Claims

作者 ruvnet6051f6702b61無授權條款74K 個星標收錄於 2026年10月8日更新於 2026年10月8日儲存庫今天更新

Claims-based authorization for agents and operations. Grant, revoke, and verify permissions for secure multi-agent coordination. Use when: permission management, access control, secure operations, authorization checks. Skip when: open access, no security requirements, single-agent local work.

AI 產生的概覽

定義以宣告為基礎的代理授權,以及跨主機的工作宣告協調。

功能
此技能說明一套以宣告為基礎的代理權限模型,列出 read、write、execute、spawn、memory、network、admin 等宣告類型,以及 check、grant、revoke、list 指令與範圍模式。它也描述用來協調多個代理對任務或資源所有權的工作宣告,包含本機帳本工具與跨主機發布的聯邦宣告訊息。內容涵蓋安全層級、最佳實務,以及宣告串流的頻道隔離。
適用情境
適用於管理代理權限、存取控制或授權檢查,或在多個代理或主機之間協調共享任務與資源的所有權。它針對安全的多代理作業,而非開放存取或單一代理的本機工作。
執行需求
僅為說明文件,未附帶指令碼。所述指令依賴透過 npx 執行的外部 claude-flow 與 ruflo 命令列工具,聯邦宣告另需聯邦中繼與頻道設定。

Claims Authorization Skill

Purpose

Claims-based authorization for secure agent operations and access control.

Claim Types

ClaimDescription
readRead file access
writeWrite file access
executeCommand execution
spawnAgent spawning
memoryMemory access
networkNetwork access
adminAdministrative operations

Commands

Check Claim

bash
npx claude-flow claims check --agent agent-123 --claim write

Grant Claim

bash
npx claude-flow claims grant --agent agent-123 --claim write --scope "/src/**"

Revoke Claim

bash
npx claude-flow claims revoke --agent agent-123 --claim write

List Claims

bash
npx claude-flow claims list --agent agent-123

Scope Patterns

PatternDescription
*All resources
/src/**All files in src
/config/*.tomlTOML files in config
memory:patternsPatterns namespace

Security Levels

LevelClaims
minimalread only
standardread, write, execute
elevated+ spawn, memory
adminall claims

Best Practices

  1. Follow principle of least privilege
  2. Scope claims to specific resources
  3. Audit claim usage regularly
  4. Revoke claims when no longer needed

Cross-Host Work Claims (federation, v3.40.0+)

Distinct from the authorization claims above: work claims coordinate ownership of a task or resource across agents, and now propagate across a cross-host federation so a claim made on one node is visible to the whole swarm.

Runtime tools (local ledger)

ToolPurpose
claims_claimTake ownership of an issue/resource (with optional TTL).
claims_releaseGive up a claim you hold.
claims_handoff / claims_accept-handoffTransfer a claim to another agent.
claims_steal / claims_mark-stealableWork-stealing for stalled claims.
claims_status / claims_listInspect current ownership.

Federated (cross-host)

Publish claim events into a federation room (federation_bbs_publish) so ownership converges across hosts. Message types: ClaimIssued / ClaimReleased / ClaimHandoff / ClaimAck.

Rules: one owner per resourceId; first valid ClaimIssued wins (ties → earliest ts, then smallest from); ClaimReleased or expired TTL frees it; ClaimHandoff only from the current owner; a coordinator posts ClaimAck naming the authoritative owner.

Before shared work: claim, sync, and proceed only if you are the acknowledged owner. When a claim must be both cross-host visible and runtime-enforced, mirror the two — publish the federation claim message and call claims_claim. See the cross-host-federation skill (ruflo-bbs-federation plugin) for the transport.

Scoping a claim stream to a channel (ADR-386)

By default every claim event lands in the shared swarm stream, where any relay member reads it. To keep a team's ownership ledger separate — or unreadable by the rest of the relay — publish claim messages into a channel instead:

npx ruflo federation channel --action create --name platform-team --visibility privatenpx ruflo federation channel --action grant --channel prv:<hex> --pubkey <teammate 64-hex>npx ruflo federation channel --action publish --channel prv:<hex> \  --type ClaimIssued --payload '{"resourceId":"repo/foo","ttlSeconds":7200}'npx ruflo federation channel --action read --channel prv:<hex>

Reduction rules are unchanged; only the audience changes. Two caveats before relying on it: a private channel hides content but not metadata (the relay still sees who published and when), and a claim nobody outside the channel can read cannot arbitrate against a claim made outside it. If ownership must be swarm-wide, keep it on the open stream. See the open-federation skill for channel mechanics.

來源與署名

來源:ruvnet/ruflo位於.agents/skills/claims提交6051f67

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架