并通过已连接的工具读取。
| Piece | Default | What it does |
|---|---|---|
| Write guard | on | 拒绝 secret 出现在 iot-*⟧ memory 记录或 cognitum-iot⟧ 命令行中。 |
| Destructive confirm | on | 除非命令带 --confirm⟧/--yes⟧ 或前缀 COGNITUM_IOT_CONFIRM=1⟧,否则拒绝 cognitum-iot fleet delete⟧ 和 device delete/remove/revoke/decommission/deregister⟧(回滚和列表不受影响)。 | | **/iot-mod⟧** | — | status⟧、scan <text>⟧、devices⟧;通过连接的 memory 工具读取 iot-devices⟧,本地回答,不调用模型。 |
| Status file | — | .claude-flow/iot-mod/status.json⟧(version⟧、`updatedMs⟧、模式标志和计数器);在工作阶段开始及计数器变化时写入。 |
选项(userConfig⟧):guard⟧ on|off、`confirmDestructive⟧ on|off。拒绝时绝不回显匹配值。
claude plugin test plugins/ruflo-iot-cognitum # 10 tests
与 federation 的信任模型并行
此插件的 5 层设备信任模型(UNKNOWN → REGISTERED → PROVISIONED → CERTIFIED → FLEET_TRUSTED)与 ruflo-federation 5-tier trust model(UNTRUSTED → VERIFIED → ATTESTED → TRUSTED → PRIVILEGED)形状相同。表面不同(IoT 设备与 federation 对等方),命名不同,但分数驱动推进和按能力门控的原则相同。
验证
bash plugins/ruflo-iot-cognitum/scripts/smoke.sh
# Expected: "12 passed, 0 failed"
架构决策
相关插件
- `ruflo-agentdb⟧ — HNSW 索引的遥测存储后端;命名空间约定所有者
- `ruflo-federation⟧ — 5 层信任模型并行(表面、命名和形状不同)
- `ruflo-intelligence⟧ — SONA 神经模式学习
- `ruflo-observability⟧ — 遥测关联与追踪
许可证
MIT
Endpoint references: http://169.254.42.1 and https://169.254.42.1:8443
安装
请先查看作者 README 确认 marketplace 和插件名称;命令可能随仓库结构改变。
claude plugin marketplace add ruvnet/ruflo claude plugin install ruflo-iot-cognitum
原文 / README
ruflo-iot-cognitum
IoT device lifecycle, telemetry anomaly detection, fleet management, and witness chain verification for Cognitum Seed hardware.
Hardware
This plugin requires a Cognitum Seed device. Get one at https://cognitum.one — the Seed is an edge appliance with on-device vector store, Ed25519 identity, OTA firmware, mesh networking, and a witness chain. Default address when attached via USB-C is http://169.254.42.1 (link-local, no auth) or https://169.254.42.1:8443 (LAN, bearer auth required for state-mutating operations).
Overview
Treats every Cognitum Seed device as a Ruflo agent with hardware capabilities. Devices progress through a 5-tier trust model, emit telemetry vectors for anomaly detection, participate in mesh networks, and maintain Ed25519 witness chains for provenance.
Backed by @claude-flow/plugin-iot-cognitum (239 tests, 39 source files).
Installation
claude --plugin-dir plugins/ruflo-iot-cognitum
Agents
| Agent | Model | Role |
|-------|-------|------|
| device-coordinator | sonnet | Device lifecycle, 5-tier trust scoring, mesh coordination |
| telemetry-analyzer | sonnet | Z-score anomaly detection, SONA learning, AgentDB persistence |
| fleet-manager | sonnet | Fleet CRUD, firmware rollout state machine, fleet policies |
| witness-auditor | haiku | Witness chain epoch verification, gap detection |
Skills
| Skill | Usage | Description |
|-------|-------|-------------|
| iot-register | /iot-register <endpoint> | Register a Seed device |
| iot-fleet | /iot-fleet <create\|list\|add\|remove\|delete> | Fleet management |
| iot-anomalies | /iot-anomalies <device-id> | Detect telemetry anomalies |
| iot-firmware | /iot-firmware <deploy\|advance\|rollback\|status\|list> | Firmware rollouts |
| iot-witness-verify | /iot-witness-verify <device-id> | Verify witness chain integrity |
Commands (25 subcommands)
# Device lifecycle
# `endpoint` defaults to http://169.254.42.1/ (the Seed link-local USB Ethernet address)
iot register [endpoint] [--token TOKEN]
iot list
iot status <device-id>
iot pair <device-id>
iot unpair <device-id>
iot remove <device-id>
# Telemetry
iot ingest <device-id>
iot baseline <device-id> [--compute]
iot anomalies <device-id>
iot query <device-id> --vector "[1,2,3]" --k 10
# Fleet management
iot fleet create --name "my-fleet"
iot fleet list
iot fleet add <fleet-id> <device-id>
iot fleet remove <fleet-id> <device-id>
iot fleet delete <fleet-id>
# Firmware rollouts
iot firmware deploy <fleet-id> --version "2.0.0"
iot firmware advance <rollout-id>
iot firmware rollback <rollout-id>
iot firmware status <rollout-id>
iot firmware list
# Mesh & witness
iot mesh <device-id>
iot witness <device-id>
iot witness verify <device-id>
iot health <device-id>
iot trust <device-id>
Trust Model (5 Tiers)
| Level | Name | Score Range | Capabilities | |-------|------|-------------|-------------| | 0 | UNKNOWN | 0.0–0.19 | Discovery only | | 1 | REGISTERED | 0.2–0.39 | Status, identity queries | | 2 | PROVISIONED | 0.4–0.59 | Telemetry ingest, vector store | | 3 | CERTIFIED | 0.6–0.79 | Mesh participation, firmware deploy | | 4 | FLEET_TRUSTED | 0.8–1.0 | Full fleet operations, witness signing |
