top of page

Claude Plugins Directory Opens, Turning Extensions Into Anthropic’s Distribution Layer

Sep 26
13 min read

Anthropic opened the Claude plugins directory to third-party submissions on September 25, 2026, giving developers a reviewed path into its extension marketplace. The shift matters because plugins are no longer an optional wrapper around Claude features. Anthropic now describes them as the main way developers should package outside capabilities for Claude.

A plugin can contain a Model Context Protocol connector, one or more Agent Skills, or both. MCP gives Claude access to external tools and data, while a Skill supplies reusable instructions, scripts, and supporting resources. Combining them lets a developer distribute both access and operating knowledge as one installable product.

That packaging decision puts Anthropic into a direct contest with the app model used by ChatGPT. Both companies now want third-party developers to build on MCP, pass a platform review, and reach users through a searchable directory. The important competition is therefore not Claude versus one individual integration. It is Claude’s bundled plugin model versus a conventional conversational app store.

Anthropic’s plugin announcement gives developers a portal for submission, review tracking, launch control, and usage analytics. It also begins consolidating several extension formats that previously appeared as separate building blocks.

The Claude plugins directory could make sophisticated agent workflows easier to install and discover. It also concentrates more responsibility in Anthropic’s review process, ranking systems, permission controls, and handling of software that can change after approval.

The Claude Plugins Directory Now Has a Submission Pipeline

The immediate change is operational: outside developers can now submit a plugin, follow its review, and publish it after approval.

The submission portal is available to developers on paid Claude plans. Anthropic offers two submission paths, reflecting the different ways developers have already extended Claude.

The first path covers a single remote MCP connector. A developer supplies the address of an MCP server, which exposes tools or data through the protocol. This route fits services that primarily need Claude to search records, call an API, or perform defined actions.

The second path covers a plugin bundle hosted in a GitHub repository. That bundle can combine MCP servers with Agent Skills. In Claude Code, it can also include language server integrations, commands, hooks, and specialized agents.

The distinction is important. A connector tells Claude what external system it can reach. A Skill tells Claude how to approach a particular task. A plugin can package both parts so that users do not need to assemble a workflow from separate components.

Consider a developer tool for resolving production incidents. Its connector might retrieve alerts, logs, and issue records. Its Skills could define the investigation sequence, the required evidence, and the format for a final incident report. The plugin then distributes the connection and the procedure together.

Anthropic says every submission receives automatic validation and a safety scan. Developers can see the review status, inspect scan results, and respond to recommended changes. Approval does not force an immediate release because the developer retains control over the publication date.

That final control separates review from launch. A team can wait until its backend, support materials, or announcement is ready before making an approved plugin public. It can also coordinate the directory release with an existing product deployment.

After publication, the portal reports installs by Claude surface and plugin version. It also shows listing views and the searches that led users to the plugin. Those metrics should help developers distinguish a discovery problem from an activation problem.

A listing that receives views but few installs may have weak positioning, unclear permissions, or limited perceived value. A plugin with strong adoption on Claude Code but little use elsewhere may need different Skills or documentation for general Claude users.

The directory itself still presents Skills, connectors, and plugins as recognizable categories. Existing entries do not require immediate changes. Anthropic says developers will eventually be able to convert connector listings into plugins, while current directory items can remain in place during the transition.

This is consolidation without an abrupt migration deadline. Anthropic can make plugins the preferred format while preserving existing integrations and the installed base behind them.

The strategy also arrives alongside the broader Claude Marketplace, which lists more than 2,000 plugins and connectors. The submission portal turns that catalog from a curated destination into a more structured developer channel.

Why Anthropic Is Bundling Tools and Instructions Now

Plugins solve a distribution problem that neither MCP connectors nor prompt packages solve well on their own.

MCP standardized the exchange between an AI application and an external service. A server can advertise tools, resources, and related capabilities in a form an MCP-compatible client can understand. That reduces the need for developers to design a different integration protocol for each AI product.

The protocol has also become easier to operate at scale. The July 2026 MCP specification introduced a stateless core, cacheable lists, header-based routing, authorization changes, and a formal extension framework. A stateless core allows requests to reach ordinary server instances without depending on a persistent transport session.

Those changes make MCP a stronger foundation for hosted commercial integrations. They do not, however, tell Claude how an organization wants a task performed. A list of available tools is not the same as an operating procedure.

Agent Skills cover that second layer. Anthropic defines a Skill as a folder containing instructions, scripts, and resources that Claude loads when relevant. Its Agent Skills model allows a developer to encode specialized workflows without placing every instruction in every conversation.

