The Claude Marketplace opened on 23 September 2026 with more than 2,000 connectors and plugins. A listing carries three assurances: a human review, an automated safety scan, and a pinned commit. In the days around the launch each of the three was shown to have a documented gap. The common cause is not carelessness. It is that all three describe what an extension was at review time, and your users run it at run time.
What did the Claude Marketplace actually change?
Anthropic's launch post describes three sections in one catalogue. Connectors and plugins, more than 2,000 at launch, including Atlassian, Google, Microsoft, Notion and Salesforce. Agents and products, which customers buy with a portion of their committed Anthropic spend, from companies such as CrowdStrike, Cursor, Harvey, Legora, Lovable and Snowflake. And service partners from the Claude Partner Network.
Two days later the plugin submission portal opened. Plugins package MCP connectors, Agent Skills, or both. A developer either points at a remote MCP server or submits a bundle hosted in a GitHub repository, and in Claude Code a bundle can also carry LSPs, commands, hooks and agents. Every submission is auto-validated and safety-scanned, and the client supports the 2026-07-28 MCP specification with its stateless core, plus the MCP Apps and Enterprise Managed Auth extensions.
The number that matters to an IT organisation is not 2,000. It is three: three different things now arrive through one catalogue, and they have three different trust boundaries. Pluto Security published a practitioner's map of that ecosystem, so take it as read that skills, connectors and plugins are not the same object. The question after that map is what each assurance attached to them is actually worth.
What does a plugin contain, and where does it run?
A remote MCP connector is an authorisation decision. The publisher's code runs on the publisher's infrastructure; what leaves your organisation is a token with a scope against your data. Your questions are the identity ones: which scopes, which sub-processor, what token lifetime, how you revoke. Enterprise Managed Auth is relevant here precisely because it works: zero-touch OAuth removes the consent screen an end user used to see. That is a real friction win and a real checkpoint loss, and the checkpoint has to reappear upstream.
A plugin bundle is a code decision. Files reach the machine. Skills are instructions the model reads and follows, which makes plain Markdown part of the execution path. In Claude Code, hooks are shell commands bound to session events. Check Point Research showed what that means with CVE-2025-59536, where a repository's own configuration files triggered code execution before the trust prompt had been answered.
One button says Add for both. Your approval process should not.
What does Anthropic's skill and plugin scan not cover?
Anthropic publishes the answer, and its help article on skill and plugin scanning is the most useful page in this whole story. Scanning is available on Enterprise plans in Claude, Claude Cowork and Enterprise plugin marketplaces. It runs when a third-party skill or plugin is uploaded or edited, takes about one to two minutes, and returns pass, warn or fail. It is off by default until 2 October 2026, when it switches on for Enterprise organisations that have not set it.
The exclusions, from the same page, are the part to read carefully. Not scanned: skills and plugins already in the organisation before scanning was turned on; skills you create with Claude; skills shared through a connected MCP server; MCP servers and hooks, which are not scanned at this time; and organisations running customer-managed encryption keys, zero data retention or HIPAA configurations.
Read that list against the previous section. MCP servers and hooks are the two components that execute code, and they are the two outside the scan. Anthropic states the limit plainly as well: a pass result "isn't a guarantee that a skill is safe in every respect".
There is a second, quieter consequence. Because pre-existing items are excluded, switching scanning on grandfathers your current inventory. An organisation that lets the 2 October default arrive and then reports its estate as scanned will be wrong about everything installed before that date. Scanning is a gate on new arrivals, not a sweep.
Why did SHA pinning fail in Plugin4Shell?
On 17 September 2026, six days before the marketplace opened, Air Security researchers Or Nevo, Dor Granat and Niv Hoffman disclosed Plugin4Shell, a pinning bypass present in Claude Code, OpenAI Codex, GitHub Copilot and Gemini CLI.

The mechanics are a git detail. The agent clones the plugin repository and runs a checkout of the pinned 40-character commit. Nothing forbids a branch being named like a hash, and when a name is both a valid ref and an object id, git prefers the ref and prints only an ambiguity warning. An attacker who controls the repository creates a branch with the pinned SHA as its name, makes it the default branch, and the checkout lands on attacker-controlled content while the install reports success at the pinned commit. Because agents update installed plugins in the background, the swap reaches machines whose owners installed the reviewed version and never touched it again.
The fix is one assertion after checkout: resolve HEAD and abort unless it equals the pinned SHA. It has to run inside the agent, because the pin is resolved on the client, which is why no marketplace can enforce the guarantee it advertises.
