ClaudeMods
☰
ZH-TW
● 0 人在線上 · 瀏覽 0 次
贊助提交作品
GitHub 儲存庫 · 發布者 ruvnet

ruflo-iot-cognitum

Cognitum Seed 硬體的 IoT 裝置生命週期、遙測異常偵測、裝置群組管理與見證鏈驗證

ruvnet@ruvnet

ruvnet/ruflo/tree/main/plugins/ruflo-iot-cognitum

已翻譯

關於這個 mod

ruflo-iot-cognitum

Cognitum Seed 硬體的 IoT 裝置生命週期、遙測異常偵測、裝置群組管理與見證鏈驗證。

硬體

這個外掛需要一台 Cognitum Seed 裝置,可在 https://cognitum.one 取得。Seed 是邊緣設備,具備裝置端向量儲存、Ed25519 身分、OTA 韌體、網狀網路與見證鏈。透過 USB-C 連接時,預設位址是 http://169.254.42.1⟧(連結本地、不需驗證)或 https://169.254.42.1:8443⟧(LAN;會變更狀態的操作需要 bearer 驗證)。

概覽

每台 Cognitum Seed 都是具備硬體能力的 Ruflo agent。裝置會經過 5 層信任模型,發出用於異常偵測的遙測向量、參與網狀網路,並維護用於溯源的 Ed25519 見證鏈。

由 `@claude-flow/plugin-iot-cognitum⟧ 支援(239 個測試、39 個原始檔)。

安裝

claude --plugin-dir plugins/ruflo-iot-cognitum

Agents

| Agent | Model | Role | |-------|-------|------| | device-coordinator⟧ | sonnet | 裝置生命週期、5 層信任評分、網狀協調 | | telemetry-analyzer⟧ | sonnet | Z-score 異常偵測、SONA 學習、AgentDB 持久化 | | fleet-manager⟧ | sonnet | 裝置群組 CRUD、韌體推出狀態機、裝置群組政策 | | witness-auditor⟧ | haiku | 見證鏈 epoch 驗證、間隙偵測 |

Skills

| Skill | Usage | Description | |-------|-------|-------------| | iot-register⟧ | /iot-register <endpoint>⟧ | 註冊 Seed 裝置 | | iot-fleet⟧ | /iot-fleet <create|list|add|remove|delete>⟧ | 裝置群組管理 | | iot-anomalies⟧ | /iot-anomalies <device-id>⟧ | 偵測遙測異常 | | iot-firmware⟧ | /iot-firmware <deploy|advance|rollback|status|list>⟧ | 韌體推出 | | iot-witness-verify⟧ | /iot-witness-verify <device-id>⟧ | 驗證見證鏈完整性 |

命令(25 個子命令)

# Device lifecycle
# `endpoint⟧ 預設為 http://169.254.42.1/(Seed 的連結本地 USB Ethernet 位址)
iot register [endpoint] [--token TOKEN]
iot list
iot status <device-id>
iot pair <device-id>
iot unpair <device-id>
iot remove <device-id>
# Telemetry
iot ingest <device-id>
iot baseline <device-id> [--compute]
iot anomalies <device-id>
iot query <device-id> --vector "[1,2,3]" --k 10
# Fleet management
iot fleet create --name "my-fleet"
iot fleet list
iot fleet add <fleet-id> <device-id>
iot fleet remove <fleet-id> <device-id>
iot fleet delete <fleet-id>
# Firmware rollouts
iot firmware deploy <fleet-id> --version "2.0.0"
iot firmware advance <rollout-id>
iot firmware rollback <rollout-id>
iot firmware status <rollout-id>
iot firmware list
# Mesh & witness
iot mesh <device-id>
iot witness <device-id>
iot witness verify <device-id>
iot health <device-id>
iot trust <device-id>

信任模型(5 層)

| Level | Name | Score Range | Capabilities | |-------------|-------------|-------------|-------------| | 0 | UNKNOWN | 0.0–0.19 | 僅限探索 | | 1 | REGISTERED | 0.2–0.39 | 狀態、身分查詢 | | 2 | PROVISIONED | 0.4–0.59 | 遙測攝取、向量儲存 | | 3 | CERTIFIED | 0.6–0.79 | 參與網狀網路、推出韌體 | | 4 | FLEET_TRUSTED | 0.8–1.0 | 完整裝置群組操作、見證簽署 |

信任分數公式:

0.3×pairingIntegrity + 0.15×firmwareCurrency + 0.2×uptimeStability
+ 0.15×witnessIntegrity + 0.1×anomalyHistory + 0.1×meshParticipation