This creates a natural division of labor. MCP handles access and actions. Skills handle procedures and task-specific context. Plugins package those layers for installation and distribution.

The timing also reflects how agent products are moving beyond simple question answering. When an assistant can retrieve private records, run code, generate files, or change an external system, successful use depends on more than model quality. The surrounding workflow determines what the model can see, what it can do, and how consistently it performs.

Developers previously had to distribute these pieces through separate channels. One repository might contain an MCP server. Another might contain prompts, scripts, or Claude Code commands. Installation instructions often required users to edit configuration files and understand how the components fitted together.

A plugin turns those fragments into a recognizable product unit. That gives the developer one listing, one versioned package, and one adoption funnel. It gives the user a simpler decision: whether to install a package designed for a particular job.

For enterprise buyers, bundling also makes governance more legible. Administrators can evaluate a named package, review its source and capabilities, and decide who should receive it. Anthropic’s organizational controls can make a plugin available, install it by default, or require it for specified users.

The package may also travel across Claude surfaces. According to Anthropic’s directory guidance, installed Skills can become available in Claude chat, Cowork, and Claude Code when the same account is used. That reach makes a plugin more useful than a narrow integration tied to one interface.

This cross-surface promise remains conditional. A plugin designed around local hooks or development commands will not deliver the same experience in a browser conversation. Developers still need to identify which capabilities work on each surface and design appropriate fallbacks.

Even so, Anthropic is establishing plugins as the unit around which discovery, review, analytics, and organizational distribution operate. MCP and Skills remain the underlying components, but the directory gives the bundle commercial and operational visibility.

Claude Plugins Versus Connectors Is the Wrong Contest

The central contest is not Claude plugins versus connectors, because Anthropic wants connectors to become ingredients inside plugins.

A connector remains useful when access is the entire product. A database search service, document retrieval endpoint, or narrowly defined API may not need additional instructions. Anthropic therefore continues to accept a single remote MCP server through the new portal.

A plugin becomes more valuable when the integration requires a sequence, a policy, or a specialized output. The developer can pair tools with Skills that describe when to use them and how to turn their results into finished work.

That means the Claude plugins versus connectors distinction is primarily about packaging depth. A connector exposes a capability. A plugin can turn one or more capabilities into a workflow with its own instructions and supporting assets.

The more consequential comparison is with ChatGPT’s app distribution model. OpenAI began accepting third-party app submissions in December 2025 and placed approved products in a searchable directory. Its submission process also asks developers for MCP connectivity details, testing instructions, directory metadata, and market availability.

OpenAI’s app submission model emphasizes conversational experiences that can retrieve context, take actions, and render interactive interfaces. Apps can be invoked by name, selected from a tools menu, or surfaced through recommendations.

Anthropic is approaching the same opportunity from a different starting point. Its bundle can join remote tools with procedural knowledge, while Claude Code plugins can extend further into commands, hooks, agents, and development infrastructure.

The two models nevertheless share more technical ground than their labels suggest. Both treat MCP as an important connection layer. Both review public submissions. Both provide a directory where distribution depends partly on search, ranking, and platform recommendations.

This shared foundation lowers some development costs. A company can expose core capabilities through MCP and then build platform-specific packaging around them. It does not eliminate adaptation because each host has different interfaces, policies, review criteria, and supported extensions.

The strategic question is which platform gives developers the best route from a working integration to repeated use. Raw audience size matters, but so do discovery quality, analytics, cross-surface availability, enterprise deployment, and the amount of platform-specific work required.

Anthropic’s portal directly addresses several of these factors. Search-query analytics can show developers how users describe a problem. Version-level installation data can reveal whether an update improved adoption. Review feedback can expose compliance issues before launch.

Yet analytics alone cannot create demand. A directory with thousands of entries can become difficult to navigate, especially when several plugins claim to solve the same workflow. Search ranking and editorial promotion then become part of the product’s economics, even without a formal payment system.

Developers also need to decide how much value to place in a platform-specific Skill. Detailed Claude instructions can improve the experience inside Anthropic’s products, but they may increase maintenance if another host interprets workflow guidance differently.

For users, the winning model will be the one that reduces configuration without hiding consequential choices. A one-click package is useful only when people can understand its permissions, data flows, maintenance state, and supported environments.

Knowledge workers may experience this competition through ordinary tasks rather than directory branding. A research plugin might collect source material, apply a verification procedure, and generate a structured brief. That kind of AI workflow becomes more valuable when its tools and operating instructions arrive together.

Anthropic is betting that this bundle is the right unit for agent software. OpenAI is betting that an app-centered experience can become native to conversation. Both approaches turn distribution and trust into platform features rather than leaving them entirely to GitHub repositories and manual configuration.

