Steve's AI Guide
The path · ten guides, in order 01The Prompting Guide45 min 02Claude Beginner35 min 03Claude Advanced50 min 04Claude in Action30 min 05Claude Code 2.040 min 06Claude Design35 min 07Claude in Office30 min 08Claude Writing25 min 09Claude Everywhere20 min 10Claude PluginsNEW15 min The apps KeyroomResidential real estate BoardroomCommercial real estate ToolroomBuilders & GCs RighthandNEWExecutive assistants RecallNEWStudents More Prompt Trainer What’s new People I learn from Back to all guides →
Guide 10 of 10 Claude Plugins All guides →
NEW . WHAT TO INSTALL, WHAT TO SKIP

Claude Plugins

What to install, what to skip.

A plugin can make Claude useful for your job in one click. It can also hand a stranger's instructions the keys to your inbox. You can tell the two apart without reading code, if you know what a plugin is made of, where it came from, and five questions to ask before you click Add.

What's Inside

1
Step 1

What a Plugin Is

Instructions plus access. The access is the part to watch.

Anthropic describes a plugin as a package that bundles skills, connectors, and sub-agents, so Claude is set up for a job from the first conversation. Plugins are on every paid plan, and they work in Claude on the web and in the desktop app.

The word "plugin" hides four different things. They do not carry the same risk.

PartWhat it isWhat it can touch
SkillWritten instructions Claude follows for a taskNothing by itself. It steers what Claude does with the access Claude already has.
CommandA shortcut you type, like /monday-briefSame as a skill. It starts one.
ConnectorA link to one of your accounts: Gmail, Drive, QuickBooksWhatever your own login can see and do in that account.
Local server or hookA small program that runs on your computerAnthropic's wording: it runs "with the same permissions as any other program you run."
The Rule A plugin is as safe as the most powerful thing inside it. Three skills and nothing else is a low-stakes install. Three skills plus a connector to your email is a decision.
2
Step 2

Where Plugins Come From

Four doors. Each one tells you how much checking was done before you arrived.

Open Customize in the sidebar, then the Plugins tab. Everything starts there.

1. The directory

The Discover tab. Each listing names its publisher ("by Anthropic", "by Figma") and shows an install count. Since September 25, 2026, new submissions go through Anthropic's portal, where each one is validated and safety-scanned, then reviewed before it is listed.

2. A marketplace you add

Add, then Add marketplace, then a repository address. This pulls plugins straight from someone's GitHub. Nobody reviewed them except the author.

3. A file someone sent you

Add, then Upload plugin, which takes a .zip or .plugin file. The upload screen itself warns that Anthropic has not checked the file. Same trust level as an email attachment from that person.

4. One you build

Add, then Create with Claude. You know exactly what is in it, because you asked for it. The Advanced guide covers building.

Review Lowers the Risk. It Does Not Remove It. A directory listing passed a scan on the day it was approved. Anthropic's own help page still says to install plugins only from sources you trust, and to review any plugin from outside Anthropic before you turn it on.
3
Step 3

The Five-Minute Check

Five questions before you click Add. None of them needs code.
3.1

Who published it?

Read the name on the listing and search for it. A company with customers, or a person with a public history, has something to lose. A name you cannot find anywhere else does not.

3.2

What is inside?

Open the listing and count the parts from Step 1. Skills and commands only: low stakes. A connector: read 3.3. Anything that runs on your computer: stop unless you would let this publisher install software on your laptop.

3.3

What can it reach?

Name each account it connects. Then finish this sentence: "If this plugin did the worst thing possible with that access, I would lose ___." If the blank is a client list or a bank login, the plugin needs to be worth it.

3.4

Can you read it?

Skills are plain text files, usually a page or two. If the plugin lives on GitHub, open them. You are looking for three things: instructions to send data somewhere, instructions to delete, and any line telling Claude to ignore what you say.

3.5

What happens when it changes?

A plugin can change after you install it. Anthropic's help page says that when an author updates a shared plugin, recipients "automatically get the updated version at next use." The publisher you trusted on install day is the publisher you are trusting on every day after it.

