Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Claude Code plugins are software packages, not just prompt templates. Depending on their components, an enabled plugin can supply instructions, expose tools, start processes, and run handlers automatically. Anthropic warns that an installed plugin can execute arbitrary code on your machine with your user privileges; Claude Code’s permission rules and sandbox do not automatically contain every process a plugin starts. Anthropic’s plugin security guidance explains the distinction.
What a Claude Code plugin contains
A plugin is a directory of components that Claude Code installs and loads as a unit. A plugin manifest is typically stored at .claude-plugin/plugin.json. Plugins are often obtained through marketplaces, which are catalogs that identify plugins and where to fetch them. The package may include skills, agents, hooks, MCP servers, and other supported components. Anthropic’s plugins overview describes the format and component types.
- Skills add task instructions.
- Agents define subagent behavior.
- Hooks register handlers that run at configured lifecycle events.
- MCP servers contribute tools Claude Code can make available.
The practical effect is not limited to a command you choose to invoke. An enabled plugin is part of every applicable session: the names and descriptions of its invocable skills, agents, and commands enter Claude’s context on each turn, while full instructions load when those components are used. Its hooks and MCP server processes also operate in sessions where the plugin is enabled. This can affect the session even when you do not deliberately invoke every component. See the plugins overview.
What an enabled plugin can access and do
The exact capabilities depend on the plugin’s components and configuration. Anthropic’s warning is deliberately broad: “A Claude Code plugin you install can execute arbitrary code on your machine with your user privileges.” That is a statement in Anthropic’s official plugin security documentation, not a guarantee that every plugin performs every action below.
Recommended Free Tools
#1 Best Overall
- Run lifecycle handlers. Hooks can run shell commands at events such as before or after tool calls. Their configured event and matcher determine when they run. The hooks reference lists supported events and handler types.
- Run JavaScript inside Claude Code. A mod can run with the user’s permissions. Anthropic’s security guidance identifies mods as a route for plugin code to act.
- Start server processes. Claude Code connects to MCP servers declared by an enabled plugin, making their tools available; stdio MCP servers run as processes started on the machine. Declared language servers are also started by Claude Code. The plugin security page explains these execution paths.
- Expose executables to Bash. An enabled plugin’s
bin/directory is added to the Bash tool’sPATH, so Bash commands can invoke executables from it. See Anthropic’s security guidance. - Steer Claude through instructions. Skills, commands, and agents can add instructions to Claude’s context and influence how it uses tools already available to it. Anthropic describes this as a plugin security consideration.
- Change after review. Marketplace auto-update can change plugin files after installation, so a one-time code review may not cover later versions. Review the update behavior as well as the initial files.
How permissions and sandboxing apply
Claude Code’s controls distinguish between actions Claude requests through its tools and code a plugin starts on its own. Permission rules apply to Claude’s tool calls, including calls to plugin MCP tools and Bash commands that invoke plugin executables. But Anthropic says command hooks execute shell commands with full user permissions, while hooks, MCP servers, and processes started by a mod run outside the sandbox. The sandbox and tool permission rules therefore do not automatically wrap every plugin process. Anthropic’s plugin security documentation sets out this boundary.
| Action path | What the controls cover | Practical implication |
|---|---|---|
| Claude makes a tool call, including a plugin MCP-tool call or a Bash call to a plugin executable | Permission rules apply to the tool call. The active session mode and settings determine how actions are reviewed. Anthropic’s security documentation; plugin security guidance. | Review and configure tool permissions, but do not treat them as a review of every plugin process. |
| Plugin-started command hook, MCP server, or mod process | These processes run outside Claude Code’s sandbox; command hooks execute with full user permissions. Anthropic’s plugin security documentation. | Inspect the code and launch configuration directly; a sandbox setting does not automatically contain these processes. |
Session modes still matter for tool calls
Anthropic’s current security documentation describes Auto mode as using a separate classifier to review actions and block ones it judges unsafe; explicit ask and deny rules still apply. In Manual mode, Claude Code starts with read-only permissions and asks before editing files, running tests, or executing commands. Users and organizations configure permissions. See Anthropic’s security documentation.
Rank #2
An approval prompt is not a full audit of plugin code. Anthropic also notes that a Bash command a user approves may have broader operating-system access than file tools bounded to the working directory. Authentication and permissions and the security guide cover permission controls and their context.
Why hook timing changes what a hook can prevent
Hooks are handlers that Claude Code runs automatically at configured lifecycle events. The hooks reference documents shell commands, HTTP endpoints, MCP tool calls, LLM prompts, and subagents as handler types, with events that can occur per session, per turn, or around tool calls. Read the hooks reference.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Rank #3
| Hook point | When it runs | What it can accomplish |
|---|---|---|
PreToolUse |
Before a tool call | Can block the call before it runs. |
PostToolUse |
After a successful tool call | Can provide feedback or alter the result Claude sees, but cannot undo side effects that have already occurred. |
Anthropic explicitly notes that replacing or filtering post-tool output does not reverse files written, commands executed, or network requests sent. A pre-tool hook can be a gate; a post-tool hook is not a rollback mechanism. See the hook event details and post-tool behavior.
How to assess a plugin before installing it
- Check who provides the marketplace. Marketplace names identify who publishes the catalog, not whether every listed plugin is safe. Anthropic distinguishes official, community, and third-party marketplaces, and recommends evaluating plugins rather than relying on category alone. Plugin security and trust.
- Open the plugin details view. In Claude Code, use
/pluginand inspect the details pane for commands, agents, skills, hooks, MCP servers, and LSP servers. Some local or custom marketplace entries may not show a complete component summary before installation. Install and manage plugins. - Read the actual configuration and code. Check hook commands, scripts, server launch commands, executables, and instructions that could steer Claude. Anthropic recommends reviewing a plugin before installation. Plugin security and trust.
- Choose scope deliberately. User scope enables a plugin across projects for that user on the machine; project scope shares enablement with repository collaborators; local scope limits it to the user’s repository context. The install and manage guide.
- Check marketplace update behavior. If auto-update is enabled, files may change after your initial review. Consider the update source and policy alongside the current plugin contents. Plugin security guidance; plugin installation guidance.
- Match safeguards to the repository’s sensitivity. Review proposed commands and code, use narrow permissions and organization-managed settings where appropriate, and consider a VM or sandbox for untrusted content. The controls are useful, but they do not replace direct review of code that runs outside the sandbox. Security; Authentication and permissions.
What a plugin approval prompt does not tell you
Installing or enabling a plugin should not be treated as a guarantee that all of its behavior will be individually presented for approval. A plugin can combine context instructions, tools, automatic hooks, and processes; some components may act without a direct invocation. The meaningful security boundary is the combination of what the plugin contains, when it runs, which processes it starts, and which tool calls Claude makes. Anthropic’s plugin security guidance and security documentation describe those separate paths.
Rank #4
Claude Code’s documentation is living documentation and may change. The distinctions above reflect Anthropic’s official plugin, security, hooks, installation, and permissions pages checked on October 4, 2026: plugins, plugin security, hooks, installation, security, and permissions.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




