# ruflo - Doramagic AI Context Pack

> Purpose: pre-work context for the user's host AI. This pack does not prove that the project has been installed, run, or validated.

## Project

- canonical_name: `ruvnet/ruflo`
- capability: 🌊 The leading agent meta-harness for Claude. Deploy intelligent multi-agent swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory, self-learning swarm intelligence, RAG integration, and native Claude Code / Codex Integration
- expected_user_outcome: 🌊 The leading agent meta-harness for Claude. Deploy intelligent multi-agent swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory, self-learning swarm intelligence, RAG integration, and native Claude Code / Codex Integration

## Operating Boundaries

- Do not claim that the project has been installed, run, called through an API, or used on local files unless separate evidence proves it.
- Project facts must come from repo evidence, Claim Graph, or explicit source references.
- When a capability is not verified, mark it as unverified instead of completing it as fact.
- publish_status: `publishable`
- blocking_gaps: none

---

## Doramagic Context Augmentation

The following sections strengthen the repository context for a host AI. Human Manual data is a reading route, and pitfall notes become operating constraints.

## Human Manual Outline

Usage rule: this is only a reading route and salience signal, not factual authority. Concrete claims must still return to repo evidence or Claim Graph.

Host AI hard rules:
- Do not treat page titles, section order, summaries, or importance values as factual project evidence.
- When explaining the Human Manual outline, state that it is only a reading route or salience signal.
- Capability, installation, compatibility, runtime state, and risk claims must cite repo evidence, source paths, or Claim Graph.

- **Ruflo Overview and Core Architecture**: importance `high`
  - source_paths: README.md, package.json, bin/cli.js, v3/@claude-flow/cli/bin/cli.js, v3/@claude-flow/cli/src/index.ts
- **Memory, Learning, and Intelligence Subsystem**: importance `high`
  - source_paths: v3/@claude-flow/memory/src/index.ts, v3/@claude-flow/memory/src/hnsw-index.ts, v3/@claude-flow/memory/src/hybrid-backend.ts, v3/@claude-flow/memory/src/agentdb-backend.ts, v3/@claude-flow/memory/src/rvf-backend.ts
- **Multi-Agent Coordination, Federation, and Security**: importance `high`
  - source_paths: v3/@claude-flow/swarm/src/queen-coordinator.ts, v3/@claude-flow/swarm/src/unified-coordinator.ts, v3/@claude-flow/swarm/src/topology-manager.ts, v3/@claude-flow/swarm/src/consensus/raft.ts, v3/@claude-flow/swarm/src/consensus/byzantine.ts
- **Plugin Ecosystem and Operational Concerns**: importance `high`
  - source_paths: plugins/README.md, plugins/ruflo-core/README.md, plugins/ruflo-core/commands/witness.md, plugins/ruflo-core/skills/witness/SKILL.md, plugins/ruflo-metaharness/README.md

## Repo Inspection Evidence

- repo_clone_verified: true
- repo_inspection_verified: true
- repo_commit: `ec1a18799651130fa7c98361219a54c4672cfbdf`
- inspected_files: `README.md`, `package.json`, `pnpm-lock.yaml`, `docs/IMPROVEMENT-ROADMAP.md`, `docs/QUALITY-SWEEP.md`, `docs/STATUS.md`, `docs/TEAM-GATEWAY-CHECKLIST.md`, `docs/USERGUIDE.md`, `docs/_config.yml`, `docs/benchmarks/BEIR-MATRIX.md`, `docs/benchmarks/guidance-baseline.json`, `docs/benchmarks/guidance-phase-1.json`, `docs/benchmarks/guidance-quantization-m4.json`, `docs/benchmarks/guidance-retriever-scale-baseline-filtered.json`, `docs/benchmarks/guidance-retriever-scale-baseline.json`, `docs/benchmarks/guidance-retriever-scale-m4.json`, `docs/benchmarks/guidance-retriever-scale-phase-1.json`, `docs/benchmarks/guidance-retriever-scale-phase-3-m3.json`, `docs/benchmarks/guidance-retriever-scale-phase-3-m3v2-filtered.json`, `docs/benchmarks/guidance-retriever-scale-phase-3-m3v2.json`

Host AI hard rules:
- Without repo_clone_verified=true, do not claim that the source code has been read.
- Without repo_inspection_verified=true, do not write README, docs, or package-file conclusions as facts.
- Without quick_start_verified=true, do not claim that the Quick Start path has run successfully.

## Doramagic Pitfall Constraints

These rules come from Doramagic discovery, validation, or compilation findings. The host AI must treat them as operating constraints, not background notes.

### Constraint 1: Security or permission risk requires verification

- Trigger: Developers should check this security_permissions risk before relying on the project: ADR-153 — Integrate @metaharness/darwin (Darwin Mode) into ruflo
- Host AI rule: Before packaging this project, run the relevant install/config/quickstart check for: ADR-153 — Integrate @metaharness/darwin (Darwin Mode) into ruflo. Context: Observed when using node, macos
- Why it matters: Developers may expose sensitive permissions or credentials: ADR-153 — Integrate @metaharness/darwin (Darwin Mode) into ruflo
- Evidence: failure_mode_cluster:github_issue | https://github.com/ruvnet/ruflo/issues/2409
- Hard boundary: Do not present this pitfall as solved, verified, or ignorable unless later evidence explicitly closes it.

