Plugin security and trust
What an installed Claude Code plugin can do on your machine, how to vet one before installing, and how to remove it cleanly if you change your mind.
Installing a plugin is closer to running npm install on a random package than to adding a browser bookmark. A plugin can execute arbitrary code on your machine with your user privileges. This page is the review routine I run before installing anything outside the official marketplace, and what Claude Code does on its side to protect you.
This is about vetting plugins. Claude Code's own security model is on /docs/security, organisation-wide controls are on /docs/plugins/org, and the security-guidance and claude-security plugins have their own pages at /docs/security-guidance and /docs/claude-security.
What a plugin can do
A plugin brings two kinds of thing: code that runs on your machine, and text that enters Claude's context as instructions. Both deserve scrutiny.
| Component | What it does | Covered by permissions and sandbox? |
|---|---|---|
| Hooks | Shell commands run at lifecycle points such as before or after a tool call | No: run with your full user permissions |
| Monitors | Background shell commands started at session start, on plugin reload, or the first time a named skill runs | No |
| Mods | JavaScript running inside Claude Code with your permissions | No, for the processes it starts |
| MCP servers | A stdio server is a process Claude Code launches; its tools are offered to Claude | Server process: no. Claude's calls to its tools: yes |
| LSP servers | Language server processes Claude Code launches | No |
bin/ directory | Added to the PATH of the Bash tool's shell, so Claude can run anything in it | Yes, because running it is a Bash tool call |
| Skills, commands, agents | Instructions in Claude's context that steer what it does with its existing tools | Indirectly: whatever Claude then does goes through permissions |
| Updates | With auto-update on, files change on disk in the background after you reviewed them | n/a |
The key point in that third column: permission rules and the sandbox govern Claude's tool calls. Hooks, monitors, MCP servers, LSP servers and processes started by a mod all run outside the sandbox. A malicious hook does not need Claude's cooperation.
Installing also enables, unless the manifest or marketplace entry sets defaultEnabled: false and you have not switched it on yourself.
Know which marketplaces are Anthropic's
Marketplace names fall into three tiers. Claude Code only accepts the official and community names for marketplaces sourced from github.com/anthropics/, so a stranger cannot call their repo claude-plugins-official and pass as Anthropic.
| Tier | Names |
|---|---|
| Official | claude-plugins-official, claude-code-marketplace, claude-code-plugins, anthropic-marketplace, anthropic-plugins, agent-skills, anthropic-agent-skills, life-sciences, knowledge-work-plugins, claude-for-legal, claude-for-financial-services, financial-services-plugins, first-party-plugins, claude-tag-plugins |
| Community | claude-community, claude-plugins-community, healthcare |
| Third-party | Anything else, including your employer's marketplace |
In the claude-community catalogue almost every entry is pinned to a commit SHA, and Claude Code refuses to install any other commit for those entries.
Remember that the tier tells you who curates the catalogue, not what each plugin does. Review the plugin regardless. More on the three Anthropic catalogues in /docs/plugins/anthropic-marketplaces.
Review a plugin before installing
My routine takes about five minutes for a typical plugin.
-
Where is the marketplace from? In your shell:
claude plugin marketplace listThis prints the source each marketplace was added from. If it is a GitHub repo you have never heard of, slow down.
-
What does the details pane say? Run
/plugin, select the plugin and read Will install: commands, agents, skills, hooks, MCP and LSP servers. When Anthropic has no published component data it shows what the marketplace entry declares, orComponents will be discovered at installation(plugin stored inside the marketplace) orComponent summary not available for remote plugin(fetched from elsewhere). -
Read the source. Use Open homepage or View on GitHub under the install options, or go to the marketplace repo from step 1. The pane tells you a hook exists, not what it runs, so read:
hooks/hooks.json: every hook command.mcp.json: each server's command or URLbin/: every file
-
Inventory it locally. Clone the repo and ask Claude Code to describe the plugin without starting a session:
git clone https://github.com/some-author/their-plugins /tmp/review claude --plugin-dir /tmp/review/plugins/their-tool plugin details their-toolThe output includes a
Component inventoryof skills and commands, agents, hooks with their events, and MCP and LSP servers.
After installing, claude plugin details <plugin> prints the same inventory for the installed copy under ~/.claude/plugins/cache/<marketplace>/<plugin>/<version>/. If a marketplace has auto-update on, re-run it occasionally: the files you reviewed can change.
Remove a plugin you no longer trust
claude plugin uninstall their-tool@their-marketplace --scope user
Use whichever --scope you installed at. Then check what was left behind:
- Persistent data: if that was the last scope it was installed at, the plugin's persistent data directory is deleted by default.
--keep-dataand other exceptions are in /docs/plugins/cli-reference. - Cached files: the plugin's files sit under
~/.claude/plugins/cache/for 14 days before a background sweep deletes them. If you uninstalled your last plugin, orphaned folders stay until you install another. To be thorough, delete~/.claude/plugins/cache/<marketplace>/<plugin>/yourself. - The marketplace: if you no longer trust the owner, remove the marketplace too. That uninstalls every plugin from it. See /docs/plugins/install.
Warnings and refusals you will see
The trust warning
Every plugin's details pane, opened from Discover or Marketplaces, shows the same notice regardless of source. It tells you to trust a plugin before installing, updating or using it, and that Anthropic does not control or verify the MCP servers, files or software inside plugins, nor guarantee they will not change. If your organisation sets pluginTrustMessage in managed settings, its text is appended.
Hard refusals
Claude Code refuses outright, rather than warning, in two cases:
- Untrusted marketplace source. A marketplace using an official or community name but sourced outside
github.com/anthropics/stops loading, along with plugins installed from it. Error:Marketplace is registered from an untrusted source. - Archive integrity failure. When a marketplace entry pins an
archivesource to asha256digest and the download does not match, the install is refused. Error:Plugin archive integrity check failed.
The sha256 archive pin is a different mechanism from the community catalogue's commit SHA pin, which chooses the git commit to check out. Both are explained further in /docs/errors and /docs/plugins/marketplace-reference.
Organisation controls
Administrators can use managed settings to:
- Allowlist or blocklist marketplace sources
- Force-enable plugins
- Disable the
--plugin-dirand--plugin-urlflags and theCLAUDE_CODE_PLUGIN_DIRSvariable - Restrict hooks to those from managed settings and force-enabled plugins
- Stop plugins from members' claude.ai accounts loading in Claude Code, via
syncClaudeAiPlugins
The exact keys and their limits are in /docs/plugins/org.
Plugins in telemetry
If you export Claude Code's OpenTelemetry events (/docs/monitoring-usage), tiers decide what names appear:
- Plugin loaded event: official-tier plugin and marketplace names appear as-is. Community and third-party ones report
plugin.nameandmarketplace.nameas the literalthird-party, unlessOTEL_LOG_TOOL_DETAILS=1is set.plugin.scopestill reports origin, for exampleorgfor managed-enabled plugins oruser-localfor other third-party ones. - Plugin installed event: for non-official plugins the name fields are omitted entirely unless
OTEL_LOG_TOOL_DETAILS=1. - Claude Code Analytics API: official and community plugins are reported by name; everything else is
third-party.