How Claude Plugins Work Creates a Harder Trust Problem

A reviewed directory reduces uncertainty, but it cannot make every plugin permanently safe.

Anthropic’s automatic validation and safety scan are useful first barriers. Its directory policy also requires privacy protections, appropriate data collection, compliance with usage rules, and compatibility with other listed servers. Reviews can continue after an item has been published.

However, a plugin is not a static document. It may connect Claude to live services, contain executable components, or depend on code that receives later updates. The safety properties observed during submission can therefore change.

Remote MCP servers present a particular challenge. The operator can alter server behavior without asking users to reinstall anything. A benign tool response during review does not guarantee that future responses will remain benign.

Anthropic has acknowledged this distinction in its own agent containment analysis. A local tool can be inspected and pinned to a known version. A remote tool can change after the user’s original trust decision, so Anthropic advises treating resources outside reviewed directories as untrusted.

Directory inclusion improves the situation through initial and ongoing review. It does not turn a remote service into immutable software. Anthropic’s terms reserve the right to remove an MCP server for security concerns, complaints, policy violations, or other reasons.

The second risk comes from prompt injection, which occurs when untrusted content includes instructions intended to redirect an agent. A plugin that retrieves web pages, messages, tickets, or documents can bring hostile text into Claude’s working context.

Traditional dependency checks do not fully address this problem. A server may run authentic, signed code and still return content designed to manipulate an agent. The harmful instruction can arrive through a document rather than the executable itself.

Bundling Skills with connectors adds another review surface. Instructions determine when Claude should use a tool, which evidence it should trust, and how it should respond to conflicts. Poorly designed guidance can cause unsafe behavior without containing obviously malicious code.

Claude Code plugins can carry even broader consequences. Hooks, commands, agents, and local MCP servers may interact with source files, shell commands, credentials, or deployment systems. The practical risk depends on permissions and the environment where the plugin runs.

Enterprises will therefore need more than an approval badge. Administrators should examine requested capabilities, authentication paths, data retention policies, update behavior, and the difference between local and remote components. They should also test new plugins with non-sensitive data before granting access to production systems.

Developers face a related disclosure problem. A clear listing should explain what information leaves Claude, what actions the plugin can perform, and whether a remote service can change independently of the installed package. Version notes matter when permissions or dependencies change.

The portal’s version analytics may encourage regular updates, but frequent releases create review pressure. Anthropic has not publicly detailed every threshold for re-review, every ranking signal, or how quickly a changed remote service can be reassessed.

There is also a governance tension in Anthropic’s decision to make plugins the primary third-party format. A unified package simplifies distribution, yet it gives the platform more influence over visibility and continued access. Developers must comply with policies that can evolve, while Anthropic controls directory placement and removal.

That arrangement is common in software marketplaces. Agent plugins raise the stakes because they can combine external data, procedural instructions, and consequential actions inside one package. Review must assess not only whether software runs, but also how it steers a model under uncertain inputs.

Users should interpret approval as a risk reduction measure, not a permanent warranty. The strongest signal will be whether Anthropic can pair automated scans with ongoing monitoring, transparent disclosures, rapid incident handling, and controls that keep each plugin’s authority narrow.

The Directory Puts Pressure on Builders and Enterprise Buyers

Anthropic’s decision forces plugin developers to treat discovery, governance, and maintenance as product requirements.

For independent builders, the portal creates a credible route to users who would never install a repository manually. That distribution can reward narrowly designed plugins that solve a complete task with little setup.

It also raises the entry standard. A public plugin now needs more than functional code. It needs a coherent listing, clear permission boundaries, reliable hosting, a review-ready repository, version discipline, and enough support to survive real-world use.

The portal’s search analytics will make naming and positioning measurable. Developers can see which searches generate listing visits, then adjust their descriptions or prioritize missing capabilities. Install data by product surface can guide platform-specific development.

Those signals may produce better products, but they can also favor teams with time to optimize directory performance. Smaller builders could find themselves competing with established software vendors that already have recognizable brands, mature authentication systems, and dedicated compliance staff.

Enterprise buyers face a different decision. They can use public directory plugins, distribute internal packages, or combine both approaches. Public listings reduce sourcing effort, while internal plugins can encode company-specific procedures and connect private systems.

Anthropic’s organization controls allow administrators to govern publication and installation. A company can make a plugin optional, install it by default, or require it. That helps standardize workflows, particularly when a Skill contains approved operating instructions.

Required deployment deserves careful handling. Anthropic notes that some Claude Code components run on the user’s computer. A mandatory plugin with local hooks or tool access can affect development environments in ways that employees cannot independently disable.