### Constraint 2: Security or permission risk requires verification

- Trigger: Developers should check this security_permissions risk before relying on the project: security cve subcommand is a stub — never returns CVE data (scan already does, via npm audit)
- Host AI rule: Before packaging this project, run the relevant install/config/quickstart check for: security cve subcommand is a stub — never returns CVE data (scan already does, via npm audit). Context: Observed when using node
- Why it matters: Developers may expose sensitive permissions or credentials: security cve subcommand is a stub — never returns CVE data (scan already does, via npm audit)
- Evidence: failure_mode_cluster:github_issue | https://github.com/ruvnet/ruflo/issues/2403
- Hard boundary: Do not present this pitfall as solved, verified, or ignorable unless later evidence explicitly closes it.

### Constraint 3: Security or permission risk requires verification

- Trigger: Project evidence flags a security or permission risk. Review the linked source before relying on this workflow.
- Host AI rule: Reproduce the official install and quickstart path in an isolated environment.
- Why it matters: May increase setup, validation, or first-run risk for the user.
- Evidence: community_evidence:github | https://github.com/ruvnet/ruflo/issues/2286
- Hard boundary: Do not present this pitfall as solved, verified, or ignorable unless later evidence explicitly closes it.

### Constraint 4: Security or permission risk requires verification

- Trigger: Project evidence flags a security or permission risk. Review the linked source before relying on this workflow.
- Host AI rule: Reproduce the official install and quickstart path in an isolated environment.
- Why it matters: May increase setup, validation, or first-run risk for the user.
- Evidence: community_evidence:github | https://github.com/ruvnet/ruflo/issues/2412
- Hard boundary: Do not present this pitfall as solved, verified, or ignorable unless later evidence explicitly closes it.

### Constraint 5: Security or permission risk requires verification

- Trigger: Project evidence flags a security or permission risk. Review the linked source before relying on this workflow.
- Host AI rule: Reproduce the official install and quickstart path in an isolated environment.
- Why it matters: May increase setup, validation, or first-run risk for the user.
- Evidence: community_evidence:github | https://github.com/ruvnet/ruflo/issues/2047
- Hard boundary: Do not present this pitfall as solved, verified, or ignorable unless later evidence explicitly closes it.

### Constraint 6: Security or permission risk requires verification

- Trigger: Project evidence flags a security or permission risk. Review the linked source before relying on this workflow.
- Host AI rule: Reproduce the official install and quickstart path in an isolated environment.
- Why it matters: May increase setup, validation, or first-run risk for the user.
- Evidence: community_evidence:github | https://github.com/ruvnet/ruflo/issues/2313
- Hard boundary: Do not present this pitfall as solved, verified, or ignorable unless later evidence explicitly closes it.

### Constraint 7: Installation risk requires verification

- Trigger: Developers should check this installation risk before relying on the project: [verification] HIGH: @claude-flow/cli@alpha --version hangs >60s on cold install (ONNX model download on every startup)
- Host AI rule: Before packaging this project, run the relevant install/config/quickstart check for: [verification] HIGH: @claude-flow/cli@alpha --version hangs >60s on cold install (ONNX model download on every startup). Context: Observed when using node, python, linux
- Why it matters: Developers may fail before the first successful local run: [verification] HIGH: @claude-flow/cli@alpha --version hangs >60s on cold install (ONNX model download on every startup)
- Evidence: failure_mode_cluster:github_issue | https://github.com/ruvnet/ruflo/issues/2286
- Hard boundary: Do not present this pitfall as solved, verified, or ignorable unless later evidence explicitly closes it.

### Constraint 8: Installation risk requires verification

- Trigger: Developers should check this installation risk before relying on the project: [verification] HIGH: Witness manifests report 95–99 missing build artifacts (dist/ absent)
- Host AI rule: Before packaging this project, run the relevant install/config/quickstart check for: [verification] HIGH: Witness manifests report 95–99 missing build artifacts (dist/ absent). Context: Observed when using node, python, windows, macos
- Why it matters: Developers may fail before the first successful local run: [verification] HIGH: Witness manifests report 95–99 missing build artifacts (dist/ absent)
- Evidence: failure_mode_cluster:github_issue | https://github.com/ruvnet/ruflo/issues/2391
- Hard boundary: Do not present this pitfall as solved, verified, or ignorable unless later evidence explicitly closes it.

### Constraint 9: Installation risk requires verification

- Trigger: Developers should check this installation risk before relying on the project: [verification] HIGH: witness manifests report missing=95 drift=2 on all three platforms
- Host AI rule: Before packaging this project, run the relevant install/config/quickstart check for: [verification] HIGH: witness manifests report missing=95 drift=2 on all three platforms. Context: Observed when using node, windows, macos, linux
- Why it matters: Developers may fail before the first successful local run: [verification] HIGH: witness manifests report missing=95 drift=2 on all three platforms
- Evidence: failure_mode_cluster:github_issue | https://github.com/ruvnet/ruflo/issues/2047
- Hard boundary: Do not present this pitfall as solved, verified, or ignorable unless later evidence explicitly closes it.

### Constraint 10: Installation risk requires verification

- Trigger: Developers should check this installation risk before relying on the project: memory_store emits 128-dim mock embeddings — AgentDB vectorBackend controller never enables
- Host AI rule: Before packaging this project, run the relevant install/config/quickstart check for: memory_store emits 128-dim mock embeddings — AgentDB vectorBackend controller never enables. Context: Observed when using node, linux
- Why it matters: Developers may fail before the first successful local run: memory_store emits 128-dim mock embeddings — AgentDB vectorBackend controller never enables
- Evidence: failure_mode_cluster:github_issue | https://github.com/ruvnet/ruflo/issues/2395
- Hard boundary: Do not present this pitfall as solved, verified, or ignorable unless later evidence explicitly closes it.
