# What Security Scans Are Performed on Claude Plugins? A Technical Breakdown

> Discover the five automated security scans Claude plugins undergo: static code analysis, credential exfiltration, network calls, dependency checks, and policy compliance. Learn more.

- Repository: [Anthropic/claude-plugins-community](https://github.com/anthropics/claude-plugins-community)
- Tags: security
- Published: 2026-08-30

---

**Claude plugins submitted to the community marketplace must pass five automated security scans—static code analysis, credential-exfiltration detection, external network-call detection, dependency-install checks, and policy compliance—enforced by the scan-plugins GitHub Action.**

The **anthropics/claude-plugins-community** repository implements a rigorous security framework to vet every plugin before it reaches end users. Understanding the **security scans performed on Claude plugins** helps developers prepare compliant submissions and helps users trust the code they install. Every plugin listed in the marketplace has cleared automated validation against Anthropic's Software Directory and Acceptable Use Policies.

## The scan-plugins GitHub Action Workflow

Security enforcement happens through a dedicated GitHub Action called **scan-plugins**, defined in [`.github/actions/scan-plugins/action.yml`](https://github.com/anthropics/claude-plugins-community/blob/main/.github/actions/scan-plugins/action.yml). When a developer submits a new plugin, this workflow triggers automatically and applies the security rubric stored in [`.github/actions/scan-plugins/policy/prompt.md`](https://github.com/anthropics/claude-plugins-community/blob/main/.github/actions/scan-plugins/policy/prompt.md). The action evaluates the submission against organizational policies and rejects the pull request if it detects violations.

## Five Critical Security Checks

The scan-plugins action performs distinct analyses to identify malicious patterns, unsafe configurations, and policy violations before code enters the marketplace.

### Static Code Analysis

The **claude-security-linter** pre-tool hook scans for unsafe language constructs such as `eval` or `Function` constructors, hard-coded secrets, and insecure imports. As referenced in `plugins/claude-security-linter` entries within [`.claude-plugin/marketplace.json`](https://github.com/anthropics/claude-plugins-community/blob/main/.claude-plugin/marketplace.json), this tool actively blocks writes when it detects high-severity issues and emits warnings for lower-severity findings.

### Credential-Exfiltration Detection

The scanner flags any code that reads from system credential stores—including macOS keychain, Linux `secret-tool`, Windows `cmdkey`, or `~/.aws/credentials`—and attempts to transmit those credentials to a different service. According to [`.github/actions/scan-plugins/policy/prompt.md`](https://github.com/anthropics/claude-plugins-community/blob/main/.github/actions/scan-plugins/policy/prompt.md) (lines 22-40), this "cross-service" usage constitutes an immediate policy violation.

### External Network-Call Detection

The analyzer determines whether plugins may initiate outbound HTTP/HTTPS requests or download additional binaries. The scan reports this capability via the `may_make_external_network_calls` flag, ensuring marketplace users understand a plugin's network footprint before installation.

### Dependency-Install-and-Download Checks

The action inspects scripts for package installation commands such as `npm install`, `pip install`, or `apt-get`. It sets the `may_download_additional_software` flag to prevent plugins from silently pulling in untrusted code during execution.

### Policy Compliance Verification

The scanner validates that the plugin's declared surface—defined in [`.claude-plugin/plugin.json`](https://github.com/anthropics/claude-plugins-community/blob/main/.claude-plugin/plugin.json), [`.mcp.json`](https://github.com/anthropics/claude-plugins-community/blob/main/.mcp.json), or directories like `skills/`, `agents/`, `commands/`, and `hooks/`—complies with the Anthropic Software Directory Policy and Acceptable Use Policy. Any deviation from the declared structure results in rejection.

## How to Verify Security Scanning Status

The [`README.md`](https://github.com/anthropics/claude-plugins-community/blob/main/README.md) (line 9) explicitly states that every plugin listed in [`.claude-plugin/marketplace.json`](https://github.com/anthropics/claude-plugins-community/blob/main/.claude-plugin/marketplace.json) has "passed automated security scanning." When you install from the community marketplace, you inherit these security guarantees.

```bash

# Add the community marketplace to Claude Code

claude plugin marketplace add anthropics/claude-plugins-community

# Install a specific plugin (guaranteed to have passed security scans)

claude plugin install <plugin-name>@claude-community

```

## Running Security Scans Locally

Developers can execute the same checks locally before submission using the **claude-security-linter** tool. This pre-tool hook scans code before Claude writes it to disk, helping you identify security issues during development rather than at CI time.

```bash

# From your plugin's root directory

npx its-animay/claude-security-linter .

# The tool blocks writes for high-severity issues and emits warnings for lower-severity findings

```

## Summary

- The **scan-plugins** GitHub Action enforces five distinct **security scans performed on Claude plugins** before marketplace acceptance
- **Static analysis** detects unsafe constructs and hard-coded secrets via the `claude-security-linter` pre-tool hook
- **Credential-exfiltration detection** prevents cross-service credential theft from system keychains and credential files
- **Network and dependency scans** identify external calls and software installation attempts using the `may_make_external_network_calls` and `may_download_additional_software` flags
- All plugins in [`.claude-plugin/marketplace.json`](https://github.com/anthropics/claude-plugins-community/blob/main/.claude-plugin/marketplace.json) carry a guarantee of automated security scanning as documented in [`README.md`](https://github.com/anthropics/claude-plugins-community/blob/main/README.md)

## Frequently Asked Questions

### What happens if a Claude plugin fails the security scans?

If any check fails, the plugin is rejected and must be corrected before resubmission. The scan-plugins action blocks the merge until the code complies with the policy defined in [`.github/actions/scan-plugins/policy/prompt.md`](https://github.com/anthropics/claude-plugins-community/blob/main/.github/actions/scan-plugins/policy/prompt.md).

### Can I use a Claude plugin that hasn't passed the community security scans?

The official marketplace only lists plugins that have cleared automated scanning as noted in [`README.md`](https://github.com/anthropics/claude-plugins-community/blob/main/README.md) line 9. While you could manually install unvetted code from other sources, the community repository guarantees security only for entries in [`.claude-plugin/marketplace.json`](https://github.com/anthropics/claude-plugins-community/blob/main/.claude-plugin/marketplace.json).

### How does the credential-exfiltration detection work?

The scanner inspects code for calls to system credential stores like macOS keychain, Linux `secret-tool`, or `~/.aws/credentials`. If it detects these credentials being sent to a service different from the one they were retrieved for, it flags a cross-service violation per the policy prompt (lines 22-40).

### Is the claude-security-linter available for local development?

Yes. The tool is available via `npx its-animay/claude-security-linter` and provides pre-tool-use hooks that scan code before Claude writes it to disk. This allows you to catch high-severity issues during development rather than discovering them during the CI pipeline execution.