Skip to content

Plugins and marketplaces in Claude Code, Codex and Cursor

A coding-agent plugin is a versioned bundle of skills, slash commands, subagents, hooks and MCP servers that Claude Code, Codex, Cursor and GitHub Copilot CLI install from a marketplace: a git repository with a catalogue file. Install commands differ per agent, and every plugin adds context cost worth measuring before a team adopts it.

A teammate says “install the Vercel plugin”. You type claude plugin add vercel and get unknown command 'add'. Once installed, it adds about 4,217 tokens to every session (claude plugin details vercel, Claude Code 2.1.283), and your teammate has a different set. This page is for developers who install plugins and tech leads who choose them.

  • One command table for four agents, with the spellings that fail
  • One plugin installed, measured and removed in each agent
  • A four-step adoption workflow (evaluate, measure, pin, review)
  • Managed settings that restrict a team to approved marketplaces

Plugin, skill or MCP server: which one do you need?

Section titled “Plugin, skill or MCP server: which one do you need?”

A skill is one SKILL.md folder of instructions. An MCP server is a live connection to a tool or data source. A plugin packages several of these, plus hooks and subagents, under one version.

You needReach for
A reusable procedure, such as a release checklistA skill
Live access to GitHub or a databaseAn MCP server
A skill, a hook and a server that work togetherA plugin
One bundle, one version, on every laptopA plugin from a marketplace

The ecosystem overview shows the other layers.

Plugin commands in Claude Code, Codex, Cursor and Copilot CLI

Section titled “Plugin commands in Claude Code, Codex, Cursor and Copilot CLI”

Checked on 2026-09-26 against Claude Code 2.1.283, codex-cli 0.157.1 and Copilot CLI 1.0.88; the Cursor column comes from Cursor’s cursor/plugins repository.

TaskClaude CodeCodexCursorCopilot CLI
Add a marketplaceclaude plugin marketplace add owner/repocodex plugin marketplace add owner/reponot verified (team marketplaces: Dashboard → Settings → Plugins, secondary)copilot plugin marketplace add owner/repo
Installclaude plugin install NAME@MKTcodex plugin add NAME@MKT/add-plugin NAME in Agent chat, or Cursor Settings → Pluginscopilot plugin install NAME@MKT
Listclaude plugin listcodex plugin listnot verifiedcopilot plugin list
Measure context costclaude plugin details NAMEno commandnot verifiedno command
Update a pluginclaude plugin update NAME@MKTno update subcommand (0.157.1); how an installed plugin gets a new version is not verifiednot verifiedcopilot plugin update --all
Refresh marketplacesclaude plugin marketplace updatecodex plugin marketplace upgradenot verifiedcopilot plugin marketplace update
Disableclaude plugin disable NAME@MKTenabled = false in config.tomlnot verifiedcopilot plugin disable NAME
Uninstallclaude plugin uninstall NAME@MKTcodex plugin remove NAME@MKTnot verifiedcopilot plugin uninstall NAME
In-session browser/plugin/pluginsnot verified/plugin (per README, not run)
  • Claude Code registers claude-plugins-official on first start; /reload-plugins applies changes without a restart.
  • Codex ships openai-curated and also reads Claude-format marketplaces.
  • Cursor reads a .cursor-plugin/plugin.json manifest.
  • Copilot CLI has awesome-copilot and copilot-plugins built in.

On claude.com/plugins on 2026-09-26, the most-installed plugins were Frontend Design (1,134,112 installs) and Superpowers (1,009,371); marketplaces and registries compares the catalogues.

Install, measure, disable and remove one plugin in each agent

Section titled “Install, measure, disable and remove one plugin in each agent”

Trail of Bits’ differential-review plugin lives in a Claude-format marketplace that Claude Code, Codex and Copilot CLI accept.

Terminal window
claude plugin marketplace add trailofbits/skills
claude plugin install differential-review@trailofbits
claude plugin details differential-review

details prints the inventory and per-session cost:

Component inventory
Skills (2) diff-review, differential-review
Agents (1) adversarial-modeler
Projected token cost
Always-on: ~258 tok added to every session

Run it in a session as /differential-review:diff-review. Then turn it off or remove it:

Terminal window
claude plugin disable differential-review@trailofbits
claude plugin uninstall differential-review@trailofbits

How a team adopts a plugin: evaluate, measure, pin, review

Section titled “How a team adopts a plugin: evaluate, measure, pin, review”
  1. Evaluate the source. Hooks and MCP servers run with your credentials; read the source first.

  2. Measure the cost. Run claude plugin details NAME, then /context in a session, because MCP tool schemas are not in that figure (cut MCP token cost). Our rule of thumb: above about 2,000 always-on tokens, use project scope, never user scope.

  3. Pin it to the project. claude plugin install differential-review@trailofbits --scope project writes the plugin into .claude/settings.json:

    { "enabledPlugins": { "differential-review@trailofbits": true } }

    Add the marketplace with --scope project too. In Codex, pin the marketplace to a tag with codex plugin marketplace add owner/repo --ref TAG.

  4. Review it like code. The settings change goes through a pull request the allowlist owner signs off. If the plugin ships evals/, claude plugin eval NAME@MKT scores it against a no-plugin baseline.

    Replace the placeholder path in this prompt with your own approved-marketplace list.

How to allowlist marketplaces for the whole team

Section titled “How to allowlist marketplaces for the whole team”

In Claude Code, managed settings restrict which marketplaces anyone can add and pre-enable approved plugins:

{
"strictKnownMarketplaces": [
{ "source": "github", "repo": "acme/*" }
],
"enabledPlugins": { "acme-review@acme-plugins": true }
}

Build a plugin or a private marketplace covers hosting the team catalogue.

Codex (a [marketplaces] table in managed requirements.toml, checked at rust-v0.157.1) and Cursor (Team Marketplaces) are compared in one policy for every coding agent.

What goes wrong with plugins, and how to recover

Section titled “What goes wrong with plugins, and how to recover”
  • A pushed fix never reaches teammates. Updates wait for a version bump in plugin.json, and third-party marketplaces do not auto-update. Run claude plugin marketplace update, then claude plugin update NAME@MKT, and restart.
  • A committed plugin is missing on a teammate’s machine. A plugin with an external source still needs claude plugin install NAME@MKT --scope project once per machine.
  • A private marketplace fails to clone. Claude Code never prompts for credentials; run gh auth login and gh auth setup-git.