Agent skill

Iot Witness Verify

by ruvnet in ruvnet/ruflo

Verify witness chain integrity and detect provenance gaps. An agent skill from ruvnet/ruflo.

MITAuto-check passed

Install Iot Witness Verify

skills CLI
$ npx skills add ruvnet/ruflo --skill iot-witness-verify -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ruvnet/ruflo iot-witness-verify --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ruvnet/ruflo.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/ruflo-iot-cognitum/skills/iot-witness-verify .claude/skills/iot-witness-verify && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
iot-witness-verify
GitHub stars
74k
Token cost
~160 tokens
SKILL.md length
53 words
Files
1
Skills in repo
265
Repo updated
First seen
Licence
MIT

At a glance

Verify witness chain integrity and detect provenance gaps. An agent skill from ruvnet/ruflo.

  • Works in 4 steps: npx -y -p… → Check for epoch gaps and hash chain breaks → Report integrity score (0.0–1.0) → …
  • Calls npx

What it does

Iot Witness Verify is an agent skill from ruvnet/ruflo. Verify witness chain integrity and detect provenance gaps

Its SKILL.md is about 160 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: 🌊 The original agent harness. Deploy intelligent multi-player swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory…. The licence is MIT.

Example prompts

  • “/iot-witness-verify”

Requirements

  • Node.js
  • Pre-approved tools (allowed-tools): Bash(npx *), mcp__plugin_ruflo-core_ruflo__memory_store, Read

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. npx -y -p @claude-flow/plugin-iot-cognitum@latest cognitum-iot witness verify DEVICE_ID
  2. Check for epoch gaps and hash chain breaks
  3. Report integrity score (0.0–1.0)
  4. If gaps found, store for audit trail

What it can do on your machine

Read from SKILL.md and the folder at commit 6c04654. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash(npx *)
    • mcp__plugin_ruflo-core_ruflo__memory_store
    • Read

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npx, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Iot Witness Verify loads about 160 tokens when it runs. Until then it costs about 19 tokens; SKILL.md has 53 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~19
When it runs · the whole SKILL.md, loaded when a task matches
~160

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ruvnet/ruflo at commit 6c04654, republished under its MIT licence (© ruvnet). 53 words, ~160 tokens.

Download SKILL.mdSave it as .claude/skills/iot-witness-verify/SKILL.md (or your agent's skills folder).
name
iot-witness-verify
description
Verify witness chain integrity and detect provenance gaps
allowed-tools
Bash(npx *), mcp__plugin_ruflo-core_ruflo__memory_store, Read
argument-hint
<device-id>

Verify the witness chain integrity for a Cognitum Seed device.

Steps:

  1. npx -y -p @claude-flow/plugin-iot-cognitum@latest cognitum-iot witness verify DEVICE_ID
  2. Check for epoch gaps and hash chain breaks
  3. Report integrity score (0.0–1.0)
  4. If gaps found, store for audit trail: mcp__plugin_ruflo-core_ruflo__memory_store({ key: "iot-witness-gap-DEVICEID", value: "Gap from EPOCH to EPOCH", namespace: "iot-audit" })

© ruvnet, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in plugins/ruflo-iot-cognitum/skills/iot-witness-verify of ruvnet/ruflo.

Open the folder on GitHubat commit 6c04654

Compare with similar skills

Iot Witness Verify next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Iot Witness Verify compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Iot Witness Verify this skillruvnet/ruflo74k—~160Automated safety check: PassMIT
Arduino Azure Iot Edge Integrationgithub/awesome-copilot40k1 repos~1.2kAutomated safety check: PassMIT
Detecting Supply Chain Attacks In CI CDmukul975/Anthropic-Cybersecurity-Skills34k—~655Automated safety check: PassApache-2.0
Agentic Supply Chain DetectionTencent/AI-Infra-Guard6.8k—~760Automated safety check: PassApache-2.0
API Integrationsickn33/agentic-awesome-skills47k1 repos~1.3kAutomated safety check: PassMIT
Supply Chain Securityzhaoxuya520/reverse-skill41k4 repos~953Automated safety check: WarnMIT

Similar skills

  • Official

    Design and implement Arduino integration with Azure IoT Hub and IoT Edge, including secure provisioning, resilient telemetry, command handling, and production guardrails.

    40k GitHub starsUsed in 1 repo~1.2k tokens
    DevelopmentAuto-check passed
  • Detecting Supply Chain Attacks In CI CD

    mukul975/Anthropic-Cybersecurity-Skills

    Scans GitHub Actions workflows and CI/CD pipeline configurations for supply chain attack vectors including unpinned actions, script injection via expressions, dependency confusion, and secrets…

    34k GitHub stars~655 tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Agentic Supply Chain Detection

    Tencent/AI-Infra-Guard

    Probes an AI agent for supply-chain weaknesses: whether it loads untrusted plugins, tools or models, updates dependencies without pinning, or trusts user-supplied artifacts.

