What Happens When a Plugin Owner Becomes Inactive in Claude Plugins Community
When a plugin owner becomes inactive, the Claude Plugins Community repository detects this through the daily Owner Liveness Sweep workflow, classifies the finding as owner_missing, and generates a report for manual review without automatically removing any marketplace entries.
The anthropics/claude-plugins-community repository maintains a curated marketplace of external plugins. To preserve data integrity, the project implements automated monitoring that tracks whether plugin owners remain active on GitHub. This article explains the detection mechanism, classification system, and resolution workflow triggered when an owner disappears.
How Owner Inactivity Is Detected
The Owner Liveness Sweep runs automatically every day via the scheduled workflow defined in .github/workflows/owner-liveness-sweep.yml. This workflow executes a Bash script located at .github/actions/owner-liveness-sweep/scripts/sweep.sh that validates each owner listed in the marketplace against GitHub's API.
The sweep compares current owner data against a baseline stored in .github/owner-baseline.json. This file maps each owner login to the GitHub account ID captured when the entry was first added. By tracking account IDs rather than just usernames, the system can distinguish between benign renames and actual account disappearances.
Classification of Owner Missing Scenarios
When the sweep cannot resolve an owner login, it categorizes the finding as owner_missing. The detection logic documented in .github/actions/owner-liveness-sweep/README.md distinguishes three dispositions:
| Classification | Meaning | Action Taken |
|---|---|---|
owner_missing |
The owner login no longer resolves (account deleted or renamed). | Reported as informational warning; no automatic marketplace modification. |
verify-successor |
The owner's repositories still resolve under a new canonical owner. | Report includes successor location for reviewer verification. |
review |
No repositories resolve for the missing owner. | Entries flagged for manual review and potential removal. |
Why the Sweep Does Not Auto-Remove Entries
The sweep only fails the CI pipeline when an identity_changed finding occurs—when the same login now points to a different GitHub account ID. This indicates potential account hijacking and demands immediate attention.
All other owner_missing findings generate informational warnings rather than hard failures. This design choice:
- Prevents breaking the CI pipeline for non-critical issues
- Allows maintainers to verify successor claims before updating records
- Preserves marketplace stability while flagging problems for human review
Running the Liveness Check Locally
You can execute the owner verification step outside of CI using the report mode. From the repository root:
MARKETPLACE_PATH=.claude-plugin/marketplace.json \
BASELINE_PATH=.github/owner-baseline.json \
MODE=report \
bash .github/actions/owner-liveness-sweep/scripts/sweep.sh
The report mode prints a formatted table showing owner statuses. Maintainers can switch to refresh mode after verifying findings to update the baseline with corrected mappings.
Key Files in the Detection System
Understanding the codebase structure helps when investigating owner inactivity reports:
| File | Purpose |
|---|---|
.github/workflows/owner-liveness-sweep.yml |
Scheduled CI workflow triggering daily execution |
.github/actions/owner-liveness-sweep/README.md |
Documentation of detection categories and baseline handling |
.github/owner-baseline.json |
Persistent mapping of logins to GitHub account IDs |
.github/actions/owner-liveness-sweep/scripts/sweep.sh |
Core bash script performing resolution checks and report generation |
Summary
- The Owner Liveness Sweep in
anthropics/claude-plugins-communityruns daily to monitor plugin owner activity - Inactive owners are classified as
owner_missingand reported without automatic marketplace deletion - Three dispositions guide resolution:
verify-successorfor re-brands,reviewfor deletions, andidentity_changedfor account hijacking - The system preserves CI stability by treating most findings as warnings, failing only on identity changes
- Local execution via
sweep.shsupports manual verification and baseline refresh operations
Frequently Asked Questions
Does the sweep automatically delete plugins from inactive owners?
No. The sweep never modifies the marketplace automatically. All owner_missing findings are reported for manual review. Only after human verification of successor claims or confirmation that repositories are truly gone will maintainers update or remove entries.
What triggers a failed CI build in the owner liveness workflow?
The workflow fails only on identity_changed findings. This occurs when a login string now resolves to a different GitHub account ID than recorded in the baseline, suggesting potential account compromise. All other classifications including owner_missing generate warnings without failing the pipeline.
How does the system distinguish between a deleted account and a renamed account?
The sweep examines repository resolution patterns rather than relying solely on login resolution. If repositories still exist under a new canonical owner name, the disposition is verify-successor. If no repositories resolve, the disposition is review for potential deletion.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →