What .github/actions Are Used in the Claude Plugins Community Repository?
The anthropics/claude-plugins-community repository defines exactly one custom composite action named validate-plugins under .github/actions/validate-plugins, which orchestrates a seven-step Bash validation pipeline on every pull request.
The Claude Plugins Community repository enforces strict quality and compatibility standards for community-contributed plugins through a centralized continuous integration strategy. Rather than distributing logic across multiple actions, the project consolidates all validation workflows into a single, sophisticated composite action located at .github/actions/validate-plugins. This action executes a coordinated suite of scripts that detect changes, verify manifest invariants, validate CLI configurations, and audit auxiliary files before any plugin code merges into the main branch.
The validate-plugins Composite Action Architecture
The .github/actions/validate-plugins directory implements a composite action—a reusable workflow component that bundles multiple execution steps into a single callable unit. This design allows the .github/workflows/validate-plugins.yml workflow to invoke the entire validation pipeline as one concise step while maintaining modular, testable script logic internally.
Change Detection Phase
The pipeline begins with scripts/00-detect-changes.sh, which analyzes the pull request context to identify which specific plugins have been modified. This targeted approach ensures the workflow only validates relevant submissions, optimizing CI runtime for large repositories with many plugins.
Core Manifest Validation
The action enforces structural and semantic requirements through three specialized validators:
scripts/11-validate-invariants.sh– Checks universal plugin rules such as required metadata fields, naming conventions, and schema compliance.scripts/20-validate-cli-marketplace.sh– Validates the marketplace-compatible CLI manifest format.scripts/30-validate-cli-external.sh– Verifies external CLI manifests that reference remote resources.scripts/40-validate-cli-local.sh– Inspects locally generated CLI manifests built from source.
Auxiliary File Auditing
Beyond manifest validation, scripts/41-validate-aux-files.sh ensures supporting assets meet repository standards. This includes verifying icon file formats, checking README.md presence and structure, and validating other documentation requirements that plugins must include for marketplace approval.
Reporting and Test Coverage
The final stage uses scripts/90-report.sh to aggregate results across all previous steps. If any validation fails, this script generates a comprehensive summary and explicitly fails the GitHub Actions job to block the merge.
Additionally, the action includes unit-style test harnesses:
test-invariants.sh– Validates the invariant checking logic itself.test-external-manifest.sh– Tests the external manifest parser against known good and bad inputs.
Workflow Integration
The .github/workflows/validate-plugins.yml file consumes the composite action using the local path syntax. This binding ensures the workflow always uses the version of the action defined in the current commit.
steps:
- name: Checkout repository
uses: actions/checkout@v3
- name: Run plugin validation
uses: ./.github/actions/validate-plugins
The action requires no explicit inputs because scripts/00-detect-changes.sh automatically parses the GitHub event context to determine the PR scope and changed files.
Local Development and Debugging
Developers can execute individual validation scripts locally without triggering the full GitHub Actions runner. This approach accelerates debugging when troubleshooting plugin submissions or developing new validation rules.
# Run invariant validation directly from repository root
bash .github/actions/validate-plugins/scripts/11-validate-invariants.sh
# Test external manifest logic
bash .github/actions/validate-plugins/test-external-manifest.sh
Running scripts locally requires that environment variables normally provided by the GitHub Actions runtime—such as workspace paths or PR metadata—be manually exported or mocked.
Summary
- The
anthropics/claude-plugins-communityrepository contains one custom action located at.github/actions/validate-plugins. - This composite action implements a seven-step validation pipeline using Bash scripts numbered sequentially from
00through90. - The pipeline covers change detection, manifest validation, CLI configuration checks, auxiliary file audits, and final reporting.
- Two test scripts provide unit-test coverage for the invariant and external-manifest validation logic.
- The action is invoked by
.github/workflows/validate-plugins.ymlusing the local pathuses: ./.github/actions/validate-plugins.
Frequently Asked Questions
What is the only custom GitHub Action defined in the Claude Plugins Community repository?
The repository defines a single composite action called validate-plugins under .github/actions/validate-plugins. According to the source code, this is the sole action used to enforce plugin quality standards, and it is referenced by the main validation workflow to check every pull request.
How does the validation action determine which plugins to check?
The action runs scripts/00-detect-changes.sh to analyze the GitHub event payload and detect which specific plugin directories have been modified in the current pull request. This allows the pipeline to validate only affected submissions rather than scanning the entire repository on every CI run.
Can developers run the validation scripts outside of GitHub Actions?
Yes. Each script in .github/actions/validate-plugins/scripts/ and the test files test-invariants.sh and test-external-manifest.sh are executable Bash scripts that can run locally from the repository root. Developers use this capability to debug validation failures before pushing commits, though they must manually provide environment variables that GitHub Actions normally injects automatically.
What happens if a plugin fails validation during CI?
The scripts/90-report.sh script aggregates results from all previous validation stages and generates a final summary. If any step reports an error, this script exits with a non-zero status code, which causes the GitHub Actions job to fail and prevents the pull request from being merged until all issues are resolved.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →