Skip to content
CAI
Software that uses CAICheck a score

anthropics/claude-plugins-official

37.2

Weak · 18 September 2026

16.2k

lines of production code

Python

with JavaScript, TypeScript

1

measurement over time

CAI band scale
CAI lens gauges

What this system is

This system is a plugin-based extension framework for Claude Code, designed to enhance the assistant's capabilities through modular, specialized agents. It provides tools for connecting to external messaging platforms like Discord and Telegram, performing deep security scanning and code modernization, and generating detailed usage and project status reports. The architecture supports custom skill creation and evaluation, allowing users to extend the core functionality with domain-specific workflows and integrations.

Features

Add fakechat channel plugin for local testing

A new localhost web-based channel plugin named 'fakechat' has been added to the external\_plugins directory. It provides a simple UI for testing the channel contract without requiring an external messaging service, supporting file uploads and message edits. The plugin is implemented as a Bun server that exposes tools (reply, edit\_message) via the Model Context Protocol (MCP) and serves a web interface on localhost:8787 by default. It is licensed under Apache 2.0 and includes configuration files for the Claude plugin system and MCP server.

_external\plugins/fakechat · high confidence

Claude Security Plugin introduces static analysis reporting with SARIF and JSONL outputs

The plugin now includes a Python-based reporting pipeline that records scan results and renders them into standardized formats. A new \render\_report.py\ script generates \CLAUDE-SECURITY-RESULTS.jsonl\ and \CLAUDE-SECURITY-RESULTS.sarif\ (SARIF 2.1.0) files, mapping findings to CWE categories via a new \cwe.py\ module and a \cwe-categories.json\ catalog. Supporting scripts \save\_result.py\ and \write\_scan\_meta.py\ handle the ingestion of scan data and the recording of repository metadata (such as revision, scope, and remote URL) into a run directory, enabling structured, machine-readable security reports.

python · high confidence

Introduce Discord channel plugin for Claude Code

Adds a new Discord channel plugin that connects a Discord bot to Claude Code via an MCP server, enabling bidirectional messaging with built-in access control. Users can install the plugin, configure a bot token, and manage access through pairing codes or allowlists using \/discord:access\ commands. The plugin supports DMs and guild channels, with features like mention detection, message threading, and attachment handling. State is stored in \\~/.claude/channels/discord/access.json\ and can be configured via environment variables like \DISCORD\_STATE\_DIR\ and \DISCORD\_ACCESS\_MODE\.

_external\plugins/discord · high confidence

Introducing Claude Security Plugin for in-session vulnerability scanning and patching

A new Claude Security plugin is available for Claude Code, enabling deep, in-session vulnerability scanning and targeted patch generation without requiring external daemons or separate processes. The plugin orchestrates a team of specialized agents to map codebases, hunt for vulnerabilities, and independently verify every finding before it reaches the report, ensuring that only confirmed issues are surfaced. Users can scan entire repositories or specific diffs (branches, pull requests, or commits) and choose from effort tiers to balance depth and cost. Verified findings are turned into targeted patch files—each reviewed by independent agents for safety and behavioral integrity—which users can review and apply at their discretion. The plugin supports Claude Fable 5.1 (with occasional fallbacks to Opus 4.8) and requires Python 3.9+.

plugins/claude-security · high confidence

New Math Olympiad plugin with adversarial verification

A new 'math-olympiad' plugin has been added to solve competition math problems (IMO, Putnam, USAMO, AIME) using a multi-agent workflow. The skill employs adversarial verification to catch errors that self-verification misses, using context-isolated verifiers and specific failure patterns to attack proofs. It features calibrated abstention (admitting when it cannot confidently solve a problem) and produces clean LaTeX/PDF outputs. The plugin includes detailed reference materials for solver heuristics, adversarial prompts, and model-tier-specific configurations.

plugins/math-olympiad · high confidence

New Skill Creator plugin for building and evaluating custom skills

The skill-creator plugin is now available, providing a structured workflow for creating, improving, and benchmarking custom skills. It includes a main skill definition (SKILL.md) that guides users through capturing intent, writing skill specifications, and running iterative evaluations. The plugin also introduces specialized agent definitions for the evaluation process: a Blind Comparator to objectively judge output quality without bias, a Post-hoc Analyzer to identify specific strengths and weaknesses in skill performance, and a Grader to evaluate execution transcripts against defined expectations. An HTML-based review interface is included to visualize evaluation results.

plugins/skill-creator · high confidence

New Telegram channel plugin for Claude Code

Adds a new external plugin that connects a Telegram bot to Claude Code via an MCP server, enabling users to send and receive messages, reply, edit messages, and add reactions through the assistant. The plugin includes built-in access control with a default pairing flow to approve senders, configurable DM and group policies, and support for sending files and photos. It requires Bun to run and is installed via the standard plugin install command.

