How the Nightly Sync from Anthropic's Internal Review Pipeline Works in Claude Plugins Community

The nightly sync from Anthropic's internal review pipeline is an automated process where approved plugins are assembled into a canonical marketplace.json file and pushed daily to the read-only anthropics/claude-plugins-community repository.

The anthropics/claude-plugins-community repository serves as a read-only mirror of the community plugin marketplace. Rather than accepting direct contributions, this repository receives all plugin entries through a curated, security-scanned internal pipeline. Understanding how this nightly sync operates is essential for developers who want to contribute plugins or consume the marketplace programmatically.

The Internal Review Pipeline

All community plugins originate from public submissions, but none enter the repository directly.

When a contributor submits a plugin via Anthropic's public submission form, an internal workflow triggers:

  • Automated security checks scan the plugin code
  • The claude plugin validate command runs against the plugin's manifest
  • Only after passing both checks does the pipeline write the entry into the assembled marketplace file

The pipeline produces a canonical .claude-plugin/marketplace.json that lists every approved plugin with its metadata and pinned SHA. As documented in the repository's README, this file is "synced nightly from Anthropic's internal review pipeline" [(README.md)](https://github.com/anthropics/claude-plugins-community/blob/main/README.md#L7).

Nightly Sync Mechanics

The sync itself runs entirely outside the repository through Anthropic's CI infrastructure.

Each night, the internal pipeline pushes a single commit that updates marketplace.json. Because this is a mirror repository, direct pull requests are automatically rejected. The Close External PRs workflow enforces this restriction [.github/workflows/close-external-prs.yml](https://github.com/anthropics/claude-plugins-community/blob/main/.github/workflows/close-external-prs.yml#L52).

This architecture guarantees a single source of truth: the internal pipeline alone controls what appears in the marketplace.

Post-Sync Validation

After the nightly push completes, the repository runs its own validation to ensure integrity.

The validate-plugins.yml workflow consumes the freshly-synced marketplace.json via the marketplace-path input [.github/workflows/validate-plugins.yml](https://github.com/anthropics/claude-plugins-community/blob/main/.github/workflows/validate-plugins.yml#L53). This step verifies:

  • Schema conformance against the Claude plugin specification
  • Reachability of all external plugin entries

SHA Bumping for Live Plugins

A separate nightly job keeps pinned references current without manual intervention.

The bump-plugin-shas.yml workflow runs daily at 07:23 UTC [.github/workflows/bump-plugin-shas.yml](https://github.com/anthropics/claude-plugins-community/blob/main/.github/workflows/bump-plugin-shas.yml#L28). Its process:

  1. Checks whether any plugin's upstream HEAD has moved past its pinned SHA
  2. Validates the new commit against security and compatibility criteria
  3. Opens a per-plugin PR to update the pin

This separation—nightly sync for new plugins, separate job for SHA updates—maintains stability while allowing plugins to evolve.

Read-Only Enforcement

The Close External PRs workflow protects the mirror from accidental modifications [.github/workflows/close-external-prs.yml](https://github.com/anthropics/claude-plugins-community/blob/main/.github/workflows/close-external-prs.yml#L18-L53).

Allowed PRs:

  • Opened by github-actions[bot] (the automation account)
  • Opened by users with write or admin permissions

All other PRs receive an immediate close with an explanatory comment describing the nightly sync model. This prevents confusion and maintains repository integrity.

Complete Pipeline Flow

The entire lifecycle follows this sequence:


Submission → Internal Review → Marketplace Assembly → Nightly Push → Repo Validation → SHA Bumping

Each stage has clear ownership: Anthropic's internal systems handle curation and assembly, while the public repository handles validation and reference maintenance.

Working with the Synced Marketplace

Command-Line Usage


# Install the community marketplace (one-time setup)

claude plugin marketplace add anthropics/claude-plugins-community

# List all available plugins (reads the synced marketplace.json)

claude plugin list

# Install a specific plugin from the community marketplace

claude plugin install my-plugin@claude-community

Programmatic Access

Read the synced marketplace file directly in Node.js:

import fs from 'fs';
import path from 'path';

// Path relative to the repo root
const marketplacePath = path.resolve(
  __dirname,
  '.claude-plugin/marketplace.json'
);

const marketplace = JSON.parse(fs.readFileSync(marketplacePath, 'utf8'));

// Print the names of all community plugins
marketplace.entries.forEach(entry => console.log(entry.name));

Key Files in the Sync Architecture

File Purpose
README.md Documents the nightly-synced read-only mirror
.github/workflows/close-external-prs.yml Auto-closes non-bot PRs, enforces read-only model
.github/workflows/bump-plugin-shas.yml Daily job that updates SHA pins
.github/workflows/validate-plugins.yml Validates synced marketplace.json for schema correctness
.claude-plugin/marketplace.json The assembled list of approved plugins updated each night

Summary

  • Single source of truth: The internal review pipeline alone controls marketplace content
  • Automated nightly delivery: Fresh marketplace.json pushes occur every night without manual intervention
  • Zero direct contributions: All external PRs are automatically rejected; changes flow through the submission form only
  • Dual validation: Internal security scans plus post-sync schema verification ensure quality
  • Self-maintaining references: SHA bumping keeps plugins current while preserving stability

Frequently Asked Questions

How can I contribute a plugin to the marketplace?

Submit your plugin through Anthropic's public submission form. Your plugin will enter the internal review pipeline where automated security checks and claude plugin validate will run against your manifest. Once approved, it will appear in the next nightly sync. Direct pull requests to the repository are automatically closed.

Why are my pull requests being rejected?

The anthropics/claude-plugins-community repository is a read-only mirror. The Close External PRs workflow rejects any PR not opened by github-actions[bot] or users with elevated permissions. This ensures the internal pipeline remains the sole source of marketplace truth.

When exactly does the nightly sync run?

The sync runs nightly through Anthropic's internal CI infrastructure. The exact timing is not publicly specified, but dependent workflows like SHA bumping run at 07:23 UTC daily. Validation workflows trigger immediately after each sync completes.

Can I pin to a specific version of the marketplace?

Yes. Because each nightly sync creates a commit with the updated marketplace.json, you can reference specific commits or SHAs from the repository history. The marketplace file itself also contains pinned SHAs for each plugin, ensuring reproducible installs even as upstream repositories evolve.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →