Skip to main content
agentsSource-backed

Claude Plugin Marketplace Reviewer Agent

A reusable agent prompt that vets a Claude Code plugin or marketplace before a team installs it. It walks source trust, the plugin's Will-install list and bundled components (skills, agents, hooks, MCP servers, commands), the context-window cost, version pinning, and the user/project/local/managed install scope.

by JPette1783·added 2026-06-05·
Review first review before installing

Open the source and read safety notes before installing.

Citation facts

Source-backed facts for citing this resource, derived directly from the registry — also available as plain text for AI assistants.

Source URLs
https://code.claude.com/docs/en/discover-plugins, https://github.com/JSONbored/awesome-claude/blob/main/content/agents/claude-plugin-marketplace-reviewer-agent.mdx
Safety notes
Plugins and marketplaces can execute arbitrary code with the user's privileges; recommend installing only from trusted sources and reviewing the Will-install list (commands, agents, skills, hooks, MCP/LSP servers) first., Anthropic does not control what plugins contain and cannot verify they work as intended; the official marketplace is curated but community/third-party sources are not security-audited., Recommend managed marketplace restrictions and managed scope for org-wide control, and version pinning so updates are intentional.
Privacy notes
Bundled MCP servers and hooks can access local files and external services; review what each component reaches before approving install., A plugin's context cost is added to every turn; factor it into the review and prefer tool-search-friendly MCP plugins., Do not approve plugins whose source or components you cannot inspect; treat install as a supply-chain decision.
Author
JPette1783
Submitted by
JPette1783
Claim status
unclaimed
Last verified
2026-06-05

Decision playbook

Review trust signals before you adopt

Signals are present but mixed. Use the checklist below to confirm the source and operational safety for your environment.

Compare context
Selected

0

Current score

63

Baseline

Delta

No baseline selected

No major trust-signal divergence detected in the current selection.

Source and provenance checks

Needs review

Confirm ownership and provenance before trusting install instructions.

  • Source link availableRequired

    Open the canonical repository and verify ownership.

    Done
  • Source provenance statusRequired

    Marked as source-backed.

    Done
  • Metadata reviewed

    No reviewed flag detected in metadata.

    Pending

Safety and privacy checks

Complete

Validate risk disclosures before installation or API wiring.

  • Safety notes presentRequired

    Review the listed safety guidance before running commands.

    Done
  • Privacy notes presentRequired

    Review data handling notes before connecting accounts or secrets.

    Done
  • Trust level risk gateRequired

    Trust level does not block evaluation.

    Done

Package and install checks

Needs review

Check package metadata and artifact integrity signals.

  • Install payload available

    Install or copy payload is available for review.

    Done
  • Package verification flag

    No package verification flag provided.

    Pending
  • Checksum metadata

    No checksum provided for downloaded artifact.

    Pending

Compare-driven decision checks

Needs review

Use compare context to validate trade-offs before adoption.

  • Compare tray has multiple entries

    Add at least one more entry to compare trust differences.

    Pending
  • Baseline comparison available

    No baseline peer selected yet.

    Pending
  • Diverging trust signals identified

    No major trust-signal divergence found.

    Pending

Setup at a glance

Copy & paste

Copy-ready — paste the snippet to get started.

Adoption plan

Balanced adoption plan

Current risk score 24/100. Use staged verification before broader rollout.

Risk 24

Pre-adoption checks

Validate source and review signals before any execution.

  • Confirm source provenanceRequired

    Source URL/provenance metadata is present.

    Done
  • Confirm metadata review state

    No review metadata found; increase manual validation.

    Pending
  • Verify install payload

    Install/config payload exists and can be inspected.

    Done

Security checks

Confirm safety, privacy, and package integrity signals.

  • Review safety notesRequired

    Safety notes are present.

    Done
  • Review privacy notesRequired

    Privacy notes are present.

    Done
  • Verify package integrity metadata

    No package verification/checksum metadata.

    Pending

Rollout

Adopt in controlled steps based on the selected plan.

  • Run in isolated sandbox firstRequired

    Use a constrained sandbox and observe behavior across multiple tasks.

    Pending
  • Roll out graduallyRequired

    Roll out to a small cohort before wider usage.

    Pending
  • Set monitoring and fallback

    Define rollback path and monitor errors after adoption.

    Pending

Evidence readiness

Evidence readiness matrix · balanced

Missing required evidence: Metadata review. Risk score 31.

Risk 31

Source provenance

Present

Source repository/provenance is listed.

Required in this preset

Metadata review

Missing

Review metadata is missing.

Required in this preset

Safety notes

Present

Safety notes are present.

Required in this preset

Privacy notes

Present

Privacy notes are present.

Optional in this preset

Package integrity

Missing

Package integrity metadata is missing.

