Skip to content

Marketplaces and registries: where plugins, skills, and MCP servers come from

Plugins, skills, and MCP servers for coding agents come from about a dozen channels: agent-maker marketplaces (claude-plugins-official, openai-curated, cursor-plugins, copilot-plugins), community catalogues (claude-community, awesome-copilot), cross-agent installers (skills.sh, plugins), and MCP registries (the Official MCP Registry, Smithery). A listing proves which catalogue an entry came from, not that the service’s vendor wrote it or that its code is safe.

You need Sentry in your agent. Search the Official MCP Registry for “sentry” and you get 13 servers: one is Sentry’s, at least two others target Sentry’s API from someone else’s namespace, and the rest merely contain the string. Codex’s built-in marketplace offers a plugin named sentry that OpenAI wrote, while Sentry publishes its own under the same name. This page is for developers who install integrations and tech leads who approve them: it shows which channel to use for which artefact and how to check a listing before it runs with your credentials.

  • A table of every major channel with its owner, size on 2026-09-26, and trust level
  • One worked search: finding the Sentry integration in each channel, with the listings that look right and are not
  • A decision table for “which channel for which artefact”
  • A six-step intake review, with two copy-paste prompts, that a tech lead can sign off, and six checks that prove it worked

Which marketplaces and registries exist, and who runs them?

Section titled “Which marketplaces and registries exist, and who runs them?”

The counts below were read from each channel’s catalogue file or API on 2026-09-26. They move weekly, so treat them as scale, not as a leaderboard.

ChannelOwnerArtefactSize (2026-09-26)How you reach it
claude-plugins-officialAnthropicClaude Code plugins314 entriesAdded on first interactive start; /plugin → Discover
claude-communityAnthropic (author-submitted)Claude Code plugins2,282 entriesclaude plugin marketplace add anthropics/claude-plugins-community
anthropic-agent-skillsAnthropicSkill bundles as plugins5 bundlesclaude plugin marketplace add anthropics/skills
knowledge-work-pluginsAnthropicRole plugins, mostly for Cowork121 entriesclaude plugin marketplace add anthropics/knowledge-work-plugins
openai-curated (“Codex official”)OpenAICodex plugins65 entriesBuilt in; /plugins in the Codex TUI
cursor-pluginsCursorCursor plugins94 entries/add-plugin NAME in Agent chat, or the Cursor Marketplace
copilot-pluginsGitHubCopilot CLI plugins, mostly Microsoft 365 and Power Platform17 pluginsBuilt into Copilot CLI
awesome-copilotGitHub org, community contentPlugins, skills, agents, and instructions168 plugins, 426 skillsBuilt into Copilot CLI; also npx skills
skills.sh + skills CLIVercel LabsSkills for 40+ agentsnpm skills 1.7.0npx skills add owner/repo
plugins CLIVercel Labs (npm)Plugins across agentsnpm plugins 1.3.4npx plugins add owner/repo
Official MCP RegistryMCP steering groupMCP server metadata36,178 to 36,184 server names (API v0.1, preview)REST API; clients and aggregators read it
SmitherySmitheryHosted MCP servers and skillsCLI banner: “100K+ AI tools and skills”npx -y @smithery/cli mcp search TERM
PulseMCPPulseMCPMCP server directory“21,810+” to “22,300+” (secondary: page titles, April 2026)Website only
GlamaGlamaMCP registry with A–F scores“91,693” (secondary: page title)Website only

Two more names trip people up. claude-code-plugins is Anthropic’s 13-plugin demo marketplace in anthropics/claude-code, not the official one. The web directory at Claude Marketplace shows install counts and an Anthropic verified badge, and it is where the install counts on this page come from.

What does a listing in each channel prove?

Section titled “What does a listing in each channel prove?”

A marketplace name tells you who publishes the catalogue, not who wrote each entry. Claude Code’s plugin security documentation says so directly: “Anthropic does not control what MCP servers, files, or other software are included in plugins.” Rank every candidate by these tiers before you rank it by stars.

