raffkin: replace the socxen entry with Raffkin 1.0 - #11
Conversation
…pository (open-agent-ai-security/raffkin#261) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016Q9UohWfy2scPhr4pavhqd Signed-off-by: Steve Wilson <steve.wilson@exabeam.com>
virtualsteve-star
left a comment
There was a problem hiding this comment.
Reviewed. Approving for flip day. The sequencing is right and stated where a reader will see it: this is a draft, the new source URL resolves only after the socxen repository is renamed, and it needs 1.0.0 already on main because the entry is ref: main.
Checked rather than assumed:
- Only two
socxenstrings remain in the repo, both inpraxen-beta/CHANGELOG.md— history describing what happened at the time. Correct to leave, same reasoning as socxen#274's group 2. validate_catalog.pypasses: 3 plugins, and the validator enforces that each source ishttps://github.com/open-agent-ai-security/<name>.gitonmain. So the name/URL agreement here is checked, not merely conventional — araffkinentry pointing atsocxen.gitwould fail the gate.- Removing the
socxen@socxenmigration block is right: that marketplace was already retired, so the instructions were doubly dead.
One suggestion — the migration guidance that is now missing.
The section you removed covered socxen@socxen. Nobody is left on that path, so removing it is correct. But after this PR the README has nothing at all for someone who installed socxen@open-agent-ai-security — the current, supported path, and exactly the population this rename strands. Their plugin does not disappear; its catalog entry does, which is a more confusing state than an outright break.
I know the plan is to tell the few pre-release users directly, and for a handful of people that is the right primary channel. The README is the thing that outlives the direct note: it is where someone who installed in early September and comes back in three weeks will look, and where anyone who hears about the rename secondhand will land. Three lines would cover it:
socxen users — socxen was renamed to Raffkin at 1.0. Uninstall the old plugin, then install the new one; there is no in-place upgrade path.
claude plugin uninstall socxen@open-agent-ai-security claude plugin install raffkin@open-agent-ai-security
Worth saying in the same place what they will see if they do nothing, since socxen@open-agent-ai-security will still be installed and enabled against a catalog entry that no longer exists — that is the state people will actually arrive with.
Not blocking, and the call on how much to say is yours. Everything mechanical here is correct.
Draft. It lands on flip day, right after the socxen repository is renamed to
raffkinand 1.0.0 reaches itsmain. The new source URL resolves only after the rename.The rename is open-agent-ai-security/raffkin#261. There's no backward compatibility: the socxen entry is replaced, not kept as a deprecated pin. The few pre-release users are being told directly.
Changes
marketplace.json: the entry becomesraffkin. It's still agit-subdirsource,ref: main,path: plugin, but the URL is nowhttps://github.com/open-agent-ai-security/raffkin.git. The description leads with Raffkin.README.md:scripts/validate_catalog.py: a docstring example points at raffkin#66.validate_catalog.pypasses. The post-merge check on flip day: installraffkin@open-agent-ai-securityfresh on both hosts from the served catalog, confirmerrors[]is empty, run preflight, and drive a skill headlessly on staging.The Forge (
soc@exabeam) is handled separately.🤖 Generated with Claude Code
https://claude.ai/code/session_016Q9UohWfy2scPhr4pavhqd