The vendor picture is worth stating fairly, because it is not uniform. Anthropic confirmed the fix in Claude Code 2.1.179 on 17 June 2026, months before public disclosure. Codex 0.146.0 was verified fixed on 12 August. Microsoft has shipped no fix for Copilot, and Google deprecated Gemini CLI rather than patching it. Air sells tooling in this market, which is worth knowing when reading its conclusions, and The Register's coverage reported the same findings independently. The git behaviour is checkable on any machine in under a minute.
What do these failures have in common?
Line them up and one shape appears.
The scanner reads a skill at upload and does not follow the URLs the skill points at. Trail of Bits reported in June 2026 that it bypassed every scanner it tested, ClawHub's, Cisco's and all three behind skills.sh, and that three of its four malicious skills took under an hour to build. Air ran malicious skills past Anthropic's scanner on 24 September: a skill already circulating that leans on an unclaimed package name, a spoofed install domain marked safe, and a credential-stealing binary that drew only a caution, the same result every harmless binary gets.
The pin records a commit at review, and the client resolves a name at install. The connector's domain is trusted at listing, and resolved on every call: Air's MCPJacking work registered 155 expired domains behind MCP servers listed in the official marketplace. The purchase assesses a supplier once, and the product keeps changing.
Every one of these assurances is a statement about time T applied to behaviour at time T plus n. That is time-of-check to time-of-use, a bug class older than the technology it has now arrived in. Air names it for the scanner in that same write-up; the argument here is that it is the shape of all three assurances, and it is what OWASP's Agentic Skills Top 10 names as AST05, untrusted external instructions, with content pinning and continuous rescanning as its mitigations, alongside AST02, supply chain compromise. Air's own sweep of 142,836 live skills found 17,822 of them, 12.4 percent covering 6.7 million installs, resting on at least one untrusted external instruction source.
So a marketplace badge is evidence about the past. It belongs in your filter, not in your control set.
Which controls still hold at run time?
Five, in rough order of effort.
Inventory first, then allowlist. The Plugins and skills section of organisation settings gives an inventory and a requests queue. Decide by publisher identity and repository host, not by how good the listing looks.
Set a client version floor in endpoint management. Plugin4Shell is fixed in the agent, not in any catalogue, so Claude Code 2.1.179 or later is a control and a stale laptop is the gap.
Fork your approval form. A connector approval asks about scopes, sub-processors, token lifetime and revocation. A bundle approval asks which repository, which host, which hooks, and what the thing is allowed to reach on the network. Hosts differ here too: GitHub rejects a 40-character hex branch name outright, while self-hosted git servers accept one.
Break the trifecta. OWASP records the pattern: private data, exposure to untrusted content, and an outbound network path. An agent that reads untrusted content should not also hold long-lived credentials with unrestricted egress. Removing any one leg costs less than defending all three.
Re-check rather than re-trust. A pass is cached; the dependency behind it is not. Rescan on a schedule and on dependency change, and keep a kill switch that does not depend on the publisher.
What does this mean for a Dutch IT organisation?
For an IT manager or security officer in a Dutch organisation of a few hundred to a few thousand people, the change is administrative before it is technical. An extension that reads your Exact, AFAS, Microsoft 365 or Salesforce data is a supplier in your ISMS whether it arrived through inkoop or through a catalogue button, and buying a third-party agent out of committed AI budget is a procurement decision wearing a product interface.
The timing is real. The Cyberbeveiligingswet, the Dutch implementation of NIS2, has been in force since 15 August 2026, and it puts supply-chain security on the entity rather than on the supplier. Under the BIO, a party that processes your data belongs in the register. A catalogue listing is not an onboarding, and an approval by an enthusiastic team lead is not a supplier assessment.
We build and support AI systems alongside the ICT partner or internal team you already have, and we do not run your IT estate, so the seam is where this lands for us: who decides which extension is allowed, who owns the version floor, and who is called when a plugin starts behaving differently. Those three answers are worth writing down before 2 October rather than after. If you want the wider picture of what an AI supplier changes in an existing landscape, our pages on AI implementation in the Netherlands and applied AI for mid-sized business cover the engagement side, and we have written separately on who gets paged when an AI system fails, on MCP permissions before capability and on what an agent audit trail cannot log.
A consultant tells you where AI pays off; Crux Digits also builds it. A fixed price per step, one named expert, from Utrecht.
AI consultancy in the Netherlands →


