Claude Code

Plugin marketplaces and distribution

Official, community, and internal marketplaces, version constraints, recommendations, security plugins, governance, and caching.

Plugins package skills, agents, hooks, MCP, LSP, and executables for reuse. A marketplace handles discovery, installation, versioning, and governance. For package structure, see Plugins and skills.

#Marketplace model

ConceptMeaning
MarketplaceCatalog of plugins
PluginInstalled extension package
SourceLocal path, repository, or relative catalog path
ScopeUser/project/local installation
ReloadApply changes with /reload-plugins

First add a marketplace, then install selected plugins. Adding the catalog does not install everything.

#Official, community, and internal catalogs

CatalogCharacterRecommendation
claude-plugins-officialOfficial curated catalog, usually availableStill inspect plugin contents
claude-communityCommunity catalog with automated validation/screeningReview before enterprise approval
Demo catalogExamplesLearn from it rather than depending blindly in production
Internal catalogCompany-maintainedStandard team workflows

Install an official plugin:

/plugin install github@claude-plugins-official

Update the catalog:

/plugin marketplace update claude-plugins-official

Add the community catalog:

/plugin marketplace add anthropics/claude-plugins-community

#Plugin categories

CategoryExamplesValue
Code intelligenceTypeScript/Python/Go/Rust LSPDiagnostics, definitions, references
IntegrationsGitHub/GitLab/Sentry/Slack/Linear/FigmaPackaged connections
Securitysecurity-guidanceEdit/turn/commit checks
WorkflowsCommit, PR review, SDK/plugin developmentRepeatable procedures
Output stylesExplanatory/LearningPresentation and teaching

LSP plugins commonly need a local language-server binary. If the Errors tab reports executable not found, install that binary.

#Create an internal catalog

company-marketplace/
├── .claude-plugin/
│   └── marketplace.json
└── plugins/
    └── quality-review-plugin/
        ├── .claude-plugin/
        │   └── plugin.json
        └── skills/
            └── quality-review/
                └── SKILL.md

Marketplace manifest:

{
  "name": "company-tools",
  "owner": {
    "name": "DevTools Team",
    "email": "[email protected]"
  },
  "plugins": [
    {
      "name": "quality-review-plugin",
      "source": "./plugins/quality-review-plugin",
      "description": "Review code for bugs, security, and performance",
      "version": "1.0.0"
    }
  ]
}

Install:

/plugin marketplace add ./company-marketplace
/plugin install quality-review-plugin@company-tools

Plugins are copied into an installation cache. Do not depend on paths outside the package such as ../shared-utils; those files are not automatically included.

#Versions and dependencies

MechanismPurpose
Plugin versionUpdate identity
Git commit sourceCommits can act as versions when no version is specified
Dependency constraintsCompatible dependency ranges
Managed marketplaceRestrict allowed sources
Lock/pinned commitReproducibility

Constrain plugin dependencies so upstream breaking changes do not unexpectedly alter team workflows.

#Recommendations

SignalUse
Pathsgo.mod, package.json, terraform directories
LanguageRelevant intelligence/checking tools
Internal frameworkCompany plugins in matching repositories
CLI markerSuggest a related plugin

Recommendations do not force installation. Use enabledPlugins/managed settings for enforced deployment.

#Security guidance

LayerCostTrigger
Per-edit patternsNo model callAfter edits
End-of-turn reviewModel callReview diff after a turn
Commit/push reviewModel callAgent invokes commit/push through Bash
/plugin install security-guidance@claude-plugins-official
/reload-plugins

Project enablement:

{
  "enabledPlugins": {
    "security-guidance@claude-plugins-official": true
  }
}

Custom rules:

# .claude/claude-security-guidance.md

- Do not log customer_id or account_number at INFO level.
- Check the admin role before every /admin route.
- Use timing-safe token comparison.

Pattern rules:

patterns:
  - rule_name: internal_api_key
    substrings: ["sk_live_", "AKIA"]
    reminder: "Possible hard-coded credential; use the secret manager."

This supplements human review, SAST, and blocking hooks; it does not replace them.

#Enterprise governance

GoalApproach
Internal catalogs onlyManaged marketplace restrictions
Universal security pluginDistribute enabledPlugins
Restrict user MCPmanaged-mcp.json or strictPluginOnlyCustomization
Track provenanceInspect plugin list/configuration
Control context costReview tool/context cost before installing
Diagnose failuresPlugin Errors tab

Treat hooks and executables as software supply-chain code: review, pin, record changes, and restrict publication.

#Cache effects

ChangeEffect
Skill-only pluginAdds descriptions/commands; prefix may change
LSPAdds diagnostics, usually not large per-turn schemas
MCP pluginUpfront schemas can significantly alter prefix
ReloadNext turn applies changed definitions
Version updateChanged manifests/skills/tools can reduce reuse
Tool searchReduces large MCP-definition impact where supported

Monitor persistent cache-creation growth when many plugins are enabled.

#Official references

Support

Need help?

For setup, billing, or model issues, email us. Check the status page for uptime.

WeChat / QQ support is available at the bottom right.