異常偵測

Z-score 綜合評分:`min(1, meanZ/3)⟧

| Type | Detection Rule | Typical Cause | |------|----------------|---------------| | spike | maxZ > 5 | 感測器突然故障 | | flatline | all zero + low Z | 感測器中斷連線 | | drift | 1-2 dimensions high Z | 校準逐漸偏移 | | oscillation | alternating high/low | 回饋迴圈 | | pattern-break | moderate Z, multiple dims | 環境變化 | | cluster-outlier | >50% dimensions high Z | 多感測器故障 |

韌體推出狀態機

pending → canary → rolling → complete
                ↘ rolled-back ↙
  • canary:部署到 `ceil(deviceCount × canaryPercentage/100)⟧ 台裝置。
  • rolling:如果 canary 異常分數 < 回滾門檻,就部署到其餘裝置。
  • rolled-back:異常門檻被突破時觸發強制回滾。

背景工作器

| Worker | Interval | Event | |--------|----------|-------| | HealthProbeWorker | 30s | iot:device-offline⟧ | | TelemetryIngestWorker | 60s | — | | AnomalyScanWorker | 120s | iot:anomaly-detected⟧ | | MeshSyncWorker | 120s | iot:mesh-partition⟧ | | FirmwareWatchWorker | 300s | iot:firmware-mismatch⟧ | | WitnessAuditWorker | 600s | `iot:witness-gap⟧ |

整合

  • AgentDB HNSW:遙測向量儲存在 `iot-telemetry⟧ 命名空間,使用 HNSW 索引(M=16、efConstruction=200)。
  • SONA Neural:將異常模式交給 SONA,進行跨裝置關聯與預測性維護。
  • Cognitum SDK:`@cognitum-one/sdk/seed⟧ 的 SeedClient,提供 12 個具型別端點。

相容性

  • **CLI:**固定使用 `@claude-flow/cli⟧ v3.6 major+minor。
  • **硬體:**需要 Cognitum Seed 裝置。SDK:`@cognitum-one/sdk/seed⟧。
  • 驗證:`bash plugins/ruflo-iot-cognitum/scripts/smoke.sh⟧ 是契約。

命名空間協調

這個外掛擁有五個 AgentDB 命名空間,全部符合 ruflo-agentdb ADR-0001 §"Namespace convention"(`<plugin-stem>-<intent>⟧ kebab-case):

| Namespace | Purpose | |-----------|---------| | iot-devices⟧ | Cognitum Seed 的裝置信任歷史 | | iot-telemetry⟧ | 遙測向量(HNSW:M=16、efConstruction=200) | | iot-telemetry-anomalies⟧ | 依類型 + 補救行動標記的已偵測異常 | | iot-anomalies⟧ | 技能層級的異常索引(上列索引的別名) | | `iot-audit⟧ | 見證鏈間隙記錄 |

保留命名空間(pattern⟧、claude-memories⟧、`default⟧)不得被覆蓋。

作為 mod(0.3.2)

function-hook mod 會與 skills 一起提供(ADR-445 模式)。需要支援 mods 的 Claude Code(2.1.287+),舊版本會忽略它。沒有網路,也不會啟動程序;它只收緊對這個外掛工具的呼叫,並透過已連接的工具讀取。

| Piece | Default | What it does | |---|---|---| | Write guard | on | 拒絕 secret 出現在 iot-*⟧ memory 記錄或 cognitum-iot⟧ 命令列。 | | Destructive confirm | on | 除非命令帶 --confirm⟧/--yes⟧ 或前綴 COGNITUM_IOT_CONFIRM=1⟧,否則拒絕 cognitum-iot fleet delete⟧ 與 device delete/remove/revoke/decommission/deregister⟧(回滾與列表不受影響)。 | | **/iot-mod⟧** | — | status⟧、scan <text>⟧、devices⟧;透過連接的 memory 工具讀取 iot-devices⟧,在本地回答,不呼叫模型。 | | Status file | — | .claude-flow/iot-mod/status.json⟧(version⟧、`updatedMs⟧、模式旗標與計數器);在工作階段開始與計數器變更時寫入。 |

選項(userConfig⟧):guard⟧ on|off、`confirmDestructive⟧ on|off。拒絕時絕不回顯符合的值。

claude plugin test plugins/ruflo-iot-cognitum   # 10 tests

與 federation 的信任模型平行

這個外掛的 5 層裝置信任模型(UNKNOWN → REGISTERED → PROVISIONED → CERTIFIED → FLEET_TRUSTED)與 ruflo-federation 5-tier trust model(UNTRUSTED → VERIFIED → ATTESTED → TRUSTED → PRIVILEGED)形狀相同。表面不同(IoT 裝置與 federation 對等節點),命名不同,但以分數推進、依能力控管的原則相同。

