Pre-install safety check
A mod is both a productivity feature and a new attack surface. Read first, then install.
What a mod can reach
Section titled “What a mod can reach”A loaded mod can do the following.
- Read and write files, run programs, and send network requests as you.
- Read environment variables and settings files, including any API keys you keep there.
- See and change every prompt and tool call, and submit prompts as if you typed them.
- Approve tool calls before they ask you. It can even approve calls blocked by an
askrule or yourPreToolUsehook. - Call models with your plan or API key.
A mod cannot change what the permission prompt shows. Even with the sandbox on, only the Bash that Claude runs is isolated. Processes started by a mod run outside it.
Ask before installing
Section titled “Ask before installing”- Does this mod solve a problem you actually have?
- Wouldn’t a settings hook or skill be enough?
- Is the source public and maintained?
- Can you trust the marketplace?
- Does it really need network access, process execution, file writes, or environment variable reads?
- Does it change or approve prompts or tool calls?
- Is it OK to use in a session with company code and secrets?
Calls to look for in the source
Section titled “Calls to look for in the source”Don’t trust the README alone. Open .claude-plugin/marketplace.json, plugin.json, hooks/hooks.json, and the hook modules. Then run validation.
claude plugin validate ./some-modIn the output, the hooks: line lists the events the mod receives, and the calls: line lists the APIs it calls. A gating hook line points to a hook that can reject something.
| Call | What it does | Risk |
|---|---|---|
$.http.fetch |
Network request | Leaking code or prompts |
$.process.run, $.process.spawn |
Run a program | Arbitrary execution outside the sandbox |
$.fs.write |
Write a file | Tampering with files |
$.env.get, $.settings.read |
Read environment variables and settings | Exposing API keys |
$.prompt.submit, $.prompt.fill |
Submit or fill a prompt | Giving work instructions without you knowing |
$.model.complete, $.model.fork |
Call a model | Using up your quota |
$.tool.register |
Add a tool the model can call | Disguising what a tool does |
Access levels in the community catalog
Section titled “Access levels in the community catalog”This site’s mod directory shows the access scope that the community catalog’s validator read from each mod, in four levels.
| Level | Meaning |
|---|---|
| Display and memory only | It draws on screen and remembers only its own state |
| Read | It reads files, environment variables, conversation history, and the like |
| Write and execute | It writes files or runs processes |
| Network | It sends requests outside |
Rules of thumb
Section titled “Rules of thumb”- Try low-risk mods in a personal experiment repository.
- Put mods through a security review before using them in company repositories.
- Avoid network mods in repositories that hold secrets.
- If a mod sends requests to another provider, check its terms and data flow.
- Avoid unknown marketplaces.
If something goes wrong, use the steps to turn mods off.
Unofficial community guide. Not affiliated with or endorsed by Anthropic. Claude and Claude Code are trademarks of Anthropic.