Optional in this preset

Install payload

Present

Install payload is available.

Required in this preset

Required gaps: Metadata review

Decision timeline

Decision timeline · balanced

Blocking gaps: Check metadata review status. Risk 28.

Risk 28

triage

Confirm source provenanceRequired

Source/provenance metadata is available.

Done

triage

Check metadata review statusRequired

Review metadata is missing.

Pending

verify

Review safety notesRequired

Safety notes are available.

Done

verify

Review privacy notes

Privacy notes are available.

Done

verify

Validate package integrity metadata

Package integrity metadata is missing.

Pending

rollout

Verify install payload and commandsRequired

Install payload is available.

Done

Blockers: Check metadata review status

Prerequisite readiness

Prerequisite readiness

3 prerequisites to line up before setup. Includes a review or approval gate.

0/3 ready
Install & runtime1Permissions & scopes1Review & approval1

Safety & privacy surface

Safety & privacy surface

3 safety and 3 privacy notes across 4 risk areas. Review closely: permissions & scopes, third-party handling.

4 areas
  • SafetyExecution & processesPlugins and marketplaces can execute arbitrary code with the user's privileges; recommend installing only from trusted sources and reviewing the Will-install list (commands, agents, skills, hooks, MCP/LSP servers) first.
  • SafetyThird-party handlingAnthropic does not control what plugins contain and cannot verify they work as intended; the official marketplace is curated but community/third-party sources are not security-audited.
  • SafetyPermissions & scopesRecommend managed marketplace restrictions and managed scope for org-wide control, and version pinning so updates are intentional.
  • PrivacyThird-party handlingBundled MCP servers and hooks can access local files and external services; review what each component reaches before approving install.
  • PrivacyGeneralA plugin's context cost is added to every turn; factor it into the review and prefer tool-search-friendly MCP plugins.
  • PrivacyExecution & processesDo not approve plugins whose source or components you cannot inspect; treat install as a supply-chain decision.

Safety notes

  • Plugins and marketplaces can execute arbitrary code with the user's privileges; recommend installing only from trusted sources and reviewing the Will-install list (commands, agents, skills, hooks, MCP/LSP servers) first.
  • Anthropic does not control what plugins contain and cannot verify they work as intended; the official marketplace is curated but community/third-party sources are not security-audited.
  • Recommend managed marketplace restrictions and managed scope for org-wide control, and version pinning so updates are intentional.

Privacy notes

  • Bundled MCP servers and hooks can access local files and external services; review what each component reaches before approving install.
  • A plugin's context cost is added to every turn; factor it into the review and prefer tool-search-friendly MCP plugins.
  • Do not approve plugins whose source or components you cannot inspect; treat install as a supply-chain decision.

Prerequisites

  • The plugin or marketplace under review (name, source repo or URL, and what it bundles).
  • Knowledge of the team's trust policy and which scope (user, project, local, managed) is intended.
  • Claude Code available to inspect the plugin's Will-install list and context-cost estimate.

Schema details

Install type
copy
Troubleshooting
No
Full copyable content
## Content

Claude Plugin Marketplace Reviewer Agent is a reusable agent prompt for vetting a
Claude Code plugin or marketplace before a team installs it. Plugins are highly
trusted components that run with the user's privileges, so this agent reviews
source trust, bundled components, context cost, the will-install list, version
pinning, and managed-scope controls.

Use it before adding a marketplace or installing a plugin for a project or
organization.

## Agent Prompt

You are a plugin and marketplace reviewer for Claude Code. Decide whether a plugin
is safe and worthwhile to install, and at what scope, using the official Claude
Code discover-plugins documentation as your reference. Default to caution for
non-official sources.

Review workflow:

1. Source trust. Identify the marketplace: the official `claude-plugins-official`
   is curated by Anthropic; the community marketplace passes automated validation
   and safety screening; arbitrary git/URL sources are neither. Treat install as a
   supply-chain decision and only proceed from trusted sources.
2. Will-install review. Inspect the plugin's Will-install list: commands, agents,
   skills, hooks, and MCP/LSP servers. Flag hooks, MCP servers, and bundled
   executables that run with user privileges.
3. Component reach. For bundled MCP servers and hooks, assess what local files and
   external services they can reach; recommend disabling components you do not
   need.
4. Context cost. Read the plugin's context-cost estimate; a plugin adds tokens
   every turn, and MCP plugins cost more when tools are not deferred by tool
   search.
5. Scope and pinning. Recommend the narrowest scope (user, project, local, or
   managed), version pinning so updates are intentional, and auto-update settings
   that match the team's risk tolerance.
6. Org controls. For organizations, recommend managed marketplace restrictions
   and managed scope so only approved marketplaces and plugins are installable.
7. Decision. Approve at a scope, approve with components disabled, or reject.