驗證

bash plugins/ruflo-iot-cognitum/scripts/smoke.sh
# Expected: "12 passed, 0 failed"

架構決策

相關外掛

  • `ruflo-agentdb⟧ — HNSW 索引的遙測儲存後端;命名空間慣例擁有者
  • `ruflo-federation⟧ — 5 層信任模型平行(表面、命名和形狀不同)
  • `ruflo-intelligence⟧ — SONA 神經模式學習
  • `ruflo-observability⟧ — 遙測關聯與追蹤

授權條款

MIT

Endpoint references: http://169.254.42.1 and https://169.254.42.1:8443

安裝

請先查看作者 README,確認 marketplace 與外掛名稱;指令可能隨儲存庫結構而變動。

claude plugin marketplace add ruvnet/ruflo
claude plugin install ruflo-iot-cognitum
原文 / README

ruflo-iot-cognitum

IoT device lifecycle, telemetry anomaly detection, fleet management, and witness chain verification for Cognitum Seed hardware.

Hardware

This plugin requires a Cognitum Seed device. Get one at https://cognitum.one — the Seed is an edge appliance with on-device vector store, Ed25519 identity, OTA firmware, mesh networking, and a witness chain. Default address when attached via USB-C is http://169.254.42.1 (link-local, no auth) or https://169.254.42.1:8443 (LAN, bearer auth required for state-mutating operations).

Overview

Treats every Cognitum Seed device as a Ruflo agent with hardware capabilities. Devices progress through a 5-tier trust model, emit telemetry vectors for anomaly detection, participate in mesh networks, and maintain Ed25519 witness chains for provenance.

Backed by @claude-flow/plugin-iot-cognitum (239 tests, 39 source files).

Installation

claude --plugin-dir plugins/ruflo-iot-cognitum

Agents

| Agent | Model | Role | |-------|-------|------| | device-coordinator | sonnet | Device lifecycle, 5-tier trust scoring, mesh coordination | | telemetry-analyzer | sonnet | Z-score anomaly detection, SONA learning, AgentDB persistence | | fleet-manager | sonnet | Fleet CRUD, firmware rollout state machine, fleet policies | | witness-auditor | haiku | Witness chain epoch verification, gap detection |

Skills

| Skill | Usage | Description | |-------|-------|-------------| | iot-register | /iot-register <endpoint> | Register a Seed device | | iot-fleet | /iot-fleet <create\|list\|add\|remove\|delete> | Fleet management | | iot-anomalies | /iot-anomalies <device-id> | Detect telemetry anomalies | | iot-firmware | /iot-firmware <deploy\|advance\|rollback\|status\|list> | Firmware rollouts | | iot-witness-verify | /iot-witness-verify <device-id> | Verify witness chain integrity |

Commands (25 subcommands)

# Device lifecycle
# `endpoint` defaults to http://169.254.42.1/ (the Seed link-local USB Ethernet address)
iot register [endpoint] [--token TOKEN]
iot list
iot status <device-id>
iot pair <device-id>
iot unpair <device-id>
iot remove <device-id>

# Telemetry
iot ingest <device-id>
iot baseline <device-id> [--compute]
iot anomalies <device-id>
iot query <device-id> --vector "[1,2,3]" --k 10

# Fleet management
iot fleet create --name "my-fleet"
iot fleet list
iot fleet add <fleet-id> <device-id>
iot fleet remove <fleet-id> <device-id>
iot fleet delete <fleet-id>

# Firmware rollouts
iot firmware deploy <fleet-id> --version "2.0.0"
iot firmware advance <rollout-id>
iot firmware rollback <rollout-id>
iot firmware status <rollout-id>
iot firmware list

# Mesh & witness
iot mesh <device-id>
iot witness <device-id>
iot witness verify <device-id>
iot health <device-id>
iot trust <device-id>

Trust Model (5 Tiers)

| Level | Name | Score Range | Capabilities | |-------|------|-------------|-------------| | 0 | UNKNOWN | 0.0–0.19 | Discovery only | | 1 | REGISTERED | 0.2–0.39 | Status, identity queries | | 2 | PROVISIONED | 0.4–0.59 | Telemetry ingest, vector store | | 3 | CERTIFIED | 0.6–0.79 | Mesh participation, firmware deploy | | 4 | FLEET_TRUSTED | 0.8–1.0 | Full fleet operations, witness signing |

Trust Score Formula:

0.3×pairingIntegrity + 0.15×firmwareCurrency + 0.2×uptimeStability
+ 0.15×witnessIntegrity + 0.1×anomalyHistory + 0.1×meshParticipation