    6.8k GitHub stars~760 tokensUpdated 2 days ago
    SecurityAuto-check passed
  • API Integration

    sickn33/agentic-awesome-skills

    Designs event-driven architectures, webhook systems, API chaining flows, ETL pipelines, and integration patterns between services.

    47k GitHub starsUsed in 1 repo~1.3k tokens
    Backend & APIsAuto-check passed
  • Supply Chain Security

    zhaoxuya520/reverse-skill

    A skill your agent uses for software supply-chain security assessment covering SBOM, SCA, CI/CD pipelines, container images, build integrity, dependency provenance, and vulnerability reachability.

    41k GitHub starsUsed in 4 repos~953 tokens
    SecurityAuto-check: warnings
  • Implementing File Integrity Monitoring With Aide

    mukul975/Anthropic-Cybersecurity-Skills

    Configures AIDE (Advanced Intrusion Detection Environment) for file integrity monitoring on Linux, covering baseline database creation, scheduled integrity checks via cron, change detection, and…

    34k GitHub stars~642 tokensUpdated 1 mo ago
    SecurityAuto-check: notes

More from ruvnet/ruflo

All 265 skills in this repo
  • Stores, searches, and retrieves successful patterns with HNSW-indexed semantic search so agents can reuse past solutions instead of relearning them.

    74k GitHub starsUsed in 1 repo~830 tokens
    Auto-check passed
  • Sets up and drives Ruflo, an npm-installed orchestration layer for multi-agent swarms, persistent memory, routing, hooks and its MCP tool catalog.

    74k GitHub starsUsed in 1 repo~975 tokens
    Auto-check passed
  • Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.

    74k GitHub starsUsed in 1 repo~823 tokens
    Auto-check passed
  • Applies the SPARC method (specification, pseudocode, architecture, refinement, completion) with 17 specialized modes and multi-agent orchestration, from research to deployment.

    74k GitHub starsUsed in 1 repo~829 tokens
    Auto-check passed
  • Coordinates a hierarchical swarm of specialized agents through the claude-flow CLI for work that spans several files or modules at once.

    74k GitHub starsUsed in 1 repo~779 tokens
    Auto-check passed
  • Finds models on the Hugging Face router that lack descriptions in chat-ui's prod.yaml and dev.yaml, researches each one and adds short descriptions.

    74k GitHub starsUsed in 1 repo~600 tokens
    Auto-check passed

Questions about Iot Witness Verify

What does Iot Witness Verify do?

Verify witness chain integrity and detect provenance gaps. An agent skill from ruvnet/ruflo. Iot Witness Verify is an agent skill from ruvnet/ruflo.

How do I install Iot Witness Verify in Claude Code?

Run `npx skills add ruvnet/ruflo --skill iot-witness-verify -a claude-code`. Or copy the skill folder (plugins/ruflo-iot-cognitum/skills/iot-witness-verify in ruvnet/ruflo) into .claude/skills/iot-witness-verify in your project. Claude Code loads it when a task matches its description.

How do I install Iot Witness Verify in Codex?

Run `npx skills add ruvnet/ruflo --skill iot-witness-verify -a codex`. Or copy the skill folder (plugins/ruflo-iot-cognitum/skills/iot-witness-verify in ruvnet/ruflo) into .agents/skills/iot-witness-verify in your project. Codex loads it when a task matches its description.

Can I use Iot Witness Verify in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ruvnet/ruflo --skill iot-witness-verify -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/iot-witness-verify, .gemini/skills/iot-witness-verify, .github/skills/iot-witness-verify and .opencode/skills/iot-witness-verify in your project.

What does Iot Witness Verify need to run?

Going by SKILL.md and its folder, Iot Witness Verify needs the command-line tools its instructions call (npx). Our summary lists: Node.js. Its frontmatter pre-approves these tools: Bash(npx *), mcp__plugin_ruflo-core_ruflo__memory_store, Read.

Does Iot Witness Verify access the network?

SKILL.md contains no URLs. Its commands use npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Iot Witness Verify safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Iot Witness Verify use?

Iot Witness Verify is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Iot Witness Verify use?

About 160 tokens (SKILL.md is roughly 640 characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Iot Witness Verify?

Skills that share tags, products or a category with Iot Witness Verify: Arduino Azure Iot Edge Integration (github/awesome-copilot, 40k stars), Detecting Supply Chain Attacks In CI CD (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Agentic Supply Chain Detection (Tencent/AI-Infra-Guard, 6.8k stars) and API Integration (sickn33/agentic-awesome-skills, 47k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Iot Witness Verify?

ruvnet (a GitHub user) maintains it in ruvnet/ruflo, which has 74,222 GitHub stars. The repository holds 265 skills in this directory. The repository was last updated on October 10, 2026.

Source: ruvnet/ruflo on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.