Security teams will want an inventory covering source, version, capabilities, audience, and recent use. They will also need a response process for plugins removed from the public directory, servers that change behavior, and packages whose maintainers stop releasing updates.

Software vendors now have to decide whether Claude deserves its own packaged workflow. A basic MCP endpoint may reach several compatible clients, but a Claude-specific Skill can improve task quality and directory positioning. The tradeoff is another product surface to maintain.

The most successful developers will likely keep their core service portable while adapting the experience for each host. MCP can provide shared access to tools. Platform-specific instructions, interfaces, and governance metadata can sit above that common layer.

This approach avoids treating portability as sameness. A server can expose the same underlying capability to Claude and ChatGPT while each platform handles discovery, recommendations, permissions, and user interaction differently.

Anthropic must make that extra work worthwhile. The directory needs to deliver qualified installs rather than passive views. Review times must remain predictable. Analytics must be accurate enough to guide decisions. Cross-surface behavior must be understandable.

The company must also prevent low-quality submissions from overwhelming discovery. Automated validation can catch formatting and known security issues, but it cannot judge whether ten nearly identical plugins provide distinct value.

Curation will become more difficult as submissions grow. If search favors incumbents, new developers may struggle to gain traction. If recommendations favor novelty, users may encounter unstable products. Anthropic will need a balance that rewards quality without freezing the directory around its earliest entries.

For buyers, the important metric is not the number of available plugins. It is the number that remain reliable, transparent, and useful after installation. A large catalog creates optionality, but active use and retention reveal whether packaging has improved actual work.

What Comes Next for the Claude Plugins Directory

Three signals will determine whether plugins become Claude’s real extension layer rather than another catalog of integrations.

The first signal is conversion of existing connectors into richer plugin bundles. Anthropic says developers will eventually be able to turn connector listings into plugins. A sustained wave of conversions would show that builders see value in attaching Skills and workflow assets to MCP access.

The quality of those conversions matters more than the raw count. Simply wrapping an existing connector in a new manifest would add little. Plugins should reduce setup, encode useful procedures, or create a consistent result that the connector alone could not deliver.

If established connector providers invest in those richer packages, Anthropic’s bundling strategy gains support. If most listings remain connector-only, plugins may function mainly as a new directory label.

The second signal is whether one discovery experience truly spans Claude and Claude Code. Anthropic says a unified experience will roll out across both products over the coming weeks. Users should be able to understand where a plugin works before installing it.

A convincing rollout would provide consistent identity, version information, permissions, and status across surfaces. It would also make surface-specific capabilities clear. A developer-focused hook should not appear equivalent to a browser-compatible Skill.

Cross-surface retention will be especially revealing. If users install a package through one Claude product and keep using it elsewhere, plugins will have achieved something a standalone connector cannot easily provide.

The third signal is how Anthropic handles the first visible security or quality incident. A large third-party ecosystem will eventually produce a vulnerable package, a compromised server, misleading metadata, or an update that behaves differently from the reviewed version.

The response will test ongoing monitoring, developer communication, user notifications, and removal procedures. Fast containment would strengthen the directory’s trust model. A slow or opaque response would weaken the value of approval.

Competitive reactions also deserve attention, but they are supporting evidence rather than the main test. OpenAI already has an MCP-based directory and submission process. Both companies will keep adding publishing tools, interfaces, analytics, and enterprise controls.

Anthropic’s distinct proposition is the plugin bundle itself. It wants a third party to package access, expertise, and workflow behavior into one installable unit that can operate across Claude products.

That is a credible direction because agents need both tools and instructions. It is not automatically a durable advantage. Open standards make core connections portable, while review quality and product distribution remain controlled by each platform.

Developers should start with one bounded task, expose the minimum required tools, and document every meaningful permission. They should test how the package behaves when retrieved content contains misleading instructions or when a remote dependency fails.

Enterprise teams should evaluate plugins as active software dependencies, not decorative prompt packs. That means reviewing updates, limiting authority, monitoring use, and maintaining a removal plan.

For individual users, the practical question is simpler: does an installed package reliably complete a real workflow with less configuration and clearer control? Watch the next few months for connector conversions, genuine cross-product use, and transparent incident handling. Those results will show whether the Claude plugins directory has become Anthropic’s durable third-party platform.

Give every agent the context to do better work

Connect your agents to the knowledge, decisions, and history already organized in remio.

remio currently supports Windows 10+ (x64) and Macs with Apple silicon.

Your AI Partner at Work
Get more done with remio

Plan. Create. Deliver.
All in one place.

bottom of page