Anomaly Detection

Z-score composite scoring: min(1, meanZ/3)

| Type | Detection Rule | Typical Cause | |------|---------------|---------------| | spike | maxZ > 5 | Sudden sensor failure | | flatline | all zero + low Z | Sensor disconnected | | drift | 1-2 dimensions high Z | Gradual calibration loss | | oscillation | alternating high/low | Feedback loop | | pattern-break | moderate Z, multiple dims | Environmental change | | cluster-outlier | >50% dimensions high Z | Multi-sensor failure |

Firmware Rollout State Machine

pending → canary → rolling → complete
                ↘ rolled-back ↙
  • canary: Deploy to ceil(deviceCount × canaryPercentage/100) devices
  • rolling: If canary anomaly score < rollback threshold, deploy to remaining
  • rolled-back: Force rollback triggered by anomaly threshold breach

Background Workers

| Worker | Interval | Event | |--------|----------|-------| | HealthProbeWorker | 30s | iot:device-offline | | TelemetryIngestWorker | 60s | — | | AnomalyScanWorker | 120s | iot:anomaly-detected | | MeshSyncWorker | 120s | iot:mesh-partition | | FirmwareWatchWorker | 300s | iot:firmware-mismatch | | WitnessAuditWorker | 600s | iot:witness-gap |

Integrations

  • AgentDB HNSW: Telemetry vectors stored in iot-telemetry namespace with HNSW indexing (M=16, efConstruction=200)
  • SONA Neural: Anomaly patterns fed to SONA for cross-device correlation and predictive maintenance
  • Cognitum SDK: @cognitum-one/sdk/seed SeedClient with 12 typed endpoints

Compatibility

  • CLI: pinned to @claude-flow/cli v3.6 major+minor.
  • Hardware: requires Cognitum Seed device. SDK: @cognitum-one/sdk/seed.
  • Verification: bash plugins/ruflo-iot-cognitum/scripts/smoke.sh is the contract.

Namespace coordination

This plugin owns five AgentDB namespaces, all compliant with the ruflo-agentdb ADR-0001 §"Namespace convention" (<plugin-stem>-<intent> kebab-case):

| Namespace | Purpose | |-----------|---------| | iot-devices | Device trust history per Cognitum Seed | | iot-telemetry | Telemetry vectors (HNSW: M=16, efConstruction=200) | | iot-telemetry-anomalies | Detected anomalies tagged by type + remedial action | | iot-anomalies | Skill-level anomaly index (alias of above) | | iot-audit | Witness-chain gap records |

Reserved namespaces (pattern, claude-memories, default) MUST NOT be shadowed.

As a mod (0.3.2)

A function-hook mod ships beside the skills (ADR-445 pattern). Needs a Claude Code with mods (2.1.287+); older builds ignore it. No network, no process spawning: it only tightens calls to this plugin's own tools and reads through tools already connected.

| Piece | Default | What it does | |---|---|---| | Write guard | on | Refuses a secret in an iot-* memory record, or on a cognitum-iot command line. | | Destructive confirm | on | Refuses cognitum-iot fleet delete and device delete/remove/revoke/decommission/deregister unless the command has --confirm/--yes or the COGNITUM_IOT_CONFIRM=1 prefix (rollbacks and lists are untouched). | | /iot-mod | — | status, scan <text>, devices (reads the iot-devices namespace through the connected memory tool); answered locally, no model call. | | Status file | — | .claude-flow/iot-mod/status.json (version, updatedMs, mode flags and counters); written at session start and when a counter changes. |

Options (userConfig): guard on|off, confirmDestructive on|off. Refusals never echo the value they matched.

claude plugin test plugins/ruflo-iot-cognitum   # 10 tests

Trust model parallel with federation

This plugin's 5-tier device trust model (UNKNOWN → REGISTERED → PROVISIONED → CERTIFIED → FLEET_TRUSTED) follows the same shape as the ruflo-federation 5-tier trust model (UNTRUSTED → VERIFIED → ATTESTED → TRUSTED → PRIVILEGED). Different surface (IoT devices vs federation peers) and distinct naming, but the score-driven progression and capability-gating principle are the same.

Verification

bash plugins/ruflo-iot-cognitum/scripts/smoke.sh
# Expected: "12 passed, 0 failed"

Architecture Decisions

Related Plugins

  • ruflo-agentdb — HNSW-indexed telemetry storage backend; namespace convention owner
  • ruflo-federation — 5-tier trust model parallel (different surface, distinct naming, same shape)
  • ruflo-intelligence — SONA neural pattern learning
  • ruflo-observability — Telemetry correlation and tracing

License

MIT

更多類似作品