Trust Score Formula:
0.3×pairingIntegrity + 0.15×firmwareCurrency + 0.2×uptimeStability
+ 0.15×witnessIntegrity + 0.1×anomalyHistory + 0.1×meshParticipation
Anomaly Detection
Z-score composite scoring: min(1, meanZ/3)
| Type | Detection Rule | Typical Cause | |------|---------------|---------------| | spike | maxZ > 5 | Sudden sensor failure | | flatline | all zero + low Z | Sensor disconnected | | drift | 1-2 dimensions high Z | Gradual calibration loss | | oscillation | alternating high/low | Feedback loop | | pattern-break | moderate Z, multiple dims | Environmental change | | cluster-outlier | >50% dimensions high Z | Multi-sensor failure |
Firmware Rollout State Machine
pending → canary → rolling → complete
↘ rolled-back ↙
- canary: Deploy to
ceil(deviceCount × canaryPercentage/100)devices - rolling: If canary anomaly score < rollback threshold, deploy to remaining
- rolled-back: Force rollback triggered by anomaly threshold breach
Background Workers
| Worker | Interval | Event |
|--------|----------|-------|
| HealthProbeWorker | 30s | iot:device-offline |
| TelemetryIngestWorker | 60s | — |
| AnomalyScanWorker | 120s | iot:anomaly-detected |
| MeshSyncWorker | 120s | iot:mesh-partition |
| FirmwareWatchWorker | 300s | iot:firmware-mismatch |
| WitnessAuditWorker | 600s | iot:witness-gap |
Integrations
- AgentDB HNSW: Telemetry vectors stored in
iot-telemetrynamespace with HNSW indexing (M=16, efConstruction=200) - SONA Neural: Anomaly patterns fed to SONA for cross-device correlation and predictive maintenance
- Cognitum SDK:
@cognitum-one/sdk/seedSeedClient with 12 typed endpoints
Compatibility
- CLI: pinned to
@claude-flow/cliv3.6 major+minor. - Hardware: requires Cognitum Seed device. SDK:
@cognitum-one/sdk/seed. - Verification:
bash plugins/ruflo-iot-cognitum/scripts/smoke.shis the contract.
Namespace coordination
This plugin owns five AgentDB namespaces, all compliant with the ruflo-agentdb ADR-0001 §"Namespace convention" (<plugin-stem>-<intent> kebab-case):
| Namespace | Purpose |
|-----------|---------|
| iot-devices | Device trust history per Cognitum Seed |
| iot-telemetry | Telemetry vectors (HNSW: M=16, efConstruction=200) |
| iot-telemetry-anomalies | Detected anomalies tagged by type + remedial action |
| iot-anomalies | Skill-level anomaly index (alias of above) |
| iot-audit | Witness-chain gap records |
Reserved namespaces (pattern, claude-memories, default) MUST NOT be shadowed.
As a mod (0.3.2)
A function-hook mod ships beside the skills (ADR-445 pattern). Needs a Claude Code with mods (2.1.287+); older builds ignore it. No network, no process spawning: it only tightens calls to this plugin's own tools and reads through tools already connected.
| Piece | Default | What it does |
|---|---|---|
| Write guard | on | Refuses a secret in an iot-* memory record, or on a cognitum-iot command line. |
| Destructive confirm | on | Refuses cognitum-iot fleet delete and device delete/remove/revoke/decommission/deregister unless the command has --confirm/--yes or the COGNITUM_IOT_CONFIRM=1 prefix (rollbacks and lists are untouched). |
| /iot-mod | — | status, scan <text>, devices (reads the iot-devices namespace through the connected memory tool); answered locally, no model call. |
| Status file | — | .claude-flow/iot-mod/status.json (version, updatedMs, mode flags and counters); written at session start and when a counter changes. |
Options (userConfig): guard on|off, confirmDestructive on|off. Refusals never echo the value they matched.
claude plugin test plugins/ruflo-iot-cognitum # 10 tests
Trust model parallel with federation
This plugin's 5-tier device trust model (UNKNOWN → REGISTERED → PROVISIONED → CERTIFIED → FLEET_TRUSTED) follows the same shape as the ruflo-federation 5-tier trust model (UNTRUSTED → VERIFIED → ATTESTED → TRUSTED → PRIVILEGED). Different surface (IoT devices vs federation peers) and distinct naming, but the score-driven progression and capability-gating principle are the same.
Verification
bash plugins/ruflo-iot-cognitum/scripts/smoke.sh
# Expected: "12 passed, 0 failed"
Architecture Decisions
Related Plugins
ruflo-agentdb— HNSW-indexed telemetry storage backend; namespace convention ownerruflo-federation— 5-tier trust model parallel (different surface, distinct naming, same shape)ruflo-intelligence— SONA neural pattern learningruflo-observability— Telemetry correlation and tracing
License
MIT

