ruflo-security-audit

PackSecurity

ruflo-security-audit is a plugin that adds security review to an agent's workflow. It scans a project's dependencies for known vulnerabilities, runs policy gates before changes go live, and monitors CVEs so issues surface early.

Unavailable. Delivery for this kind is on the roadmap — not serving yet.

Have a project with declared dependencies that the agent can read.

What your AI can do with it

  • Reviews code for security issues
  • Scans project dependencies for known vulnerabilities
  • Enforces security policy gates before changes go live
  • Monitors CVEs and flags relevant disclosures

Getting started

  1. Have a project with declared dependencies that the agent can read.
  2. Add the ruflo-security-audit plugin to the agent's configuration.
  3. Define the security policies you want enforced before changes go live.
  4. Run a security review through the agent to scan dependencies and check policy gates.

Signals

GitHub stars
73k
Forks
9k
Last commit
Sep 2026

Questions

What does the plugin scan?
It scans the project's dependencies for known vulnerabilities and monitors CVEs that may affect them.
When are policies enforced?
Policy gates run before changes go live, blocking changes that do not meet the configured security policies.
Advanced
Item type
plugin
Key
ruvnet-ruflo-ruflo-security-audit
Source
github.com/ruvnet/ruflo