Marketplaces and registries: where plugins, skills, and MCP servers come from
Plugins, skills, and MCP servers for coding agents come from about a dozen channels: agent-maker marketplaces (claude-plugins-official, openai-curated, cursor-plugins, copilot-plugins), community catalogues (claude-community, awesome-copilot), cross-agent installers (skills.sh, plugins), and MCP registries (the Official MCP Registry, Smithery). A listing proves which catalogue an entry came from, not that the service’s vendor wrote it or that its code is safe.
You need Sentry in your agent. Search the Official MCP Registry for “sentry” and you get 13 servers: one is Sentry’s, at least two others target Sentry’s API from someone else’s namespace, and the rest merely contain the string. Codex’s built-in marketplace offers a plugin named sentry that OpenAI wrote, while Sentry publishes its own under the same name. This page is for developers who install integrations and tech leads who approve them: it shows which channel to use for which artefact and how to check a listing before it runs with your credentials.
What this marketplace map gives you
Section titled “What this marketplace map gives you”- A table of every major channel with its owner, size on 2026-09-26, and trust level
- One worked search: finding the Sentry integration in each channel, with the listings that look right and are not
- A decision table for “which channel for which artefact”
- A six-step intake review, with two copy-paste prompts, that a tech lead can sign off, and six checks that prove it worked
Which marketplaces and registries exist, and who runs them?
Section titled “Which marketplaces and registries exist, and who runs them?”The counts below were read from each channel’s catalogue file or API on 2026-09-26. They move weekly, so treat them as scale, not as a leaderboard.
| Channel | Owner | Artefact | Size (2026-09-26) | How you reach it |
|---|---|---|---|---|
claude-plugins-official | Anthropic | Claude Code plugins | 314 entries | Added on first interactive start; /plugin → Discover |
claude-community | Anthropic (author-submitted) | Claude Code plugins | 2,282 entries | claude plugin marketplace add anthropics/claude-plugins-community |
anthropic-agent-skills | Anthropic | Skill bundles as plugins | 5 bundles | claude plugin marketplace add anthropics/skills |
knowledge-work-plugins | Anthropic | Role plugins, mostly for Cowork | 121 entries | claude plugin marketplace add anthropics/knowledge-work-plugins |
openai-curated (“Codex official”) | OpenAI | Codex plugins | 65 entries | Built in; /plugins in the Codex TUI |
cursor-plugins | Cursor | Cursor plugins | 94 entries | /add-plugin NAME in Agent chat, or the Cursor Marketplace |
copilot-plugins | GitHub | Copilot CLI plugins, mostly Microsoft 365 and Power Platform | 17 plugins | Built into Copilot CLI |
awesome-copilot | GitHub org, community content | Plugins, skills, agents, and instructions | 168 plugins, 426 skills | Built into Copilot CLI; also npx skills |
skills.sh + skills CLI | Vercel Labs | Skills for 40+ agents | npm skills 1.7.0 | npx skills add owner/repo |
plugins CLI | Vercel Labs (npm) | Plugins across agents | npm plugins 1.3.4 | npx plugins add owner/repo |
| Official MCP Registry | MCP steering group | MCP server metadata | 36,178 to 36,184 server names (API v0.1, preview) | REST API; clients and aggregators read it |
| Smithery | Smithery | Hosted MCP servers and skills | CLI banner: “100K+ AI tools and skills” | npx -y @smithery/cli mcp search TERM |
| PulseMCP | PulseMCP | MCP server directory | “21,810+” to “22,300+” (secondary: page titles, April 2026) | Website only |
| Glama | Glama | MCP registry with A–F scores | “91,693” (secondary: page title) | Website only |
Two more names trip people up. claude-code-plugins is Anthropic’s 13-plugin demo marketplace in anthropics/claude-code, not the official one. The web directory at Claude Marketplace shows install counts and an Anthropic verified badge, and it is where the install counts on this page come from.
What does a listing in each channel prove?
Section titled “What does a listing in each channel prove?”A marketplace name tells you who publishes the catalogue, not who wrote each entry. Claude Code’s plugin security documentation says so directly: “Anthropic does not control what MCP servers, files, or other software are included in plugins.” Rank every candidate by these tiers before you rank it by stars.
| Tier | What the listing proves | Channels |
|---|---|---|
| A. Vendor first-party | The service’s own organisation publishes it (getsentry/*, github/*) | Vendor repos and vendor marketplaces, whichever catalogue links to them |
| B. Curated by the agent maker | The agent vendor chose to list it; the author may still be a third party | claude-plugins-official, openai-curated, cursor-plugins, copilot-plugins |
| C. Submitted and pinned | The author submitted it and it passed Anthropic’s automated review; where the entry pins a commit SHA, Claude Code refuses any other commit | claude-community |
| D. Open catalogue under a big name | Anyone’s contribution, accepted by maintainers; the README tells you to inspect before installing | awesome-copilot, third-party marketplaces such as wshobson/agents |
| E. Index | Only that the publisher controls the namespace or repo | Official MCP Registry, Smithery, skills.sh, PulseMCP, and Glama |
Claude Code enforces one part of this for you: it accepts the official and community marketplace names only from github.com/anthropics/ repositories, so a third-party repo cannot call itself claude-plugins-official. Nothing else in the table is enforced by a tool. Per the same plugin security documentation, Claude Code runs hooks and MCP servers outside its sandbox, and command hooks execute with your full user permissions, whatever tier they came from.
