Plugins and marketplaces in Claude Code, Codex and Cursor
A coding-agent plugin is a versioned bundle of skills, slash commands, subagents, hooks and MCP servers that Claude Code, Codex, Cursor and GitHub Copilot CLI install from a marketplace: a git repository with a catalogue file. Install commands differ per agent, and every plugin adds context cost worth measuring before a team adopts it.
A teammate says “install the Vercel plugin”. You type claude plugin add vercel and get unknown command 'add'. Once installed, it adds about 4,217 tokens to every session (claude plugin details vercel, Claude Code 2.1.283), and your teammate has a different set. This page is for developers who install plugins and tech leads who choose them.
What this plugins overview gives you
Section titled “What this plugins overview gives you”- One command table for four agents, with the spellings that fail
- One plugin installed, measured and removed in each agent
- A four-step adoption workflow (evaluate, measure, pin, review)
- Managed settings that restrict a team to approved marketplaces
Plugin, skill or MCP server: which one do you need?
Section titled “Plugin, skill or MCP server: which one do you need?”A skill is one SKILL.md folder of instructions. An MCP server is a live connection to a tool or data source. A plugin packages several of these, plus hooks and subagents, under one version.
| You need | Reach for |
|---|---|
| A reusable procedure, such as a release checklist | A skill |
| Live access to GitHub or a database | An MCP server |
| A skill, a hook and a server that work together | A plugin |
| One bundle, one version, on every laptop | A plugin from a marketplace |
The ecosystem overview shows the other layers.
Plugin commands in Claude Code, Codex, Cursor and Copilot CLI
Section titled “Plugin commands in Claude Code, Codex, Cursor and Copilot CLI”Checked on 2026-09-26 against Claude Code 2.1.283, codex-cli 0.157.1 and Copilot CLI 1.0.88; the Cursor column comes from Cursor’s cursor/plugins repository.
| Task | Claude Code | Codex | Cursor | Copilot CLI |
|---|---|---|---|---|
| Add a marketplace | claude plugin marketplace add owner/repo | codex plugin marketplace add owner/repo | not verified (team marketplaces: Dashboard → Settings → Plugins, secondary) | copilot plugin marketplace add owner/repo |
| Install | claude plugin install NAME@MKT | codex plugin add NAME@MKT | /add-plugin NAME in Agent chat, or Cursor Settings → Plugins | copilot plugin install NAME@MKT |
| List | claude plugin list | codex plugin list | not verified | copilot plugin list |
| Measure context cost | claude plugin details NAME | no command | not verified | no command |
| Update a plugin | claude plugin update NAME@MKT | no update subcommand (0.157.1); how an installed plugin gets a new version is not verified | not verified | copilot plugin update --all |
| Refresh marketplaces | claude plugin marketplace update | codex plugin marketplace upgrade | not verified | copilot plugin marketplace update |
| Disable | claude plugin disable NAME@MKT | enabled = false in config.toml | not verified | copilot plugin disable NAME |
| Uninstall | claude plugin uninstall NAME@MKT | codex plugin remove NAME@MKT | not verified | copilot plugin uninstall NAME |
| In-session browser | /plugin | /plugins | not verified | /plugin (per README, not run) |
How each tool’s marketplace works
Section titled “How each tool’s marketplace works”- Claude Code registers
claude-plugins-officialon first start;/reload-pluginsapplies changes without a restart. - Codex ships
openai-curatedand also reads Claude-format marketplaces. - Cursor reads a
.cursor-plugin/plugin.jsonmanifest. - Copilot CLI has
awesome-copilotandcopilot-pluginsbuilt in.
On claude.com/plugins on 2026-09-26, the most-installed plugins were Frontend Design (1,134,112 installs) and Superpowers (1,009,371); marketplaces and registries compares the catalogues.
Install, measure, disable and remove one plugin in each agent
Section titled “Install, measure, disable and remove one plugin in each agent”Trail of Bits’ differential-review plugin lives in a Claude-format marketplace that Claude Code, Codex and Copilot CLI accept.
claude plugin marketplace add trailofbits/skillsclaude plugin install differential-review@trailofbitsclaude plugin details differential-reviewdetails prints the inventory and per-session cost:
Component inventory Skills (2) diff-review, differential-review Agents (1) adversarial-modelerProjected token cost Always-on: ~258 tok added to every sessionRun it in a session as /differential-review:diff-review. Then turn it off or remove it:
claude plugin disable differential-review@trailofbitsclaude plugin uninstall differential-review@trailofbitscodex plugin marketplace add trailofbits/skillscodex plugin add differential-review@trailofbitscodex plugin list # differential-review@trailofbits installed, enabled 1.1.4codex plugin remove differential-review@trailofbitsCodex has no cost report; to disable without removing, see the table above.
In Cursor Settings → Plugins, search for Playwright and click Install, or type /add-plugin playwright in chat (per its README in cursor/plugins). It starts npx -y @playwright/mcp@latest, so Node.js must be on PATH. Cost, disable and uninstall controls were not verified on 2026-09-26.
How a team adopts a plugin: evaluate, measure, pin, review
Section titled “How a team adopts a plugin: evaluate, measure, pin, review”-
Evaluate the source. Hooks and MCP servers run with your credentials; read the source first.
-
Measure the cost. Run
claude plugin details NAME, then/contextin a session, because MCP tool schemas are not in that figure (cut MCP token cost). Our rule of thumb: above about 2,000 always-on tokens, use project scope, never user scope. -
Pin it to the project.
claude plugin install differential-review@trailofbits --scope projectwrites the plugin into.claude/settings.json:{ "enabledPlugins": { "differential-review@trailofbits": true } }Add the marketplace with
--scope projecttoo. In Codex, pin the marketplace to a tag withcodex plugin marketplace add owner/repo --ref TAG. -
Review it like code. The settings change goes through a pull request the allowlist owner signs off. If the plugin ships
evals/,claude plugin eval NAME@MKTscores it against a no-plugin baseline.Replace the placeholder path in this prompt with your own approved-marketplace list.
How to allowlist marketplaces for the whole team
Section titled “How to allowlist marketplaces for the whole team”In Claude Code, managed settings restrict which marketplaces anyone can add and pre-enable approved plugins:
{ "strictKnownMarketplaces": [ { "source": "github", "repo": "acme/*" } ], "enabledPlugins": { "acme-review@acme-plugins": true }}Build a plugin or a private marketplace covers hosting the team catalogue.
Codex (a [marketplaces] table in managed requirements.toml, checked at rust-v0.157.1) and Cursor (Team Marketplaces) are compared in one policy for every coding agent.
What goes wrong with plugins, and how to recover
Section titled “What goes wrong with plugins, and how to recover”- A pushed fix never reaches teammates. Updates wait for a
versionbump inplugin.json, and third-party marketplaces do not auto-update. Runclaude plugin marketplace update, thenclaude plugin update NAME@MKT, and restart. - A committed plugin is missing on a teammate’s machine. A plugin with an external source still needs
claude plugin install NAME@MKT --scope projectonce per machine. - A private marketplace fails to clone. Claude Code never prompts for credentials; run
gh auth loginandgh auth setup-git.