Is This Claude Code Plugin Safe to Install?
A Claude Code plugin can run real code on your machine. Here is what it can touch, how to check one before you install it, and how to remove it.
Evgenii Arsentev · PhDReviewed for accuracy by Evgenii Arsentev, PhD · 2026-09-30
A Claude Code plugin can run real code on your machine, with your own user permissions, the moment it turns on. Anthropic says this outright in its own docs, not as a warning label nobody reads. So before you run one install command, it is worth knowing exactly what you are letting in.
I run a small team, and we install plugins the same casual way most people do, fast, mid-task, because someone in a thread said it was useful. This guide is basically me slowing that habit down for myself first.
What can a Claude Code plugin actually touch on your computer?
A plugin is not one simple thing. It is a folder that can hold hooks, MCP or LSP servers, a bin directory full of executables, and skills or commands that Claude reads as instructions. Each piece behaves differently once it is on your machine.
Hooks are shell commands that fire on their own, at set points in a session, for example right after Claude edits a file. An MCP server is a process the plugin starts and keeps running in the background while you work. Anything sitting in the plugin's bin folder gets added to the same PATH that Claude's own Bash commands use, so Claude can run those programs too, without you writing a line of code.
Here is the part I did not expect: Claude Code's permission prompts and its sandbox cover the tool calls Claude makes, not what a hook or a server does by itself. A hook runs with your full user permissions, outside the sandbox entirely. So the safety net you already trust for Claude's own actions does not automatically extend to a plugin's own code.
Skills, commands and agents are the mild case. They just enter Claude's context as extra instructions, so at most they steer what Claude does with tools it already has permission to use.
Does the marketplace name tell you a plugin is safe?
Not on its own. A marketplace is only the catalog a plugin comes from, and its name tells you who publishes that catalog, not what any single plugin inside it does. Anthropic keeps an official tier and a community tier, both locked to its own GitHub repositories, and everything else, including a marketplace your coworker or your own company runs, counts as third party. The advice stays the same whichever tier a plugin comes from: review it before you install it.
How do you know if a Claude Code plugin is safe before you install it?
Claude Code actually gives you a way to look first, and it takes a few minutes, not an afternoon. Start in your shell with a command that shows where a marketplace really comes from.
claude plugin marketplace list
Prints the source behind every marketplace you have added, a GitHub repository or a plain local folder, so a name alone never has to be enough.
Inside a session, open /plugin and select the plugin itself. The details pane has a Will install section listing every command, skill, agent, hook and server it adds, plus a context cost estimate for official plugins, meaning how many tokens it quietly adds to every message you send. I look at that number the same way I look at any other recurring line in my company's bills.
For anything past the summary, open the plugin's GitHub page from that same pane and read the real files, hooks/hooks.json for what a hook runs and .mcp.json for what a server connects to. If you want the full picture before starting a session at all, clone the repository and run claude --plugin-dir on it together with the plugin details command, and it prints a component inventory without loading anything into a live conversation.
What about scope, and how do you remove a plugin you stop trusting?
When you install, you also pick a scope: user, which follows you into every project on the machine, project, which turns on for everyone in that repository, or local, which stays yours alone in that one repository. Pick the narrowest one that actually solves your problem.
Removing a plugin is one command, claude plugin uninstall, run with the scope you installed it at. Its files stay cached on disk for 14 days afterward, so delete the plugin's folder under ~/.claude/plugins/cache yourself if you want it gone sooner. And if you stop trusting the marketplace itself, remove that too, because it takes every plugin you got from it down with it.
Anthropic's own install warning says it plainly: it does not control what a plugin contains and cannot verify that it works as intended or will not change later. My rule for my own team is boring, and that is the point. Nobody installs a plugin mid-task just to get unblocked. Read the Will install pane first, every single time, even for a plugin a colleague already swears by.
A quick safety check before you install
- 1Open /plugin, select the plugin, and read its Will install section before anything else.
- 2Run claude plugin marketplace list to see the real source behind the marketplace name.
- 3For anything unfamiliar, open its GitHub page and read hooks/hooks.json and .mcp.json yourself.
- 4Install at the narrowest scope that solves your problem, local or project rather than user.
- 5If you stop trusting it, run claude plugin uninstall, and remove the marketplace too if you stop trusting that as well.
Lab: read a plugin before you trust it
0/4None of this means plugins are dangerous by default. Most of what sits in Anthropic's own official marketplace does exactly what its listing says. It just means a plugin is code and not a menu item, so it earns the same couple of minutes of attention you would give any script before running it on your own machine.
Free course
Stop reading about AI — start building with it
The free Claude Code course: your first site, tool or game — no coding. No upsells, no cross-sells — nothing to buy here.
Start free →
Author
Evgenii Arsentev
PhD · Chief Executive Officer, digital health
Reading is a good start
Want to actually build this?
Guides explain. The free course transforms — personalized, gamified, and built to get you shipping fast.
Start the free course →