Output contract:

- Plugin summary: source, marketplace, bundled components, context cost.
- Findings: untrusted source, risky components, high context cost.
- Recommended scope, pinning, and disabled components.
- Decision: approve, approve with limits, or reject.

## Features

- Assesses marketplace and plugin source trust.
- Reviews the will-install component list and their reach.
- Factors in context cost and version pinning.
- Recommends scope and managed-marketplace controls.

## Use Cases

- Vet a third-party plugin before a team installs it.
- Review a marketplace before adding it org-wide.
- Decide install scope and which components to disable.
- Enforce managed marketplace restrictions for an organization.

## Source Notes

- Claude Code marketplaces include the curated official marketplace, a
  safety-screened community marketplace, and arbitrary git/URL sources that are
  not audited; plugins run arbitrary code with user privileges.
- The plugin manager shows a Will-install list and a context-cost estimate, and
  organizations can apply managed marketplace restrictions and managed scope.

## Duplicate Check

The content tree and open PRs were checked for plugin marketplace, plugin review,
and plugin governance agents. This entry is distinct from plugin-dependency review:
it is an `agents` prompt focused on reviewing a plugin or marketplace's trust and
contents before install.

## Editorial Disclosure

Submitted as an independent community agent entry by `JPette1783`, based on
public Claude Code documentation. No paid placement, referral, or affiliate
relationship.

## Sources

- Discover and install plugins: https://code.claude.com/docs/en/discover-plugins
- Claude Code plugins documentation: https://code.claude.com/docs/en/plugins
- Claude Code features overview: https://code.claude.com/docs/en/features-overview

About this resource

Content

Claude Plugin Marketplace Reviewer Agent is a reusable agent prompt for vetting a Claude Code plugin or marketplace before a team installs it. Plugins are highly trusted components that run with the user's privileges, so this agent reviews source trust, bundled components, context cost, the will-install list, version pinning, and managed-scope controls.

Use it before adding a marketplace or installing a plugin for a project or organization.

Agent Prompt

You are a plugin and marketplace reviewer for Claude Code. Decide whether a plugin is safe and worthwhile to install, and at what scope, using the official Claude Code discover-plugins documentation as your reference. Default to caution for non-official sources.

Review workflow:

  1. Source trust. Identify the marketplace: the official claude-plugins-official is curated by Anthropic; the community marketplace passes automated validation and safety screening; arbitrary git/URL sources are neither. Treat install as a supply-chain decision and only proceed from trusted sources.
  2. Will-install review. Inspect the plugin's Will-install list: commands, agents, skills, hooks, and MCP/LSP servers. Flag hooks, MCP servers, and bundled executables that run with user privileges.
  3. Component reach. For bundled MCP servers and hooks, assess what local files and external services they can reach; recommend disabling components you do not need.
  4. Context cost. Read the plugin's context-cost estimate; a plugin adds tokens every turn, and MCP plugins cost more when tools are not deferred by tool search.
  5. Scope and pinning. Recommend the narrowest scope (user, project, local, or managed), version pinning so updates are intentional, and auto-update settings that match the team's risk tolerance.
  6. Org controls. For organizations, recommend managed marketplace restrictions and managed scope so only approved marketplaces and plugins are installable.
  7. Decision. Approve at a scope, approve with components disabled, or reject.

Output contract:

  • Plugin summary: source, marketplace, bundled components, context cost.
  • Findings: untrusted source, risky components, high context cost.
  • Recommended scope, pinning, and disabled components.
  • Decision: approve, approve with limits, or reject.

Features

  • Assesses marketplace and plugin source trust.
  • Reviews the will-install component list and their reach.
  • Factors in context cost and version pinning.
  • Recommends scope and managed-marketplace controls.

Use Cases

  • Vet a third-party plugin before a team installs it.
  • Review a marketplace before adding it org-wide.
  • Decide install scope and which components to disable.
  • Enforce managed marketplace restrictions for an organization.

Source Notes

  • Claude Code marketplaces include the curated official marketplace, a safety-screened community marketplace, and arbitrary git/URL sources that are not audited; plugins run arbitrary code with user privileges.
  • The plugin manager shows a Will-install list and a context-cost estimate, and organizations can apply managed marketplace restrictions and managed scope.

Duplicate Check

The content tree and open PRs were checked for plugin marketplace, plugin review, and plugin governance agents. This entry is distinct from plugin-dependency review: it is an agents prompt focused on reviewing a plugin or marketplace's trust and contents before install.

Editorial Disclosure

Submitted as an independent community agent entry by JPette1783, based on public Claude Code documentation. No paid placement, referral, or affiliate relationship.

Sources

Source citations

Add this badge to your README

Show that Claude Plugin Marketplace Reviewer Agent is listed on HeyClaude. Paste this Markdown into your README — it renders the badge and links back to this page.

Listed on HeyClaude
[![Listed on HeyClaude](https://heyclau.de/badge/agents/claude-plugin-marketplace-reviewer-agent.svg)](https://heyclau.de/entry/agents/claude-plugin-marketplace-reviewer-agent)

How it compares

Claude Plugin Marketplace Reviewer Agent side by side with 2 alternatives on trust, install, platform support, and disclosed safety notes — all from reviewed registry metadata.

1 trust signal differ across this comparison (Submitter).

Field

A reusable agent prompt that vets a Claude Code plugin or marketplace before a team installs it. It walks source trust, the plugin's Will-install list and bundled components (skills, agents, hooks, MCP servers, commands), the context-window cost, version pinning, and the user/project/local/managed install scope.

Open dossier

A Claude agent persona for building and publishing Claude Code plugins: bundling commands, agents, hooks, and MCP servers into a plugin and distributing it through a plugin marketplace.

Open dossier

Source-backed Claude Code subagent prompt for reviewing Agent Skills before adoption or publication, checking SKILL.md scope, descriptions, invocation control, supporting files, tool permissions, helpfulness, safety, and privacy risks against official Claude Code skills guidance.

Open dossier
Next steps
Trust
Review statusNot reviewedNot reviewedNot reviewed
Package trustPackage not verifiedPackage not verifiedPackage not verified
Source provenanceSource-backedSource-backedSource-backed
SubmitterDiffersJPette1783Desel72
Install riskReview firstReview firstReview first
Notes Safety ✓ Privacy ✓ Safety ✓ Privacy ✓ Safety ✓ Privacy ✓
Brand
Categoryagentsagentsagents
SourceSource-backedSource-backedSource-backed
AuthorJPette1783JSONboredDesel72
Added2026-06-052025-10-252026-06-08
Platforms
Harness
Source repo
Safety notesPlugins and marketplaces can execute arbitrary code with the user's privileges; recommend installing only from trusted sources and reviewing the Will-install list (commands, agents, skills, hooks, MCP/LSP servers) first. Anthropic does not control what plugins contain and cannot verify they work as intended; the official marketplace is curated but community/third-party sources are not security-audited. Recommend managed marketplace restrictions and managed scope for org-wide control, and version pinning so updates are intentional.This is an agent persona (prompt guidance), not executable code, but the plugins it designs bundle hooks and MCP servers that run commands with your permissions; review bundled hooks and tools before installing a plugin from any marketplace.This agent reviews skill quality and adoption readiness; it does not execute the skill, install plugins, run scripts, or approve production rollout by itself. Flag skills that can perform writes, deployments, destructive actions, account changes, network calls, credential handling, or background automation without explicit user control. Recommend `disable-model-invocation: true`, least-privilege `allowed-tools`, or additional human review when a skill has side effects or could trigger too broadly. Treat supporting files, shell injection blocks, and bundled scripts as executable or instruction-bearing review surfaces, not harmless documentation.
Privacy notesBundled MCP servers and hooks can access local files and external services; review what each component reaches before approving install. A plugin's context cost is added to every turn; factor it into the review and prefer tool-search-friendly MCP plugins. Do not approve plugins whose source or components you cannot inspect; treat install as a supply-chain decision.Plugins installed from third-party marketplaces run in your environment and can read local files or call external services; vet the marketplace source and a plugin's MCP servers before adding it.Reads local skill instructions and supporting files, which may expose internal workflow names, repository paths, policies, examples, customer data, or credentials accidentally written into prompts. Review output can mention sensitive skill names, tool permissions, file paths, dynamic commands, and risk findings; keep it out of public PR comments unless sanitized. Skills loaded by Claude can place their descriptions or full instructions into model context, so the review should flag secrets and unnecessary confidential details before adoption.
Prerequisites
  • The plugin or marketplace under review (name, source repo or URL, and what it bundles).
  • Knowledge of the team's trust policy and which scope (user, project, local, managed) is intended.
  • Claude Code available to inspect the plugin's Will-install list and context-cost estimate.
— none listed
  • One or more Agent Skill directories with a `SKILL.md` file and any referenced supporting files.
  • Access to the skill's intended user, task boundary, invocation path, and expected output.
  • A clear policy for whether the skill may be model-invoked automatically or must be user-invoked.
  • Permission to inspect tool restrictions, dynamic context commands, scripts, examples, templates, and bundled plugin metadata if present.
Install
Config
Citations
ClaimUnclaimedUnclaimedUnclaimed
Open 3 picks in the interactive comparison tool

Related guides

Signals

Loading live community signals…

More like this, weekly

A short, calm digest of reviewed Claude resources. Unsubscribe any time.