# Claude External Plugin Security Model: Automated Validation and Policy Enforcement

> Discover the Claude plugin security model. Learn how automated validation and policy enforcement prevent credential exfiltration and unauthorized network requests in external plugins.

- Repository: [Anthropic/claude-plugins-community](https://github.com/anthropics/claude-plugins-community)
- Tags: security
- Published: 2026-08-24

---

**The Claude plugin marketplace enforces a layered security model that combines automated schema validation, policy-driven security scanning, and immutable commit pinning to ensure external plugins cannot exfiltrate credentials or execute unauthorized network requests.**

The `anthropics/claude-plugins-community` repository implements a comprehensive security framework for third-party integrations. Every external plugin undergoes rigorous automated checks before appearing in the marketplace, protecting users from malicious code, credential exfiltration, and unauthorized network activity.

## Automated Schema Validation with Zod

Every plugin submission must conform to the official Claude plugin schema defined in the Zod model. The validation process begins with the **`claude plugin validate`** command, which runs against each plugin's [`plugin.json`](https://github.com/anthropics/claude-plugins-community/blob/main/plugin.json) manifest (or a synthesized manifest for skill-only entries).

The **validate-plugins** composite action ([`.github/actions/validate-plugins/action.yml`](https://github.com/anthropics/claude-plugins-community/blob/main/.github/actions/validate-plugins/action.yml)) orchestrates this process. When a pull request adds or modifies plugins, the [`.github/workflows/validate-plugins.yml`](https://github.com/anthropics/claude-plugins-community/blob/main/.github/workflows/validate-plugins.yml) workflow triggers the validation pipeline. This ensures structural integrity before any security analysis begins.

For external plugins specifically, the validation script at [`validate-plugins/scripts/30-validate-cli-external.sh`](https://github.com/anthropics/claude-plugins-community/blob/main/validate-plugins/scripts/30-validate-cli-external.sh) clones the third-party repository at the exact pinned SHA and executes the validation command:

```bash
git clone "$url" "$tmp_dir"
git checkout "$sha"
claude plugin validate "$tmp_dir/.claude-plugin/plugin.json"

```

## Policy-Driven Security Scanning

The **scan-plugins** action implements the core security review through a dedicated policy prompt located at [`.github/actions/scan-plugins/policy/prompt.md`](https://github.com/anthropics/claude-plugins-community/blob/main/.github/actions/scan-plugins/policy/prompt.md). This prompt defines specific checks for dangerous behaviors in external codebases.

The security scanner flags four critical risk categories:

- **Cross-service credential exfiltration**: Code that reads credentials from stores (e.g., `~/.aws/credentials`, macOS keychain, `ANTHROPIC_AUTH_TOKEN`) and transmits them to different services
- **External network calls**: Any outbound network requests made by the plugin
- **Software downloads**: Attempts to install additional software or dependencies at runtime
- **Malicious code patterns**: General security anti-patterns and unsafe operations

The policy prompt (lines 22-49) specifically enumerates credential sources to monitor, while lines 56-57 define the JSON output fields `may_make_external_network_calls` and `may_download_additional_software` that capture these risks.

## Immutable Pinning for External Plugins

External plugins cannot reference mutable branches like `@main`. The security model requires **pinned commit SHAs** (`source.sha`) for every external entry, enforced by the **bump-plugin-shas** action ([`.github/actions/bump-plugin-shas/action.yml`](https://github.com/anthropics/claude-plugins-community/blob/main/.github/actions/bump-plugin-shas/action.yml)).

This immutability guarantee prevents supply-chain attacks where a trusted plugin might be compromised after initial approval. Plugins without SHA references are either explicitly exempted (`sha-exempt`) or automatically rejected from the marketplace.

The [`bump-plugin-shas/README.md`](https://github.com/anthropics/claude-plugins-community/blob/main/bump-plugin-shas/README.md) documents this requirement, explaining that the action ensures external plugins remain at exact, auditable code states throughout their marketplace lifecycle.

## Continuous Validation and Nightly Monitoring

Security validation does not end at submission. The [`.github/workflows/validate-plugins-nightly.yml`](https://github.com/anthropics/claude-plugins-community/blob/main/.github/workflows/validate-plugins-nightly.yml) workflow runs continuous re-validation against the entire marketplace catalog. This nightly process detects security drift, newly discovered vulnerabilities in pinned dependencies, or policy violations that emerge after initial publication.

The **validate-plugins-nightly** job re-executes the full validation suite—including schema checks and security scans—ensuring that previously approved plugins maintain compliance with evolving security standards.

## Summary

- **Schema validation** via `claude plugin validate` ensures all plugins conform to the official Zod schema before security review
- **Policy-driven scanning** at [`.github/actions/scan-plugins/policy/prompt.md`](https://github.com/anthropics/claude-plugins-community/blob/main/.github/actions/scan-plugins/policy/prompt.md) detects credential exfiltration, external network calls, and software installation attempts
- **Immutable pinning** enforced by `bump-plugin-shas` requires external plugins to use fixed commit SHAs rather than mutable branch references
- **External isolation** through [`30-validate-cli-external.sh`](https://github.com/anthropics/claude-plugins-community/blob/main/30-validate-cli-external.sh) clones third-party repos at exact SHAs and validates them in isolated environments
- **Continuous monitoring** via [`validate-plugins-nightly.yml`](https://github.com/anthropics/claude-plugins-community/blob/main/validate-plugins-nightly.yml) re-scans the entire marketplace catalog for security drift or new vulnerabilities

## Frequently Asked Questions

### How does the Claude marketplace prevent credential theft by external plugins?

The security model specifically detects **cross-service credential exfiltration** by scanning for code that reads from credential stores (such as `~/.aws/credentials`, macOS keychain, or the `ANTHROPIC_AUTH_TOKEN` environment variable) and subsequently transmits that data to a different service. According to the policy prompt at [`.github/actions/scan-plugins/policy/prompt.md`](https://github.com/anthropics/claude-plugins-community/blob/main/.github/actions/scan-plugins/policy/prompt.md), normal integrations that use credentials to call their own service are permitted, but exfiltration patterns are flagged and rejected.

### What is the difference between internal and external plugin validation?

Internal plugins undergo schema validation directly within the repository, while **external plugins** trigger an additional isolation step. The [`validate-plugins/scripts/30-validate-cli-external.sh`](https://github.com/anthropics/claude-plugins-community/blob/main/validate-plugins/scripts/30-validate-cli-external.sh) script clones the third-party repository at the exact pinned SHA and runs `claude plugin validate` in that isolated context. Both types receive identical policy scans, but external plugins require SHA pinning and remote repository access.

### Why does the security model require pinned commit SHAs for external plugins?

Pinned SHAs enforce **immutability** and prevent supply-chain attacks. Without this requirement, a malicious actor could compromise a legitimate plugin repository after marketplace approval and push malicious code to the main branch. The `bump-plugin-shas` action ensures every external reference points to an exact, auditable commit, making the marketplace catalog deterministic and tamper-resistant.

### How often are plugins re-evaluated for security compliance?

The marketplace runs **nightly validation** via [`.github/workflows/validate-plugins-nightly.yml`](https://github.com/anthropics/claude-plugins-community/blob/main/.github/workflows/validate-plugins-nightly.yml), which re-scans the entire plugin catalog for security drift, policy violations, and newly discovered vulnerabilities. This continuous validation ensures that plugins remain compliant with the Anthropic Software Directory Policy and Acceptable Use Policy even after initial publication.