How Changes to the Claude Plugin Marketplace Are Reflected: A Complete Technical Guide
Changes to the Claude plugin marketplace propagate through a nightly sync to a single JSON file, followed by CI validation and a local CLI update command that refreshes the user's plugin cache.
The anthropics/claude-plugins-community repository serves as the official community plugin marketplace for Claude. Understanding how changes to this marketplace are reflected to end users requires examining the automated pipeline that maintains data integrity and the CLI workflow that distributes updates. This article breaks down the complete propagation chain from Anthropic's internal review system to your local machine.
The Single Source of Truth: marketplace.json
All marketplace changes are reflected in one canonical file: .claude-plugin/marketplace.json. This JSON file contains the complete list of approved community plugins, each with a name, description, source URL, and pinned SHA for reproducible builds.
According to the repository's README.md, this repo functions as "a read-only mirror of the community plugin marketplace"【/cache/repos/github.com/anthropics/claude-plugins-community/main/README.md†L5-L9】. The mirror status means contributors cannot directly edit marketplace.json; instead, Anthropic's internal systems write to it.
The Nightly Sync Pipeline
Step 1: Internal Review and Nightly Writes
Anthropic's internal review pipeline performs a complete overwrite of marketplace.json each night. This process:
- Collects all approved plugins from the internal queue
- Generates fresh metadata for new submissions
- Updates pinned SHAs for version bumps
- Writes the assembled JSON to the repository
Because this is a full replacement rather than a patch, the file always represents a coherent, validated state.
Step 2: CI Validation on Every Change
When any pull request touches marketplace entries, the GitHub Actions workflow validate-plugins executes. The validation script at .github/actions/validate-plugins/scripts/20-validate-cli-marketplace.sh runs:
#!/bin/bash
claude plugin validate
This command performs a full schema check against the official plugin specification【/cache/repos/github.com/anthropics/claude-plugins-community/main/.github/actions/validate-plugins/scripts/20-validate-cli-marketplace.sh†L2-L8】. The CI pipeline can assemble the marketplace from individual *.json entry files or validate a pre-assembled file, ensuring the nightly-synced marketplace.json never violates schema invariants.
How Users Receive Marketplace Changes
After the nightly sync completes, users must explicitly pull the update. The CLI provides a dedicated command for this workflow.
Adding the Community Marketplace
First-time users add the marketplace source once:
claude plugin marketplace add anthropics/claude-plugins-community
Updating the Local Cache
To reflect the latest marketplace changes, run:
claude plugin marketplace update
This command reads https://github.com/anthropics/claude-plugins-community/.claude-plugin/marketplace.json (or the local copy if the repo is cloned) and refreshes the user's plugin cache with the latest SHA-pinned entries. As noted in quickdesign/README.md, "new skill versions reach you whenever you run /plugin marketplace update"【/cache/repos/github.com/anthropics/claude-plugins-community/main/quickdesign/README.md†L39-L41】.
Installing Updated Plugins
After updating the marketplace cache, install any plugin with precise version pinning:
claude plugin install <plugin-name>@claude-community
The installer looks up the plugin's source URL and pinned SHA in marketplace.json. For example, the 0x entry in the marketplace shows this structure:
{
"name": "0x",
"description": "...",
"source_url": "https://github.com/...",
"sha": "abc123..."
}
【/cache/repos/github.com/anthropics/claude-plugins-community/main/.claude-plugin/marketplace.json†L14-L20】
Because the SHA is fixed at sync time, every installation of a given marketplace version uses identical code—no drift, no surprise updates.
Complete User Workflow Example
# 1️⃣ Add the community marketplace (one-time setup)
claude plugin marketplace add anthropics/claude-plugins-community
# 2️⃣ Pull the latest marketplace state (run after each nightly sync)
claude plugin marketplace update
# 3️⃣ Install a newly-added plugin (e.g., "10x-shopping")
claude plugin install 10x-shopping@claude-community
# 4️⃣ Verify the installed version matches the marketplace SHA
cat ~/.claude/plugins/10x-shopping/metadata.json
The metadata.json file in your local plugin directory contains the same SHA recorded in marketplace.json, confirming your installation matches the curated version.
Key Files Controlling Marketplace Reflection
| File | Function |
|---|---|
.claude-plugin/marketplace.json |
Canonical plugin registry with pinned SHAs |
README.md (root) |
Documents the read-only mirror architecture【/cache/repos/github.com/anthropics/claude-plugins-community/main/README.md†L5-L11】 |
.github/workflows/validate-plugins.yml |
Triggers validation on PR changes |
.github/actions/validate-plugins/scripts/20-validate-cli-marketplace.sh |
Executes claude plugin validate for schema enforcement |
quickdesign/README.md |
Demonstrates marketplace update behavior【/cache/repos/github.com/anthropics/claude-plugins-community/main/quickdesign/README.md†L39-L41】 |
Summary
- Single source of truth: All marketplace data lives in
.claude-plugin/marketplace.json - Nightly propagation: Anthropic's internal pipeline writes approved changes every night
- Automated validation: CI runs
claude plugin validateon every modification to enforce schema compliance - Explicit user action:
claude plugin marketplace updatepulls changes to your local machine - Reproducible installs: SHA pinning in
marketplace.jsonguarantees consistent plugin versions across all users
Frequently Asked Questions
How often does the marketplace update?
The marketplace file updates nightly via Anthropic's internal review pipeline. However, users only see these changes after running claude plugin marketplace update on their local machine. There is no automatic background refresh—updates are pull-based, not push-based.
Can I contribute directly to marketplace.json?
No. The repository is explicitly designated as a read-only mirror in README.md【/cache/repos/github.com/anthropics/claude-plugins-community/main/README.md†L5-L9】. To add or update a plugin, submit through Anthropic's official review process; approved changes will appear in the next nightly sync.
Why are plugin versions pinned to specific SHAs rather than tags or branches?
SHA pinning ensures reproducible builds. When you install plugin-name@claude-community, you receive exactly the code referenced in marketplace.json at sync time. This prevents supply-chain attacks where a malicious actor could re-point a tag to different code after approval.
What happens if I skip the marketplace update command?
Your local plugin cache remains at the version from your last claude plugin marketplace update. New plugins won't appear in search, and updated plugin descriptions or pinned SHAs won't be visible. Installations will use stale metadata, potentially missing security patches or bug fixes included in newer marketplace versions.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →