Fetching from the wire…
Public story · 2026-08-23 · high
The mirror syncs nightly from Anthropic's internal review queue, and every plugin in it already cleared automated security scanning before listing.
Why now: The anthropics/claude-plugins-community repo picked up roughly 190 stars on August 22 and hit GitHub Trending again on August 23.
Anthropic pushed anthropics/claude-plugins-community live as a read-only mirror, and it's already on GitHub Trending. The repo gained around 190 stars on August 22, then got pushed again the next day.
Here's what's actually in it. The repo's .claude-plugin/marketplace.json file syncs nightly from Anthropic's internal review queue. Every plugin listed there was submitted through claude.ai, ran through automated security scanning, and got approved before it showed up. You don't submit to the GitHub repo directly, it just mirrors what already passed.
Installing is two commands: claude plugin marketplace add anthropics/claude-plugins-community, then claude plugin install <name>@claude-community. The same marketplace backs Claude Cowork at claude.com/plugins, so this isn't a side channel, it's the same list showing up in a second product.
What matters here isn't the star count, it's the trust model. Before this, if you wanted a Claude Code plugin, you found a gist or a GitHub repo and read the code yourself, or you didn't. Now there's a default path where someone else already checked. That's a real convenience, and it's also a chokepoint: whatever Anthropic's automated scanning misses ships to everyone using the one-line install, and the mirror being read-only means you can't audit the review queue itself, only the output.
Worth watching whether plugin authors start optimizing for what the scanner catches rather than what's actually safe. Automated security scanning has a known shape, and once people know the shape of the gate, some of them build to pass it instead of to be clean. The repo doesn't say what the scanning actually checks for, so there's no way yet to tell how far that gap could run.
Each link below shares sources, entities, or timing with this story.
Same source domain / Semantically similar
Reported by the same outlet (github.com); covers closely related ground (similarity 0.77).
Same source
Cite the same source (GitHub).
Same source domain / Semantically similar
Reported by the same outlet (github.com); covers closely related ground (similarity 0.69).
Reported by the same outlet (github.com); covers closely related ground (similarity 0.69).
Reported by the same outlet (github.com); covers closely related ground (similarity 0.69).
Reported by the same outlet (github.com); covers closely related ground (similarity 0.69).
Reported by the same outlet (github.com); covers closely related ground (similarity 0.68).
Reported by the same outlet (github.com); covers closely related ground (similarity 0.67).