4 min read

Claude Plugins Official: Anthropic's Claude Code Plugin Directory (GitHub, Scanned)

Anthropic's curated plugin directory for Claude Code, and the marketplace it ships with.

Claude Plugins Official logo
✅
Scan: safe. Nothing malicious. Know that several plugins run hooks automatically once installed, and that the external plugins are written by third parties, not Anthropic. Scanned Oct 8, 2026; the full report is below.

This is the plugin directory behind Claude Code's built-in marketplace. A plugin bundles slash commands, subagents, skills, hooks or MCP server settings into one installable package, and anything listed here can be installed with /plugin install name@claude-plugins-official or found under /plugin then Discover. The marketplace file lists about 315 entries, many of them pointing at their makers' own repositories.

The repository itself holds two groups. plugins/ has 40 plugins built and maintained by Anthropic: language servers for a dozen languages, code review, commit commands, feature development, a plugin and skill creator, security guidance, output styles and more. external_plugins/ holds 14 made by partners and the community, such as Asana, Linear, GitHub, GitLab, Firebase, Playwright, Discord and Telegram.

It has about 37,500 stars and is Apache-2.0 at the root, with each plugin pointing to its own licence. Anthropic's own README asks you to trust a plugin before installing it, since it cannot verify what third-party MCP servers and files do or whether they change.

Who it is for

Claude Code users looking for vetted plugins to add commands, agents, language servers or integrations, and plugin authors who want reference implementations to copy.

Getting started

1. In Claude Code, browse the directory

/plugin

2. Install a plugin by name

/plugin install {plugin-name}@claude-plugins-official

Both commands are typed inside Claude Code, not a shell. The marketplace is available by default, so there is nothing to add first; open /plugin and choose Discover to browse, or replace {plugin-name} with a folder name such as code-review.

Safety scan

We cloned anthropics/claude-plugins-official at commit f713a7c on Oct 8, 2026 and ran the checks described on the GitHub Tools page: credential patterns, decode-and-execute code, install-time scripts, committed binaries, risky CI workflows, every host the code talks to, known vulnerabilities in pinned dependencies, and project hygiene. A person read every hit. This is what we found.

  • No secrets and no committed binaries across 555 files and about 107,000 lines. The one pattern hit is a very long line in learning-output-style's session-start.sh, a hook that prints a long instruction string to set the output style; it is benign.
  • Several plugins ship hooks that run automatically once installed: hookify, claude-security, security-guidance, code-modernization, ralph-loop and the explanatory and learning output styles. That is how those plugins work, but it is worth knowing which ones act without being asked. ralph-loop's 205-line setup script uses no sudo and makes no network calls.
  • The 14 plugins in external_plugins/ are made by third parties. The repository carries a review prompt in .github/policy for checking submitted plugins for malicious behaviour, but Anthropic's own README still says to trust a plugin before installing it.
  • A second, skill-specific pass found nothing malicious. Its invisible-Unicode hits and hosts like evil.example sit in tests that deliberately feed hostile strings to the security plugins.
  • Nine workflows. Two use pull_request_target (close-external-prs and external-pr-scope-guard), but neither checks out code from the pull request; they only label or close outside submissions. The 4 third-party actions are pinned to commits. No lockfiles, so no dependency advisories; no security policy or Dependabot.

What the scanner counted

CheckResult
SecretsNone found.
Suspicious code1 pattern hit found and read; every one is listed under the raw findings.
Install-time code1 installer script
Committed binariesNone.
CI workflows9 workflows. 2 use pull_request_target, none check out the pull request head. 0 of 4 third-party actions pinned to a tag rather than a commit.
Network hosts16 distinct hosts referenced from source; most often evil.example, github.com, api.telegram.org, fonts.googleapis.com. No URLs to bare IP addresses.
Known vulnerabilitiesNo lockfile to check: dependencies are declared as ranges, so what gets installed is whatever is current on the day.
Project hygieneHas licence file. Missing security policy, automated dependency updates, CodeQL, contributing guide.
OpenSSF ScorecardNot scored: the project is not in Scorecard's weekly index.

The raw findings

Every hit the scanner wrote out, with a link to the exact line at the scanned commit. Secrets candidates are redacted.

Pattern hits (1)
WhereRuleMatch
plugins/learning-output-style/hooks-handlers/session-start.sh:10very-long-line3127 chars
Installer scripts (1)
Workflows worth a look

By the numbers

Stars37.5K
Forks4,225
Contributors41
Commits4,362
Open issues1,041
Open pull requests28
Releases0
Latest releasenone tagged
LicenceApache-2.0
Main languagePython
Project age10 months
Last pushOct 8, 2026
Tracked files555
Lines of code107.1K
Checkout size14 MB

Lines by language: Markdown 44.3K, Python 29.6K, TypeScript 14.4K, JSON 7,078, JavaScript 4,858, HTML 3,462.

Questions

Is Claude Plugins Official free?

The plugins cost nothing to install. The repository is Apache-2.0 at the root and each plugin points to its own licence. Using them needs Claude Code, which requires a paid Claude plan or API billing, and some external plugins connect to services with their own accounts and pricing.

Are all these plugins made by Anthropic?

No. The 40 in plugins/ are developed and maintained by Anthropic. The 14 in external_plugins/, and the many marketplace entries that point to other repositories, are made by partners and the community and approved through a submission form.

Do I need to add this marketplace?

No. It is Claude Code's default marketplace, so /plugin install name@claude-plugins-official works without a marketplace add step.


This post is part of GitHub Tools, where every repository is cloned and scanned before it is written up. The scan is a snapshot of one commit on one day; the repository has moved on since, so check it before you install.