Find the Sentry integration in each channel
Section titled “Find the Sentry integration in each channel”Sentry is a good test case because it ships a plugin, a skill library, and a remote MCP server (https://mcp.sentry.dev/mcp), and because several channels list things named “sentry” that Sentry did not write. Everything below was read from each catalogue on 2026-09-26.
| Channel | What a search for “sentry” returns | Publisher | Tier |
|---|---|---|---|
claude-plugins-official | sentry (source getsentry/plugin-claude, pinned SHA) and sentry-cli (from getsentry/cli) | Sentry | A via B |
claude-community | sentry-cli (Sentry) and sentry-error-assistant (a personal repo, not Sentry) | Mixed | C |
openai-curated | sentry 0.1.2, skills only, “read-only workflow” | OpenAI, not Sentry | B |
| Sentry’s Codex marketplace | sentry@sentry-plugin-marketplace from getsentry/plugin-codex: skills plus the hosted MCP server | Sentry | A |
cursor-plugins | Nothing: no Sentry entry among the 94 | — | — |
awesome-copilot | sentry-triage 1.2.0, a Copilot canvas plugin | A community author, not Sentry | D |
skills.sh / skills CLI | getsentry/sentry-for-ai: 34 skills (npx skills add getsentry/sentry-for-ai --list) | Sentry | A via E |
| Official MCP Registry | 13 servers for GET /v0.1/servers?search=sentry on 2026-09-26; io.github.getsentry/sentry-mcp 0.42.0 is Sentry’s, com.mcparmory/sentry and io.github.friendlygeorge/sentry-mcp-server target Sentry from other namespaces, and the rest (datasentry, flowsentry, …) only share the string | Mixed | E |
Smithery is missing from the table because its API (npx -y @smithery/cli mcp search sentry) was not reachable from the environment this page was written in; read its hits with the tier E rule. For scale on the same date: claude.com showed 38,810 installs for Sentry’s Claude Code plugin, and getsentry/sentry-mcp had 862 GitHub stars (GitHub API).
The pattern holds beyond Sentry: the vendor’s own entry exists in most channels, and it sits next to look-alikes and next to agent-maker rewrites with the same name. Pick the vendor’s entry, then install it in your agent.
Sentry’s plugin bundles its skill library and the hosted MCP server. Install it at project scope so it does not load in every repo you open, then measure what it adds:
claude plugin install sentry@claude-plugins-official --scope projectclaude plugin details sentry # component inventory and always-on token costIf you only want the MCP tools, skip the plugin (the --transport http flag matters; see the traps below):
claude mcp add --transport http sentry https://mcp.sentry.dev/mcpPlugin skills are namespaced, so they appear as /sentry:SKILL_NAME. The first MCP call opens Sentry’s OAuth flow.
The built-in openai-curated entry named sentry is OpenAI’s own skills-only plugin. For Sentry’s plugin, which also wires the MCP server, add Sentry’s marketplace (commands from Sentry’s README; the marketplace name matches its .agents/plugins/marketplace.json):
codex plugin marketplace add getsentry/plugin-codexcodex plugin add sentry@sentry-plugin-marketplacecodex plugin listFor the MCP server alone, register it and sign in:
codex mcp add sentry --url https://mcp.sentry.dev/mcpcodex mcp login sentryCodex has no per-plugin token report (codex-cli 0.157.1), so compare /status context usage in a fresh session before and after.
cursor-plugins has no Sentry entry, so go to the vendor. Sentry’s README for getsentry/plugin-cursor says to add that repository in Cursor Settings → Plugins; its mcp.json points at the hosted server. That path was not run in a Cursor binary for this page.
The route verified here is the skill library, installed into the project for Cursor (and optionally other agents) with Vercel’s CLI:
npx skills add getsentry/sentry-for-ai -s sentry-debug-issue -a cursor -ySkills alone do not connect to Sentry. Add the MCP server to .cursor/mcp.json:
{ "mcpServers": { "sentry": { "url": "https://mcp.sentry.dev/mcp" } } }Then check that the integration works on real data, not that it installed. Sentry’s own example prompt, “What are the top errors in the last 24 hours?”, is a good smoke test: a correct setup answers with issue IDs you can open in Sentry, and a broken one answers from the model’s general knowledge.
Which channel should you use for which artefact?
