I'm Lena. I always use Claude to do my jobs.
Claude marketplace plugins can change more than the answer you see in chat: some connect services or run code. I would treat the first installation as a reversible trial: find one, inspect it, add it, test with disposable material, then remove it if its behavior or permissions do not make sense. A directory listing is no safety guarantee.
What Claude Plugin Marketplaces Contain
Claude's directory brings skills, connectors, and plugins into one Customize area. Skills supply instructions; connectors link services; plugging package capabilities for a workflow. Anthropic-built marketplaces, repository sources, organization-managed collections, and partner-built plugins have different publishers and controls. The label “Claude plugin marketplace” alone says little about who maintains an individual plugin.
Claude Marketplace on the web is a browsable site; the marketplace you add in Claude is a source catalog. A web listing does not enable a plugin.
Skills and commands can work in chat, Cowork, and Claude Code under the same Claude account. Hooks and sub-agents run in Cowork and Claude Code; local MCP servers can run on your computer there. Claude Desktop plugins you add are saved to your account, beyond one installation.
Find One Plugin in the Directory
Open the Claude plugin directory in Claude Desktop through Customize → Plugins → Discover. The official directory guide distinguishes Discover listings from a colleague's direct share, which appears under Shared with you. Choose one narrow task you can check yourself, such as turning a public note into a draft outline. Open the detail page before selecting Add.
If it is missing, your organization may limit the catalog. Confirm its exact name and source rather than picking a similar result.
Inspect Its Source and Capabilities
Review Skills, Commands, Hooks, and MCP Servers
Read the description and available files before installation. Skills and commands shape instructions; sub-agents take on tasks; hooks run at workflow events; MCP servers provide tools. Check triggers, files, services, and any ability to write, send, or delete data. Review connector access separately. Anthropic warns that a local MCP server may run with your user-account permissions.
For Claude plugin permissions, I would note the smallest expected access before clicking Add: service, folder, and whether read access suffices. Summarizing one public page should not require an entire private drive or permission to send messages. If the detail page leaves this unclear, inspect the publisher's documentation or ask your team's owner.
For repository sources, inspect plugin files and recent changes. The manifest identifies the package; skills, hook definitions, and MCP configuration show what it may do. If those files are unavailable or opaque, I would choose another plugin. The OWASP agentic security guidance identifies tool misuse and excess privilege as risk categories; it does not judge this plugin.
Check Who Published and Manages It
Look for a named publisher, repository owner, maintenance history, and problem-reporting route. Anthropic-built, organization-managed, colleague-uploaded, and third-party plugins warrant separate trust decisions. Approval or optional scanning cannot prove safety. If the maintainer is unclear or access exceeds your task, stop.
Add and Test the Plugin on a Low-Risk Task
Select Add. In a new chat or Cowork task, use a short, non-sensitive sample: “Turn these fictional meeting notes into five action items. Do not access accounts, edit files, or send messages.” Find its skill through / or +, then compare output with input. Cowork commands may use /plugin-name:command.
This is a proposed test, not a hands-on result. Watch for sign-in prompts, tool requests, and scope changes. Grant only necessary access; stop at unexplained account or write permissions. Check for invented details and unintended changes. One clean response cannot certify sensitive use.
Keep the acceptance check simple: the output should contain five actions drawn only from the fictional notes, with no new names or commitments. If it fails, save the prompt and observed behavior, disable or remove the plugin, and report the issue to its maintainer. That small record is more useful than a vague claim that the plugin “worked.”
Disable or Remove What You Do Not Need
Return to Customize → Plugins. Turn the plugin off if that control is available; to take one you added off your account, open it and select Remove. Removing its marketplace is a separate action, so check which item you selected.
Review connected-service permissions separately: plugin removal does not prove an external authorization was revoked. Recheck tools and publishers after a material update.
Understand Organization Controls
On Team and Enterprise, owners can offer organization plugins, install them by default, or require them. Members can turn off default-installed plugins but cannot disable or remove required ones. Enterprise groups may see different selections. Members cannot edit organization-managed plugins; raise concerning capabilities with an owner.
Claude organization plugins may therefore appear in your installed list without you selecting Add. Before a first run, inspect them by the same standard as personal installs. An organization's decision to distribute a tool establishes who manages availability; it does not tell you whether a particular customer document is suitable test data.
The Claude plugin usage documentation separates marketplace installs from direct sharing. Account-saved plugins can sync into supported Claude Code sessions using the same Claude login; API-key or cloud-provider sign-in does not use that sync. Hooks and MCP servers may then run locally, even if your first trial was in chat.
FAQ
Which Claude plans currently include plugin marketplaces?
Anthropic lists Pro, Max, Team, and Enterprise. The catalog may depend on organization policy.
Can an individual share a marketplace plugin with a colleague?
No. On Team or Enterprise, you may share a plugin you created or uploaded if an owner enabled sharing, but not a marketplace install.
How are plugin updates delivered after installation?
It depends on the source. Managed plugins update through upload or repository sync; members get changes at next session or refresh, and Claude Code at startup. Direct shares update for next use. Check the version; schedules differ.
Can users add a marketplace from a Git repository?
Yes. Choose Customize → Plugins → Add → Add marketplace → Add from a repository. Claude accepts a GitHub URL or owner/repo, plus public GitLab or Bitbucket repositories. Inspect the source first.
Does the same plugin appear in Claude Desktop and Claude Code?
Yes, with the same account and supported Claude Code version. Components differ: hooks, sub-agents, and local MCP servers run outside ordinary chat. Start with the smallest task and permissions you need.
Previous Posts:
- If your Claude marketplace plugin also appears in Claude Code, Claude Code Opus 5.5 setup shows how to verify the active environment, keep permissions visible, and test changes inside a bounded, reversible workflow.
- Before allowing a plugin to call tools, connect services, or run local components, agentic AI security solutions explains how permissions, identity, tool access, approval gates, and monitoring affect agent safety.
- To understand why a plugin is more than a prompt or UI add-on, DeepSeek harness plugin architecture separates models from plugins, tools, sessions, and the runtime layer that actually executes agent capabilities.




