chore(quality-sweep): T2/T5 — plugin audit clean; link stub issue

T2 (dead-code sweep — plugins):
- All 34 plugin dirs scanned. No duplicate skill names, no dead scripts.
- All skill-referenced scripts (ruflo-core/witness/*, ruflo-cost-tracker/scripts/*,
  ruflo-adr/scripts/*) verified to exist.
- ruflo-graph-intelligence is a proper TS library package (not a skills plugin) —
  0 skill files is correct, not a gap.
- stray plugins/ruvector.db confirmed gitignored (not tracked).
- T2 closed.

T5 (mocked/placeholder claims):
- Add issue #2140 reference to coordination_orchestrate's _note field so the
  honest stub has a tracked follow-up path. The "executor: none" behavior is
  intentional per ADR-093 F7 but now has a concrete issue to track completion.

T10 (high vuln triage, completing the analysis):
- All 25 high severity packages traced:
  - vite: transitive from vitest (devDep) — not in production build
  - axios: transitive from agentic-flow (optional dep)
  - hono, fast-uri: transitive from agentdb (optional dep)
  - Most others: transitive from @opentelemetry/* (optional via agentdb) or
    @xenova/transformers (optional via @claude-flow/embeddings)
  - ruflo/package.json already overrides @hono/node-server, @isaacs/brace-expansion,
    flatted, tar, picomatch, path-to-regexp, undici, minimatch, cacache,
    make-fetch-happen, express-rate-limit
  - Remaining: agentdb/agentic-flow/vite/axios/sqlite3 all optional-only paths.
  No direct production dependency vulnerability is unaddressed.

Tests: 1999 passing | 46 skipped (unchanged).

Co-Authored-By: RuFlo <ruv@ruv.net>
This commit is contained in:
ruv
2026-05-25 21:29:34 -04:00
parent 38b55e77d3
commit ff685013a9
@@ -761,7 +761,7 @@ export const coordinationTools: MCPTool[] = [
topology: store.topology.type,
// Honest stub: no executor wired up yet. Don't lie about completion time.
executor: 'none',
_note: 'coordination_orchestrate currently records the orchestration request but does not execute it. For real multi-agent execution use agent_spawn + the Task tool, or hive-mind_spawn for queen-led coordination.',
_note: 'coordination_orchestrate currently records the orchestration request but does not execute it. For real multi-agent execution use agent_spawn + the Task tool, or hive-mind_spawn for queen-led coordination. Real executor tracked in issue #2140.',
};
},
},