_external\plugins/telegram · high confidence

New code-modernization plugin for legacy system analysis and migration

Introduces the code-modernization plugin, which provides a structured workflow (preflight, assess, map, extract-rules, brief, transform/reimagine/uplift, harden, status) for modernizing legacy codebases such as COBOL, legacy Java/C++/.NET, and monolith web apps. The plugin includes specialist agents for architecture criticism, business rule extraction, security auditing, and version-delta analysis, along with an interactive topology viewer and safeguards against credential leaks and adversarial input injection.

plugins/code-modernization · high confidence

New iMessage channel plugin for macOS

Adds a new external plugin that connects Claude Code to iMessage on macOS. The plugin reads the local Messages database (\chat.db\) for history and new messages, and sends replies via AppleScript. It includes built-in access control with a default allowlist policy (only self-chat is allowed by default), support for group chats, and configuration via environment variables like \IMESSAGE\_ALLOW\_SMS\ and \IMESSAGE\_APPEND\_SIGNATURE\.

_external\plugins/imessage · high confidence

New project-artifact plugin for living project status pages

A new plugin, project-artifact, enables the generation and publishing of tabbed, self-contained HTML status pages for complex projects. These pages cover overview, success criteria, workstreams, and optional sections like risks and FAQs, and are published via the built-in Artifact tool to a private claude.ai URL that can be shared with teammates. The plugin supports a 'refresh' workflow that re-gathers live state, redeploys to the same URL, and reports only the delta. It includes domain-neutral logic and specific support for software projects where workstreams are pull requests, leveraging the gh CLI for live PR/CI/review state. Note that publishing requires an interactive session with a claude.ai login, as the Artifact tool is not available in headless mode.

plugins/project-artifact · high confidence

New receipts plugin for local usage impact reports

The new receipts plugin lets you generate a personal impact report from your local Claude Code session transcripts. It mines \\~/.claude/projects\ and cross-references local git history to produce a markdown report and a self-contained HTML receipt showing what you shipped (files, lines, commits, PRs) and how usage was distributed by project. The plugin runs entirely offline with no network calls, and is installed via \/plugin install receipts@claude-plugins-official\.

plugins/receipts · high confidence

New session-report plugin for analyzing Claude Code usage

The session-report plugin introduces a self-contained HTML report capability for Claude Code session usage. It includes an analyzer script that scans local transcript files to extract token usage, cache breaks, subagent activity, and skill invocations, and a styled HTML template that renders this data into an interactive dashboard with drill-downs, timeline visualizations, and anomaly detection. This allows users to generate detailed usage reports directly from their local session data.

plugins/session-report · high confidence

Behavioural changes

Ralph Loop plugin: session isolation, Windows hook fix, and state tracking

The ralph-wiggum plugin has been renamed to ralph-loop. The stop hook now explicitly invokes bash (fixing Windows compatibility issues where the command might resolve incorrectly) and isolates loop state to the specific session that started it, preventing other sessions in the same project from blocking or modifying the state file. The setup script now records the session ID in the state file and caps the assistant message extraction to the last 100 lines to handle long-running sessions more robustly.

plugins/ralph-loop · high confidence

Security-guidance plugin hooks refactored with improved state management, telemetry, and extensibility

The security-guidance plugin hooks have been restructured into modular components (\_base, diffstate, ensure\_agent\_sdk, extensibility, gitutil, llm, patterns) to enhance maintainability and functionality. State file resolution now respects the CLAUDE\_CONFIG\_DIR environment variable, providing better integration with user configurations. The plugin introduces detailed telemetry for SDK bootstrap failures, encoding error types and phases as integers for improved BigQuery analysis, and adds a cooldown mechanism for signal-killed venv builds to prevent resource exhaustion. Extensibility is enhanced through support for project-specific security guidance (claude-security-guidance.md) and custom regex patterns (security-patterns.{yaml,json}), allowing users to define org-specific security policies. Git subprocess handling has been hardened to correctly process non-ASCII filenames by disabling core.quotePath and using raw byte capture with UTF-8 replacement decoding. The LLM integration now includes provenance tagging for injected security reviews, improved HTTP error tracking for API failures, and support for OAuth tokens and third-party provider configurations.

