# workflow_execute

Execute a workflow Use when native TodoWrite + sequential Bash is wrong because the work has a real dependency graph that needs persistence, retry policy, pause/resume, and step-output binding across LLM-driven steps. For a single linear todo list, native TodoWrite is fine.

Agent View of the PolicyLayer registry record for `workflow_execute`. HTML page: https://policylayer.com/tools/io-github-ruvnet-claude-flow/workflow-execute

## Facts

- Tool: `workflow_execute`
- Server: Claude Flow (`claude-flow`) — https://policylayer.com/tools/io-github-ruvnet-claude-flow.md
- Install: `npx -y claude-flow`
- Homepage: https://github.com/ruvnet/claude-flow
- Risk category: Execute (High risk)
- Registry record: grade F, identity unverified
- Server rate-limited: no
- Parameters: 0
- Recommended policy verdict: Rate-limited

## Example call (MCP tools/call, JSON-RPC 2.0)

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "workflow_execute",
    "arguments": {}
  }
}
```

## Why workflow_execute is rated High

The tool executes workflows with dependency graphs and LLM-driven steps, which is a form of code execution. While the tool itself doesn't delete data, it runs external operations that could have side effects depending on what workflow is submitted. This qualifies as Execute rather than Write (which would be for data creation/modification) or Destructive (no mention of irreversible data deletion).

From the tool's own definition: "Tool name 'workflow_execute' and description states 'Execute a workflow' with features like 'step-output binding across LLM-driven steps', 'retry policy', and 'pause/resume'."

## Use case

AI agents invoke workflow_execute to trigger actions in Claude Flow. What it does depends on the arguments the agent supplies, and its effects often reach beyond the immediate call: builds kicked off, notifications sent, workflows started.

## Recommended policy (PolicyLayer)

Verdict: **Rate-limited**. Enforced by the PolicyLayer MCP gateway (https://policylayer.com/mcp-gateway) before a call reaches Claude Flow:

```json
{
  "version": "1",
  "default": "deny",
  "tools": {
    "workflow_execute": {
      "limits": [
        {
          "counter": "workflow_execute_rate",
          "window": "minute",
          "max": 10,
          "scope": "grant"
        }
      ]
    }
  }
}
```

## Other tools on Claude Flow (495)

- `agent_terminate` — Destructive — https://policylayer.com/tools/io-github-ruvnet-claude-flow/agent-terminate.md
- `agentdb_batch` — Destructive — https://policylayer.com/tools/io-github-ruvnet-claude-flow/agentdb-batch.md
- `agentdb_causal-edge-delete` — Destructive — https://policylayer.com/tools/io-github-ruvnet-claude-flow/agentdb-causal-edge-delete.md
- `agentdb_causal-node-delete` — Destructive — https://policylayer.com/tools/io-github-ruvnet-claude-flow/agentdb-causal-node-delete.md
- `agentdb_hierarchical-delete` — Destructive — https://policylayer.com/tools/io-github-ruvnet-claude-flow/agentdb-hierarchical-delete.md
- `agenticow_rollback` — Destructive — https://policylayer.com/tools/io-github-ruvnet-claude-flow/agenticow-rollback.md
- `autopilot_reset` — Destructive — https://policylayer.com/tools/io-github-ruvnet-claude-flow/autopilot-reset.md
- `config_reset` — Destructive — https://policylayer.com/tools/io-github-ruvnet-claude-flow/config-reset.md
- `federation_wg_keyrotate` — Destructive — https://policylayer.com/tools/io-github-ruvnet-claude-flow/federation-wg-keyrotate.md
- `hooks_codemod` — Destructive — https://policylayer.com/tools/io-github-ruvnet-claude-flow/hooks-codemod.md
- `hooks_intelligence-reset` — Destructive — https://policylayer.com/tools/io-github-ruvnet-claude-flow/hooks-intelligence-reset.md
- `hooks_worker-cancel` — Destructive — https://policylayer.com/tools/io-github-ruvnet-claude-flow/hooks-worker-cancel.md
- `iot_device_remove` — Destructive — https://policylayer.com/tools/io-github-ruvnet-claude-flow/iot-device-remove.md
- `iot_firmware_rollout_rollback` — Destructive — https://policylayer.com/tools/io-github-ruvnet-claude-flow/iot-firmware-rollout-rollback.md
- `iot_fleet_delete` — Destructive — https://policylayer.com/tools/io-github-ruvnet-claude-flow/iot-fleet-delete.md
- `iot_fleet_remove_device` — Destructive — https://policylayer.com/tools/io-github-ruvnet-claude-flow/iot-fleet-remove-device.md
- `managed_agent_terminate` — Destructive — https://policylayer.com/tools/io-github-ruvnet-claude-flow/managed-agent-terminate.md
- `memory_delete` — Destructive — https://policylayer.com/tools/io-github-ruvnet-claude-flow/memory-delete.md
- `policy_revoke` — Destructive — https://policylayer.com/tools/io-github-ruvnet-claude-flow/policy-revoke.md
- `ruvector_delete` — Destructive — https://policylayer.com/tools/io-github-ruvnet-claude-flow/ruvector-delete.md
- `session_delete` — Destructive — https://policylayer.com/tools/io-github-ruvnet-claude-flow/session-delete.md
- `system_reset` — Destructive — https://policylayer.com/tools/io-github-ruvnet-claude-flow/system-reset.md
- `task_cancel` — Destructive — https://policylayer.com/tools/io-github-ruvnet-claude-flow/task-cancel.md
- `teammate_cleanup` — Destructive — https://policylayer.com/tools/io-github-ruvnet-claude-flow/teammate-cleanup.md
- `wasm_agent_reset` — Destructive — https://policylayer.com/tools/io-github-ruvnet-claude-flow/wasm-agent-reset.md
- `wasm_gallery_remove_custom` — Destructive — https://policylayer.com/tools/io-github-ruvnet-claude-flow/wasm-gallery-remove-custom.md
- `workflow_cancel` — Destructive — https://policylayer.com/tools/io-github-ruvnet-claude-flow/workflow-cancel.md
- `workflow_delete` — Destructive — https://policylayer.com/tools/io-github-ruvnet-claude-flow/workflow-delete.md
- `agent_pool` — Execute — https://policylayer.com/tools/io-github-ruvnet-claude-flow/agent-pool.md
- `agent_spawn` — Execute — https://policylayer.com/tools/io-github-ruvnet-claude-flow/agent-spawn.md
- …and 465 more: https://policylayer.com/tools/io-github-ruvnet-claude-flow.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=io-github-ruvnet-claude-flow · API: https://policylayer.com/registry/api · Policy library: https://policylayer.com/policies/io-github-ruvnet-claude-flow