TierWhat the listing provesChannels
A. Vendor first-partyThe service’s own organisation publishes it (getsentry/*, github/*)Vendor repos and vendor marketplaces, whichever catalogue links to them
B. Curated by the agent makerThe agent vendor chose to list it; the author may still be a third partyclaude-plugins-official, openai-curated, cursor-plugins, copilot-plugins
C. Submitted and pinnedThe author submitted it and it passed Anthropic’s automated review; where the entry pins a commit SHA, Claude Code refuses any other commitclaude-community
D. Open catalogue under a big nameAnyone’s contribution, accepted by maintainers; the README tells you to inspect before installingawesome-copilot, third-party marketplaces such as wshobson/agents
E. IndexOnly that the publisher controls the namespace or repoOfficial MCP Registry, Smithery, skills.sh, PulseMCP, and Glama

Claude Code enforces one part of this for you: it accepts the official and community marketplace names only from github.com/anthropics/ repositories, so a third-party repo cannot call itself claude-plugins-official. Nothing else in the table is enforced by a tool. Per the same plugin security documentation, Claude Code runs hooks and MCP servers outside its sandbox, and command hooks execute with your full user permissions, whatever tier they came from.

Find the Sentry integration in each channel

Section titled “Find the Sentry integration in each channel”

Sentry is a good test case because it ships a plugin, a skill library, and a remote MCP server (https://mcp.sentry.dev/mcp), and because several channels list things named “sentry” that Sentry did not write. Everything below was read from each catalogue on 2026-09-26.

ChannelWhat a search for “sentry” returnsPublisherTier
claude-plugins-officialsentry (source getsentry/plugin-claude, pinned SHA) and sentry-cli (from getsentry/cli)SentryA via B
claude-communitysentry-cli (Sentry) and sentry-error-assistant (a personal repo, not Sentry)MixedC
openai-curatedsentry 0.1.2, skills only, “read-only workflow”OpenAI, not SentryB
Sentry’s Codex marketplacesentry@sentry-plugin-marketplace from getsentry/plugin-codex: skills plus the hosted MCP serverSentryA
cursor-pluginsNothing: no Sentry entry among the 94——
awesome-copilotsentry-triage 1.2.0, a Copilot canvas pluginA community author, not SentryD
skills.sh / skills CLIgetsentry/sentry-for-ai: 34 skills (npx skills add getsentry/sentry-for-ai --list)SentryA via E
Official MCP Registry13 servers for GET /v0.1/servers?search=sentry on 2026-09-26; io.github.getsentry/sentry-mcp 0.42.0 is Sentry’s, com.mcparmory/sentry and io.github.friendlygeorge/sentry-mcp-server target Sentry from other namespaces, and the rest (datasentry, flowsentry, …) only share the stringMixedE

Smithery is missing from the table because its API (npx -y @smithery/cli mcp search sentry) was not reachable from the environment this page was written in; read its hits with the tier E rule. For scale on the same date: claude.com showed 38,810 installs for Sentry’s Claude Code plugin, and getsentry/sentry-mcp had 862 GitHub stars (GitHub API).

The pattern holds beyond Sentry: the vendor’s own entry exists in most channels, and it sits next to look-alikes and next to agent-maker rewrites with the same name. Pick the vendor’s entry, then install it in your agent.

Sentry’s plugin bundles its skill library and the hosted MCP server. Install it at project scope so it does not load in every repo you open, then measure what it adds:

Terminal window
claude plugin install sentry@claude-plugins-official --scope project
claude plugin details sentry # component inventory and always-on token cost

If you only want the MCP tools, skip the plugin (the --transport http flag matters; see the traps below):

Terminal window
claude mcp add --transport http sentry https://mcp.sentry.dev/mcp

Plugin skills are namespaced, so they appear as /sentry:SKILL_NAME. The first MCP call opens Sentry’s OAuth flow.

Then check that the integration works on real data, not that it installed. Sentry’s own example prompt, “What are the top errors in the last 24 hours?”, is a good smoke test: a correct setup answers with issue IDs you can open in Sentry, and a broken one answers from the model’s general knowledge.

Which channel should you use for which artefact?

Section titled “Which channel should you use for which artefact?”

Choose the artefact first (plugin, skill or MCP server), then the channel. The first row that matches wins.

You needLook here firstThenAvoid
A vendor’s integration (Sentry, GitHub, Stripe)The vendor’s own repo or marketplaceYour agent maker’s curated marketplace, checking the publisherIndex hits with the vendor’s name in someone else’s namespace
A workflow plugin (review, planning, or TDD)claude-plugins-official, openai-curated, cursor-pluginsclaude-community, then named third-party marketplacesInstalling the same bundle from two channels
A single skill for several agentsThe author’s repo through npx skills addawesome-copilot skillsA skill whose repo has no licence or no recent commits
An MCP serverThe vendor’s docs, then the Official MCP Registry to confirm the namespaceSmithery, PulseMCP, or Glama for discoveryRegistry entries whose repository URL is empty
Something only your team usesA private team marketplace—Public registries

Skills and MCP servers are portable across agents; plugins are only partly portable. Codex 0.157.1 installs from Claude-format marketplaces, and Copilot CLI 1.0.88 accepted trailofbits/skills but rejected wshobson/agents, so test each marketplace in each agent you support.

How a team takes in a new integration: the intake review

Section titled “How a team takes in a new integration: the intake review”

Treat an integration like a dependency that runs with your credentials. The review fits the verify stage of your loop: nothing reaches a shared settings file until these steps pass, and the tech lead or the owner of your allowlist signs off the pull request.

  1. Name the publisher. Resolve every candidate to a repository and compare its owner with the vendor’s GitHub organisation. For Codex, open the plugin’s .codex-plugin/plugin.json and read author; for the MCP Registry, read the namespace (io.github.getsentry/…) and the repository field.

  2. Read what runs. List hooks (hooks/hooks.json), MCP servers (.mcp.json or mcp.json), anything in bin/, and scripts that make network calls. In Claude Code, claude --plugin-dir PATH plugin details NAME prints the inventory without starting a session.

  3. Measure the context cost. Run claude plugin details NAME and note the always-on tokens, then /context in a session, because MCP tool schemas are not in that figure. Over roughly 2,000 always-on tokens, install at project scope only (cut MCP token cost).

  4. Pin the version. Prefer catalogues that pin a commit SHA: on 2026-09-26 all 262 externally sourced entries in claude-plugins-official carried a sha, and claude-community pins nearly every entry. In Codex, add third-party marketplaces with --ref TAG. For skills, commit the installed folder or the lock file so a teammate gets the same text.

  5. Run the smoke test from the previous section and keep its output in the pull request. An integration that installs but cannot answer from live data fails the review.

  6. Record and restrict. Commit the project-scope settings and add the marketplace source to your managed allowlist (strictKnownMarketplaces in Claude Code, with blockedMarketplaces for known-bad sources; see one policy across every agent). Re-run steps 2 and 3 when auto-update or a version bump changes the files.

You do not need to read every skill file to trust the result. Check these instead:

  • Publisher match: every enabled integration resolves to the vendor’s organisation or to a publisher your team approved by name, and the pull request says which.
  • Pinned state: claude plugin list on two laptops shows the same versions. In Codex, compare the installed array of codex plugin list --json; plain codex plugin list also shows uninstalled plugins from every configured marketplace, so do not compare that output (codex-cli 0.157.1).
  • Measured cost: the always-on token figure is in the pull request, and it matches claude plugin details after merge.
  • Live answer: the smoke-test output cites real issue IDs.
  • Measured benefit, where the plugin ships evals: claude plugin eval NAME runs the plugin’s own eval cases with and without it and reports the score delta. Its help text is explicit that a passing bundled suite is not a security vetting, so this complements steps 1 and 2 rather than replacing them.
  • Enforced allowlist: a teammate who tries to add an unlisted marketplace gets a refusal from managed settings, not a warning in chat.

What breaks when you pull integrations from several channels?

Section titled “What breaks when you pull integrations from several channels?”

A skill runs twice or contradicts itself. You installed the same bundle through a plugin marketplace and through npx skills, or from two marketplaces. Run claude plugin list and npx skills list, keep one channel per agent, and uninstall the other copy.

Plugin "NAME" not found in marketplace. The suffix after @ is the marketplace’s name field, not the repository. Run claude plugin marketplace list (or codex plugin marketplace list) and use the name it prints, for example @claude-code-workflows for wshobson/agents.

The files you reviewed changed. By default, auto-update is on for claude-plugins-official and most other official marketplace names, and off for knowledge-work-plugins, the community marketplace and every third-party one. If a reviewed plugin updates itself, repeat steps 2 and 3 of the intake review, or turn auto-update off for that marketplace and update deliberately.

The integration installs but answers from general knowledge. The skill loaded but the MCP server did not connect, usually a missing OAuth sign-in or a wrong transport. Run claude mcp list or codex mcp list, sign in, and rerun the smoke test.

Someone installed a look-alike. Uninstall it with its scope, remove the marketplace if you do not trust its owner, revoke any token the server read, and add its source to blockedMarketplaces in managed settings.

Where to go next with marketplaces and registries

Section titled “Where to go next with marketplaces and registries”