Then Run It Carefully Once First run: keep Claude on Manual so it asks before each action. For a plugin with no connectors, point it at a folder with nothing sensitive in it. For a plugin with connectors, the folder does not limit what it can reach, so read every action before you approve it, sends above all. A plugin that asks for more than its description promised fails the test.
4
Step 4

Choosing Connectors

Thousands are listed. You need about five.

The Connectors tab listed 4,287 on October 5, 2026. Four rules cover the choosing.

  • Prefer the one the service publishes. The Gmail connector says "by Google." The Canva connector says "by Canva." When the company that holds your data also wrote the connector, there is no third company in the middle.
  • Connect for a task, not for completeness. Every connected account is one more place a bad instruction can reach. Add a connector the day a workflow needs it.
  • Your existing permissions still apply. Anthropic's small-business launch put it plainly: if an employee cannot see something in QuickBooks or Google Drive today, they cannot see it through Claude.
  • Disconnect what you stopped using. Review the Yours list once a quarter. Step 8 shows how.
Why This Matters More Than It Looks An attack needs three things at once: private data, untrusted content, and a way to send something out. One connector can supply all three. An email connector holds your private data, reads messages from strangers, and can send. The Prompting Guide, Section 11 walks through the four habits that break the chain.
5
Step 5

Updates, and What Plugin4Shell Taught

The plugin you installed in March is not guaranteed to be the plugin you are running in October.

On September 17, 2026, the security firm Air Security published a flaw it named Plugin4Shell. It affected four coding agents, Claude Code among them. Whoever controlled a plugin's repository could swap in different code during an automatic update, while the setting meant to lock the plugin to one approved version appeared to hold.

According to the report, Anthropic fixed it in Claude Code 2.1.179. Not every vendor had shipped a fix when the report came out. If you use the Claude app and never Claude Code, this flaw did not reach you.

The technical detail matters less than the three habits it argues for, and those apply to everyone.

  • Keep the app current. A fix only protects you if you have it. Update Claude Code and the desktop app when they ask.
  • Install fewer plugins. Each one is a publisher who can change what runs on your account. Five plugins you use are safer than twenty you tried once.
  • Remove what you are not using. A plugin that is not installed cannot change underneath you.
6
Step 6

Claude Code Mods: Wait

New in October 2026, and the most powerful thing a plugin can carry.

A mod is a small program, shipped inside a plugin, that changes how Claude Code itself works. It can rewrite a prompt, add a panel, or replace a built-in feature. Mods arrived on October 1, 2026.

Mods are not sandboxed, Anthropic says. They run with the same access to your machine as Claude Code, and its advice is to install them only from sources you trust, the way you would any software.

For Most Readers of This Guide If you only use the Claude app, mods do not apply to you. If you use Claude Code, skip mods unless the publisher is Anthropic or someone you would trust alone with your laptop while you are signed in. Nothing in the other guides needs one.
7
Step 7

A Starter Set

What I would install first, with the check already run.
PluginPublisherWhat is insideUse it for
Claude for Small BusinessAnthropic43 workflows plus connectors to accounting, CRM, and payments. Each workflow starts in approval mode.Weekly briefs, proposals, month-end close. See the crosswalk.
Anthropic's role pluginsAnthropicSkills for one job: Data, Design, Engineering, Legal, and others.A head start in your own field. Find them under Discover.

Mine

I wrote these, and the four larger ones each have a page here. Apply the same five questions to them.

8
Step 8

Turning One Off, Removing One

Thirty seconds, and worth doing the moment you have a doubt.
8.1

Turn it off first

Go to Customize, then Plugins, then Yours. Each plugin has a Turn off button. Off means Claude stops using it, and you can turn it back on later. Use this when you are unsure.

8.2

Remove it

Same list. Open the three-dot menu beside the plugin and choose Remove.

8.3

Close the doors it opened

Removing a plugin does not always disconnect the accounts it used. Open the Connectors tab, check Yours, and disconnect any you no longer need. Then remove Claude's access inside the service too. For a Google account, that list is under third-party connections in your account's security settings.

8.4

Check what it left running

Open Scheduled in the sidebar. Delete any recurring task the plugin set up that you no longer want.

The Checklist Before you add: who published it, what is inside, what it can reach, can you read it, what happens when it changes. First run on Manual. Turn a plugin off at the first doubt, and remove the ones you stopped using.

Sources