Section titled “Which channel should you use for which artefact?”Choose the artefact first (plugin, skill or MCP server), then the channel. The first row that matches wins.
| You need | Look here first | Then | Avoid |
|---|---|---|---|
| A vendor’s integration (Sentry, GitHub, Stripe) | The vendor’s own repo or marketplace | Your agent maker’s curated marketplace, checking the publisher | Index hits with the vendor’s name in someone else’s namespace |
| A workflow plugin (review, planning, or TDD) | claude-plugins-official, openai-curated, cursor-plugins | claude-community, then named third-party marketplaces | Installing the same bundle from two channels |
| A single skill for several agents | The author’s repo through npx skills add | awesome-copilot skills | A skill whose repo has no licence or no recent commits |
| An MCP server | The vendor’s docs, then the Official MCP Registry to confirm the namespace | Smithery, PulseMCP, or Glama for discovery | Registry entries whose repository URL is empty |
| Something only your team uses | A private team marketplace | — | Public registries |
Skills and MCP servers are portable across agents; plugins are only partly portable. Codex 0.157.1 installs from Claude-format marketplaces, and Copilot CLI 1.0.88 accepted trailofbits/skills but rejected wshobson/agents, so test each marketplace in each agent you support.
How a team takes in a new integration: the intake review
Section titled “How a team takes in a new integration: the intake review”Treat an integration like a dependency that runs with your credentials. The review fits the verify stage of your loop: nothing reaches a shared settings file until these steps pass, and the tech lead or the owner of your allowlist signs off the pull request.
-
Name the publisher. Resolve every candidate to a repository and compare its owner with the vendor’s GitHub organisation. For Codex, open the plugin’s
.codex-plugin/plugin.jsonand readauthor; for the MCP Registry, read the namespace (io.github.getsentry/…) and therepositoryfield. -
Read what runs. List hooks (
hooks/hooks.json), MCP servers (.mcp.jsonormcp.json), anything inbin/, and scripts that make network calls. In Claude Code,claude --plugin-dir PATH plugin details NAMEprints the inventory without starting a session. -
Measure the context cost. Run
claude plugin details NAMEand note the always-on tokens, then/contextin a session, because MCP tool schemas are not in that figure. Over roughly 2,000 always-on tokens, install at project scope only (cut MCP token cost). -
Pin the version. Prefer catalogues that pin a commit SHA: on 2026-09-26 all 262 externally sourced entries in
claude-plugins-officialcarried asha, andclaude-communitypins nearly every entry. In Codex, add third-party marketplaces with--ref TAG. For skills, commit the installed folder or the lock file so a teammate gets the same text. -
Run the smoke test from the previous section and keep its output in the pull request. An integration that installs but cannot answer from live data fails the review.
-
Record and restrict. Commit the project-scope settings and add the marketplace source to your managed allowlist (
strictKnownMarketplacesin Claude Code, withblockedMarketplacesfor known-bad sources; see one policy across every agent). Re-run steps 2 and 3 when auto-update or a version bump changes the files.
How you know the intake review worked
Section titled “How you know the intake review worked”You do not need to read every skill file to trust the result. Check these instead:
- Publisher match: every enabled integration resolves to the vendor’s organisation or to a publisher your team approved by name, and the pull request says which.
- Pinned state:
claude plugin liston two laptops shows the same versions. In Codex, compare theinstalledarray ofcodex plugin list --json; plaincodex plugin listalso shows uninstalled plugins from every configured marketplace, so do not compare that output (codex-cli 0.157.1). - Measured cost: the always-on token figure is in the pull request, and it matches
claude plugin detailsafter merge. - Live answer: the smoke-test output cites real issue IDs.
- Measured benefit, where the plugin ships evals:
claude plugin eval NAMEruns the plugin’s own eval cases with and without it and reports the score delta. Its help text is explicit that a passing bundled suite is not a security vetting, so this complements steps 1 and 2 rather than replacing them. - Enforced allowlist: a teammate who tries to add an unlisted marketplace gets a refusal from managed settings, not a warning in chat.
What breaks when you pull integrations from several channels?
Section titled “What breaks when you pull integrations from several channels?”A skill runs twice or contradicts itself. You installed the same bundle through a plugin marketplace and through npx skills, or from two marketplaces. Run claude plugin list and npx skills list, keep one channel per agent, and uninstall the other copy.
Plugin "NAME" not found in marketplace. The suffix after @ is the marketplace’s name field, not the repository. Run claude plugin marketplace list (or codex plugin marketplace list) and use the name it prints, for example @claude-code-workflows for wshobson/agents.
The files you reviewed changed. By default, auto-update is on for claude-plugins-official and most other official marketplace names, and off for knowledge-work-plugins, the community marketplace and every third-party one. If a reviewed plugin updates itself, repeat steps 2 and 3 of the intake review, or turn auto-update off for that marketplace and update deliberately.
The integration installs but answers from general knowledge. The skill loaded but the MCP server did not connect, usually a missing OAuth sign-in or a wrong transport. Run claude mcp list or codex mcp list, sign in, and rerun the smoke test.
Someone installed a look-alike. Uninstall it with its scope, remove the marketplace if you do not trust its owner, revoke any token the server read, and add its source to blockedMarketplaces in managed settings.