How the Read‑Only Mirror Model Affects Contributions to the Claude Plugins Community Repository
The Claude Plugins Community repository automatically rejects all pull requests because it functions as a read‑only mirror that syncs nightly from Anthropic's internal review pipeline, requiring contributors to submit plugins through the official web portal instead.
The anthropics/claude-plugins-community repository serves as the public face of Anthropic’s community plugin marketplace, but it operates under a strict read‑only mirror model. Unlike typical open‑source projects that accept direct contributions via GitHub, this repository is generated automatically each night from an internal review pipeline. Understanding how this read‑only mirror model works is essential for developers who want to share their Claude plugins with the community.
Understanding the Read‑Only Mirror Architecture
What Is a Read‑Only Mirror?
A read‑only mirror means the repository contents are not editable by the public. According to the source code in README.md, this repository is explicitly designated as a read‑only mirror of the official community plugin marketplace. The file states that the repository’s contents are "synced nightly from Anthropic's internal systems," establishing that GitHub is not the source of truth for the plugin data.
The Nightly Sync Process
The authoritative source of plugin information resides in .claude-plugin/marketplace.json. This file is overwritten every night during the automated sync process. Any manual changes made directly to this file—or any other file in the repository—would be permanently erased during the next synchronization cycle. This ensures the repository always reflects the vetted, security‑scanned state of the internal marketplace.
How Pull Requests Are Automatically Rejected
The Close External PRs Workflow
When external contributors attempt to open pull requests, the repository enforces its read‑only policy through the .github/workflows/close-external-prs.yml workflow. This GitHub Action runs automatically on every pull request event and determines whether to allow or reject the contribution based on the author's permissions.
The workflow implements the following logic as seen in the source code:
# .github/workflows/close-external-prs.yml (excerpt)
script: |
const author = context.payload.pull_request.user.login;
if (author === 'github-actions[bot]') { return; } # allow internal bot
const { data } = await github.rest.repos.getCollaboratorPermissionLevel({
owner: context.repo.owner,
repo: context.repo.repo,
username: author,
});
if (['admin', 'write'].includes(data.permission)) { return; }
await github.rest.issues.createComment({
body: [
"Thanks for the PR! This repo is a **read-only mirror** — its contents are synced nightly from Anthropic's internal review pipeline, so direct pull requests are closed automatically.",
"",
"To submit a plugin to the community marketplace, use https://clau.de/plugin-directory-submission."
].join('\n')
});
await github.rest.pulls.update({ state: 'closed' });
This automation ensures that no external contributions can accidentally modify the mirrored content.
Permission Checks and Exemptions
The workflow specifically checks for two conditions before allowing a PR to remain open:
- Administrators and writers: Users with
adminorwritepermissions (reserved for internal automation) are exempt from closure - GitHub Actions bot: The
github-actions[bot]account is allowed to pass through, as it handles the nightly sync operations
Everyone else receives an automated comment explaining the read‑only nature of the repository and directing them to the proper submission channel.
The Correct Contribution Pathway
Submitting via the Official Portal
Because direct GitHub contributions are blocked, the only way to add a plugin to this repository is through the external submission system. As documented in README.md (lines 24‑27), authors must submit their plugins via https://clau.de/plugin-directory-submission.
Once submitted, plugins undergo the following process:
- Automated security scans validate the plugin code
- Internal review by Anthropic's team ensures quality and safety standards
- Upon approval, the plugin is added to the internal marketplace database
- The nightly sync job updates
.claude-plugin/marketplace.jsonin this repository - The plugin becomes available for installation via the CLI
Why Direct File Changes Don't Work
Attempting to bypass the portal by editing marketplace.json or other files directly is futile. As noted in the repository documentation, the file is "generated automatically" and explicitly marked as the authoritative source that is "synced nightly." Manual edits would persist only until the next synchronization, at which point the file would revert to match Anthropic's internal state, discarding any unauthorized modifications.
Summary
- The repository is a read‑only mirror that syncs nightly from Anthropic's internal review pipeline, not a traditional open‑source project.
- Pull requests are automatically closed by the
.github/workflows/close-external-prs.ymlworkflow unless the author has admin/write permissions or is the GitHub Actions bot. - The marketplace.json file is authoritative but ephemeral—any manual edits are overwritten during the next sync cycle.
- Contributions require portal submission through
https://clau.de/plugin-directory-submission, followed by automated security scans and internal review. - Plugins appear after nightly sync once approved, ensuring the repository always reflects a vetted, secure state.
Frequently Asked Questions
Can I open a pull request to add my plugin to the repository?
No. The repository automatically closes all external pull requests via the close-external-prs.yml workflow. This read‑only mirror model requires you to submit your plugin through the official portal at https://clau.de/plugin-directory-submission instead.
What happens if I try to edit the marketplace.json file directly?
Your changes would be temporary and overwritten. The .claude-plugin/marketplace.json file is synced nightly from Anthropic's internal systems, so any direct edits made through GitHub would be erased during the next automated synchronization cycle.
Who can contribute directly to this repository?
Only automated systems and users with elevated permissions. According to the workflow logic, only accounts with admin or write collaborator permissions—plus the github-actions[bot]—can open pull requests that remain open. All other contributors are automatically rejected.
How long does it take for my submitted plugin to appear in the repository?
After submission through the portal, your plugin must pass automated security scans and internal review. Once approved, it will appear in the repository during the next nightly sync cycle. The exact timing depends on when you receive approval relative to the daily synchronization schedule.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →