From 008ba463f505d8d259249b8c0f9836834a2caa87 Mon Sep 17 00:00:00 2001 From: Steve Wilson Date: Mon, 28 Sep 2026 12:42:05 -0700 Subject: [PATCH] raffkin: the socxen entry becomes raffkin, pointing at the renamed repository (open-agent-ai-security/raffkin#261) Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_016Q9UohWfy2scPhr4pavhqd Signed-off-by: Steve Wilson --- .claude-plugin/marketplace.json | 6 +++--- README.md | 28 +++++++--------------------- scripts/validate_catalog.py | 2 +- 3 files changed, 11 insertions(+), 25 deletions(-) diff --git a/.claude-plugin/marketplace.json b/.claude-plugin/marketplace.json index a8862f2..74c5690 100644 --- a/.claude-plugin/marketplace.json +++ b/.claude-plugin/marketplace.json @@ -41,14 +41,14 @@ "category": "security" }, { - "name": "socxen", + "name": "raffkin", "source": { "source": "git-subdir", - "url": "https://github.com/open-agent-ai-security/socxen.git", + "url": "https://github.com/open-agent-ai-security/raffkin.git", "ref": "main", "path": "plugin" }, - "description": "socxen — agentic SOC analyst for Claude Code and OpenAI Codex. Triages Exabeam New-Scale alerts and cases end to end via the Exabeam MCP: gathers evidence, correlates activity, reaches a threat/false-positive verdict, and acts — containment recommended for human approval, and dismiss/close gated by the host agent's tool-approval rules.", + "description": "Raffkin — agentic SOC analyst for Claude Code and OpenAI Codex. Triages Exabeam New-Scale alerts and cases end to end via the Exabeam MCP: gathers evidence, correlates activity, reaches a threat/false-positive verdict, and acts — containment recommended for human approval, and dismiss/close gated by the host agent's tool-approval rules.", "license": "Apache-2.0", "keywords": [ "soc", diff --git a/README.md b/README.md index 996a1c9..a546dc1 100644 --- a/README.md +++ b/README.md @@ -19,22 +19,22 @@ Then install what you need: ```bash claude plugin install praxen@open-agent-ai-security -claude plugin install socxen@open-agent-ai-security +claude plugin install raffkin@open-agent-ai-security ``` | Plugin | What it does | Repo | |---|---|---| | **praxen** | Agent behavior verifier — compares an AI agent's declared policy (Worker Remit) against the available evidence and reports where observed behavior diverges from declared intent, scored against the RAISE framework and OWASP LLM/Agentic guidance. | [open-agent-ai-security/praxen](https://github.com/open-agent-ai-security/praxen) | -| **socxen** | Agentic SOC analyst — triages Exabeam New-Scale alerts and cases end to end via the Exabeam MCP, with governance gates and guardrails. | [open-agent-ai-security/socxen](https://github.com/open-agent-ai-security/socxen) | +| **raffkin** | Agentic SOC analyst — triages Exabeam New-Scale alerts and cases end to end via the Exabeam MCP, with governance gates and guardrails. | [open-agent-ai-security/raffkin](https://github.com/open-agent-ai-security/raffkin) | The in-session equivalents (`/plugin marketplace add …`, `/plugin install …`) do the same thing; run `/reload-plugins` (or restart the session) after an in-session install. ## Migrating from an older install path -Both plugins were previously distributed from marketplaces hosted in their own repos. -The marketplace name (`open-agent-ai-security`) and the plugin keys are unchanged, so -migration is one command and nothing about your installed plugins is lost. +Praxen was previously distributed from a marketplace hosted in its own repo. The +marketplace name (`open-agent-ai-security`) and the plugin key are unchanged, so migration +is one command and nothing about your installed plugin is lost. **Praxen users** — if you added the marketplace from `open-agent-ai-security/praxen`, just add this one; the same-named marketplace is re-pointed in place and your installed @@ -47,21 +47,7 @@ claude plugin marketplace add open-agent-ai-security/plugins Do **not** run `claude plugin marketplace remove` first — removing a marketplace uninstalls the plugins that came from it, and it isn't necessary. Migrating is optional for praxen (the legacy repo still publishes a praxen-only marketplace) but **required to -install socxen**, which only this catalog publishes. - -**socxen users** — if you installed the plugin as `socxen@socxen`, remove that marketplace -first. It has a *different* name from this one, so simply adding this catalog would leave you -with two enabled copies of socxen (the current release and the retired one), both registering -the `soc-investigate` skill: - -```bash -claude plugin marketplace remove socxen # also uninstalls socxen@socxen -claude plugin marketplace add open-agent-ai-security/plugins # re-points in place if already present -claude plugin install socxen@open-agent-ai-security -``` - -A separate `claude plugin uninstall socxen@socxen` isn't needed — removing the marketplace -uninstalls its plugins, which is the point here. +install raffkin**, which only this catalog publishes. ## OpenAI Codex @@ -89,7 +75,7 @@ codex plugin list praxen's CI and the legacy install path. A one-way drift check (`marketplace-sync.yml` + `check_marketplace_mirror.py`, currently on praxen's `dev` and reaching `main` with the 1.2 release) compares praxen's entry against this index; there - is no check in this repo, and nothing checks the socxen entry. + is no check in this repo, and nothing checks the raffkin entry. - `main` is protected, and the protection is enforced: every change lands by PR with one approving review, **review from a code owner is required** (`.github/CODEOWNERS` covers the manifest, `scripts/` and `.github/` — the three places that decide what installs and diff --git a/scripts/validate_catalog.py b/scripts/validate_catalog.py index 690da71..bff8391 100755 --- a/scripts/validate_catalog.py +++ b/scripts/validate_catalog.py @@ -13,7 +13,7 @@ `https://github.com/open-agent-ai-security/../attacker/repo.git`, which git silently normalizes to another org); - source type is 'url' (whole repo) or 'git-subdir' (a subdirectory of the - repo — used when a plugin ships only part of its repo, e.g. socxen#66's + repo — used when a plugin ships only part of its repo, e.g. raffkin#66's plugin/ payload split). 'git-subdir' additionally requires `path`: a strictly relative, traversal-free directory path — segments of [A-Za-z0-9._-] only, no leading/trailing '/', no '.' or '..' segments,