plugins/security-guidance/hooks · high confidence

Fixes

Fix hookify plugin import errors and command execution failures

Resolves import failures in the hookify plugin by correcting the Python module path from 'hookify.core.\' to 'core.\' and simplifying the sys.path configuration to only add the plugin root. Additionally, fixes command execution issues in hooks.json by properly quoting the ${CLAUDE\_PLUGIN\_ROOT} environment variable in the pretooluse, posttooluse, stop, and userpromptsubmit hook commands.

plugins/hookify/hooks · high confidence

Fixes import path for core configuration module

The rule engine now correctly imports the Rule and Condition classes from the local core.config\_loader module, resolving the previous import error where the system failed to find the 'hookify' module. This ensures the plugin loads and functions as intended without raising a ModuleNotFoundError.

plugins/hookify/core · high confidence

Test coverage

Added tests for security guidance plugin repository resolution and hook execution

Added comprehensive test coverage for the security-guidance plugin, including a new conftest.py with fixtures for mocking git repositories and API responses, and new test files verifying repository resolution logic (parsing git commands, resolving roots from paths and SHAs) and hook execution behavior.

plugins/security-guidance/tests · high confidence

Dependencies

Add external channel plugins for Discord, Telegram, iMessage, and FakeChat

New external plugins have been added to support messaging channels including Discord, Telegram, iMessage, and a FakeChat test channel. Each plugin is packaged as a standalone module using Bun, with dependencies on the Model Context Protocol SDK and channel-specific libraries (discord.js, grammy, zod). These plugins enable users to connect Claude to their preferred chat platforms or test integrations locally.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Baseline

  • First survey — no prior run to compare against. CAI 37.

Lenses

  • Code Health 28
  • Architecture 100
  • Maturity 79
  • Readiness 30
  • Security 71
  • Accessibility 40

Changes since last survey

  • 300 commits — 300 feature/other, 0 fixes

By area

  • .claude-plugin/marketplace.json — 184 commits
  • (repo) — 116 commits

Notable commits

  • change: Add BlackRock Advisor Center plugin (#6094)
  • change: Add Chronograph GP and LP plugins (#6199)
  • change: Add Claude for Small Business plugin (#6145)
  • change: Add Clay plugin (clay) (#6191)
  • change: Add Informatica plugin (informatica-for-claude-platform) (#6152)
  • change: Add Intuit QuickBooks plugin (intuit-quickbooks) (#6189)
  • change: Add Leadfeeder plugin (leadfeeder) (#6198)
  • change: Add Pendo plugins (pendo-analytics, pendo-guides, pendo-orchestrate, setup-agent-analytics, setup-mcp-agent-analytics) (#6190)
  • change: Add Zocks Advisor Intelligence plugin (zocks-advisor) (#6188)
  • change: Merge pull request #5974 from anthropics/bump/stripe
  • change: Merge pull request #6000 from anthropics/bump/stackhawk-hawkscan
  • change: Merge pull request #6001 from anthropics/bump/stackhawk-api
  • change: Merge pull request #6002 from anthropics/bump/teamcity-cli
  • change: Merge pull request #6003 from anthropics/bump/youdotcom-agent-skills
  • change: Merge pull request #6007 from anthropics/bump/airwallex-agentos
  • change: Merge pull request #6008 from anthropics/bump/aws-agents-for-devsecops
  • change: Merge pull request #6009 from anthropics/bump/ckeditor
  • change: Merge pull request #6010 from anthropics/bump/clickhouse-best-practices
  • change: Merge pull request #6011 from anthropics/bump/huggingface-skills
  • change: Merge pull request #6012 from anthropics/bump/mergify
  • …and 280 more

Architecture

  • 0 containers · 1 bounded contexts · 0 dependency edges (baseline)

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

anthropics/claude-plugins-official was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 18 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 1aa8f02ec8327f513686934f458a620f83db91ed — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-5d04157a340d.