Claude External Plugin Security Model: Automated Validation and Policy Enforcement
The Claude plugin marketplace enforces a layered security model that combines automated schema validation, policy-driven security scanning, and immutable commit pinning to ensure external plugins cannot exfiltrate credentials or execute unauthorized network requests.
The anthropics/claude-plugins-community repository implements a comprehensive security framework for third-party integrations. Every external plugin undergoes rigorous automated checks before appearing in the marketplace, protecting users from malicious code, credential exfiltration, and unauthorized network activity.
Automated Schema Validation with Zod
Every plugin submission must conform to the official Claude plugin schema defined in the Zod model. The validation process begins with the claude plugin validate command, which runs against each plugin's plugin.json manifest (or a synthesized manifest for skill-only entries).
The validate-plugins composite action (.github/actions/validate-plugins/action.yml) orchestrates this process. When a pull request adds or modifies plugins, the .github/workflows/validate-plugins.yml workflow triggers the validation pipeline. This ensures structural integrity before any security analysis begins.
For external plugins specifically, the validation script at validate-plugins/scripts/30-validate-cli-external.sh clones the third-party repository at the exact pinned SHA and executes the validation command:
git clone "$url" "$tmp_dir"
git checkout "$sha"
claude plugin validate "$tmp_dir/.claude-plugin/plugin.json"
Policy-Driven Security Scanning
The scan-plugins action implements the core security review through a dedicated policy prompt located at .github/actions/scan-plugins/policy/prompt.md. This prompt defines specific checks for dangerous behaviors in external codebases.
The security scanner flags four critical risk categories:
- Cross-service credential exfiltration: Code that reads credentials from stores (e.g.,
~/.aws/credentials, macOS keychain,ANTHROPIC_AUTH_TOKEN) and transmits them to different services - External network calls: Any outbound network requests made by the plugin
- Software downloads: Attempts to install additional software or dependencies at runtime
- Malicious code patterns: General security anti-patterns and unsafe operations
The policy prompt (lines 22-49) specifically enumerates credential sources to monitor, while lines 56-57 define the JSON output fields may_make_external_network_calls and may_download_additional_software that capture these risks.
Immutable Pinning for External Plugins
External plugins cannot reference mutable branches like @main. The security model requires pinned commit SHAs (source.sha) for every external entry, enforced by the bump-plugin-shas action (.github/actions/bump-plugin-shas/action.yml).
This immutability guarantee prevents supply-chain attacks where a trusted plugin might be compromised after initial approval. Plugins without SHA references are either explicitly exempted (sha-exempt) or automatically rejected from the marketplace.
The bump-plugin-shas/README.md documents this requirement, explaining that the action ensures external plugins remain at exact, auditable code states throughout their marketplace lifecycle.
Continuous Validation and Nightly Monitoring
Security validation does not end at submission. The .github/workflows/validate-plugins-nightly.yml workflow runs continuous re-validation against the entire marketplace catalog. This nightly process detects security drift, newly discovered vulnerabilities in pinned dependencies, or policy violations that emerge after initial publication.
The validate-plugins-nightly job re-executes the full validation suite—including schema checks and security scans—ensuring that previously approved plugins maintain compliance with evolving security standards.
Summary
- Schema validation via
claude plugin validateensures all plugins conform to the official Zod schema before security review - Policy-driven scanning at
.github/actions/scan-plugins/policy/prompt.mddetects credential exfiltration, external network calls, and software installation attempts - Immutable pinning enforced by
bump-plugin-shasrequires external plugins to use fixed commit SHAs rather than mutable branch references - External isolation through
30-validate-cli-external.shclones third-party repos at exact SHAs and validates them in isolated environments - Continuous monitoring via
validate-plugins-nightly.ymlre-scans the entire marketplace catalog for security drift or new vulnerabilities
Frequently Asked Questions
How does the Claude marketplace prevent credential theft by external plugins?
The security model specifically detects cross-service credential exfiltration by scanning for code that reads from credential stores (such as ~/.aws/credentials, macOS keychain, or the ANTHROPIC_AUTH_TOKEN environment variable) and subsequently transmits that data to a different service. According to the policy prompt at .github/actions/scan-plugins/policy/prompt.md, normal integrations that use credentials to call their own service are permitted, but exfiltration patterns are flagged and rejected.
What is the difference between internal and external plugin validation?
Internal plugins undergo schema validation directly within the repository, while external plugins trigger an additional isolation step. The validate-plugins/scripts/30-validate-cli-external.sh script clones the third-party repository at the exact pinned SHA and runs claude plugin validate in that isolated context. Both types receive identical policy scans, but external plugins require SHA pinning and remote repository access.
Why does the security model require pinned commit SHAs for external plugins?
Pinned SHAs enforce immutability and prevent supply-chain attacks. Without this requirement, a malicious actor could compromise a legitimate plugin repository after marketplace approval and push malicious code to the main branch. The bump-plugin-shas action ensures every external reference points to an exact, auditable commit, making the marketplace catalog deterministic and tamper-resistant.
How often are plugins re-evaluated for security compliance?
The marketplace runs nightly validation via .github/workflows/validate-plugins-nightly.yml, which re-scans the entire plugin catalog for security drift, policy violations, and newly discovered vulnerabilities. This continuous validation ensures that plugins remain compliant with the Anthropic Software Directory Policy and Acceptable Use Policy even after initial publication.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →