Skip to content

Plugin security and trust

What an installed Claude Code plugin can do on your machine, how to vet one before installing, and how to remove it cleanly if you change your mind.

Installing a plugin is closer to running npm install on a random package than to adding a browser bookmark. A plugin can execute arbitrary code on your machine with your user privileges. This page is the review routine I run before installing anything outside the official marketplace, and what Claude Code does on its side to protect you.

This is about vetting plugins. Claude Code's own security model is on /docs/security, organisation-wide controls are on /docs/plugins/org, and the security-guidance and claude-security plugins have their own pages at /docs/security-guidance and /docs/claude-security.

What a plugin can do

A plugin brings two kinds of thing: code that runs on your machine, and text that enters Claude's context as instructions. Both deserve scrutiny.

ComponentWhat it doesCovered by permissions and sandbox?
HooksShell commands run at lifecycle points such as before or after a tool callNo: run with your full user permissions
MonitorsBackground shell commands started at session start, on plugin reload, or the first time a named skill runsNo
ModsJavaScript running inside Claude Code with your permissionsNo, for the processes it starts
MCP serversA stdio server is a process Claude Code launches; its tools are offered to ClaudeServer process: no. Claude's calls to its tools: yes
LSP serversLanguage server processes Claude Code launchesNo
bin/ directoryAdded to the PATH of the Bash tool's shell, so Claude can run anything in itYes, because running it is a Bash tool call
Skills, commands, agentsInstructions in Claude's context that steer what it does with its existing toolsIndirectly: whatever Claude then does goes through permissions
UpdatesWith auto-update on, files change on disk in the background after you reviewed themn/a

The key point in that third column: permission rules and the sandbox govern Claude's tool calls. Hooks, monitors, MCP servers, LSP servers and processes started by a mod all run outside the sandbox. A malicious hook does not need Claude's cooperation.

Installing also enables, unless the manifest or marketplace entry sets defaultEnabled: false and you have not switched it on yourself.

Know which marketplaces are Anthropic's

Marketplace names fall into three tiers. Claude Code only accepts the official and community names for marketplaces sourced from github.com/anthropics/, so a stranger cannot call their repo claude-plugins-official and pass as Anthropic.

TierNames
Officialclaude-plugins-official, claude-code-marketplace, claude-code-plugins, anthropic-marketplace, anthropic-plugins, agent-skills, anthropic-agent-skills, life-sciences, knowledge-work-plugins, claude-for-legal, claude-for-financial-services, financial-services-plugins, first-party-plugins, claude-tag-plugins
Communityclaude-community, claude-plugins-community, healthcare
Third-partyAnything else, including your employer's marketplace

In the claude-community catalogue almost every entry is pinned to a commit SHA, and Claude Code refuses to install any other commit for those entries.

Remember that the tier tells you who curates the catalogue, not what each plugin does. Review the plugin regardless. More on the three Anthropic catalogues in /docs/plugins/anthropic-marketplaces.

Review a plugin before installing

My routine takes about five minutes for a typical plugin.

  1. Where is the marketplace from? In your shell:

    claude plugin marketplace list
    

    This prints the source each marketplace was added from. If it is a GitHub repo you have never heard of, slow down.

  2. What does the details pane say? Run /plugin, select the plugin and read Will install: commands, agents, skills, hooks, MCP and LSP servers. When Anthropic has no published component data it shows what the marketplace entry declares, or Components will be discovered at installation (plugin stored inside the marketplace) or Component summary not available for remote plugin (fetched from elsewhere).

  3. Read the source. Use Open homepage or View on GitHub under the install options, or go to the marketplace repo from step 1. The pane tells you a hook exists, not what it runs, so read:

    • hooks/hooks.json: every hook command
    • .mcp.json: each server's command or URL
    • bin/: every file
  4. Inventory it locally. Clone the repo and ask Claude Code to describe the plugin without starting a session:

    git clone https://github.com/some-author/their-plugins /tmp/review
    claude --plugin-dir /tmp/review/plugins/their-tool plugin details their-tool
    

    The output includes a Component inventory of skills and commands, agents, hooks with their events, and MCP and LSP servers.

After installing, claude plugin details <plugin> prints the same inventory for the installed copy under ~/.claude/plugins/cache/<marketplace>/<plugin>/<version>/. If a marketplace has auto-update on, re-run it occasionally: the files you reviewed can change.

Remove a plugin you no longer trust

claude plugin uninstall their-tool@their-marketplace --scope user

Use whichever --scope you installed at. Then check what was left behind:

  • Persistent data: if that was the last scope it was installed at, the plugin's persistent data directory is deleted by default. --keep-data and other exceptions are in /docs/plugins/cli-reference.
  • Cached files: the plugin's files sit under ~/.claude/plugins/cache/ for 14 days before a background sweep deletes them. If you uninstalled your last plugin, orphaned folders stay until you install another. To be thorough, delete ~/.claude/plugins/cache/<marketplace>/<plugin>/ yourself.
  • The marketplace: if you no longer trust the owner, remove the marketplace too. That uninstalls every plugin from it. See /docs/plugins/install.

Warnings and refusals you will see

The trust warning

Every plugin's details pane, opened from Discover or Marketplaces, shows the same notice regardless of source. It tells you to trust a plugin before installing, updating or using it, and that Anthropic does not control or verify the MCP servers, files or software inside plugins, nor guarantee they will not change. If your organisation sets pluginTrustMessage in managed settings, its text is appended.

Hard refusals

Claude Code refuses outright, rather than warning, in two cases:

  • Untrusted marketplace source. A marketplace using an official or community name but sourced outside github.com/anthropics/ stops loading, along with plugins installed from it. Error: Marketplace is registered from an untrusted source.
  • Archive integrity failure. When a marketplace entry pins an archive source to a sha256 digest and the download does not match, the install is refused. Error: Plugin archive integrity check failed.

The sha256 archive pin is a different mechanism from the community catalogue's commit SHA pin, which chooses the git commit to check out. Both are explained further in /docs/errors and /docs/plugins/marketplace-reference.

Organisation controls

Administrators can use managed settings to:

  • Allowlist or blocklist marketplace sources
  • Force-enable plugins
  • Disable the --plugin-dir and --plugin-url flags and the CLAUDE_CODE_PLUGIN_DIRS variable
  • Restrict hooks to those from managed settings and force-enabled plugins
  • Stop plugins from members' claude.ai accounts loading in Claude Code, via syncClaudeAiPlugins

The exact keys and their limits are in /docs/plugins/org.

Plugins in telemetry

If you export Claude Code's OpenTelemetry events (/docs/monitoring-usage), tiers decide what names appear:

  • Plugin loaded event: official-tier plugin and marketplace names appear as-is. Community and third-party ones report plugin.name and marketplace.name as the literal third-party, unless OTEL_LOG_TOOL_DETAILS=1 is set. plugin.scope still reports origin, for example org for managed-enabled plugins or user-local for other third-party ones.
  • Plugin installed event: for non-official plugins the name fields are omitted entirely unless OTEL_LOG_TOOL_DETAILS=1.
  • Claude Code Analytics API: official and community plugins are reported by name; everything else is third-party.