Skip to content

The plugins worth installing, with usage examples

The plugins most worth installing in September 2026 are the ones from Anthropic’s claude-plugins-official marketplace that add a capability Claude Code lacks without a heavy context bill: Context7, a language-server plugin, security-guidance, commit-commands and claude-md-management together cost about 278 always-on tokens plus Context7’s two MCP tool schemas. Heavier bundles such as Vercel (about 4,217 tokens) belong at project scope.

You open /plugin, see 314 entries in the official marketplace, and install a dozen popular ones, including Vercel, Figma and the PR review toolkit. A week later every session carries more than 8,000 extra tokens, /code-review does not run the plugin you installed, and nobody on the team can say which plugin posts comments on pull requests. This page is for developers choosing plugins for their own machine or one repository: what each popular plugin does, what it can touch, what it costs, and one command to prove it works.

  • The 20 most-installed plugins, ranked by Anthropic’s install counts, dated, with the always-on cost we measured for each
  • What each plugin can touch: the tools its commands allow, its hooks, the servers it connects to and the secrets it reads
  • Which of them also exist for Codex and Cursor, and how to install them there
  • A “starter five” install with a cost comparison you can repeat on your own machine
  • One example per plugin, one plugin-driven feature workflow, and a quarterly audit with claude plugin list, details and prune

Which Claude Code plugins are most installed?

Section titled “Which Claude Code plugins are most installed?”

Install counts come from each plugin’s page on Anthropic’s directory at claude.com/plugins, read on 2026-09-26. Always-on tokens are what claude plugin details NAME reported on Claude Code 2.1.283 the same day, for a fresh install from claude-plugins-official. “What it can touch” comes from the plugin’s own files: allowed-tools in its commands, hooks.json and .mcp.json.

#PluginWhat it addsInstallsAlways-on tokensWhat it can touch
1frontend-designOne skill that sets a design direction before UI code1,134,112~78Nothing beyond the session’s own tools
2superpowers15 workflow skills and a SessionStart hook1,009,371~838A shell hook on every start, clear and compact
3code-review/code-review:code-review, a multi-agent PR review438,525~20Read-only gh pr, gh issue and gh search commands, plus gh pr comment
4context7Context7’s hosted MCP server for current library docs417,801~0 (tool schemas not counted)Sends queries to mcp.context7.com; reads optional CONTEXT7_API_KEY
5code-simplifierOne subagent that refines recently changed code346,763~64Session tools; runs on the opus model alias
6playwrightPlaywright MCP through npx @playwright/mcp@latest319,887~0A local browser; fetches the latest package on each start
7githubGitHub’s hosted MCP server319,381~0GitHub API with GITHUB_PERSONAL_ACCESS_TOKEN
8claude-md-managementAudit and revise CLAUDE.md files287,247~175Reads the repo, edits CLAUDE.md
9feature-devA seven-phase feature command and three subagents256,017~238Read, search and web tools in its subagents
10security-guidanceFive hooks: edit warnings, a review on stop, a commit reviewer241,800~0 (hooks are harness-only)Python hooks; builds a venv under ~/.claude/security/ on first start
11vercel37 skills, hooks and Vercel’s remote MCP227,688~4,217Node hooks on start; Vercel account through OAuth
12typescript-lspTypeScript language server for definitions and references212,522~0Starts typescript-language-server from your PATH
13ralph-loopA Stop hook that feeds the same prompt back until done196,527~84Blocks session exit; writes .claude/ralph-loop.local.md
14claude-code-setupRecommends hooks, skills, MCP servers and subagents for a repo195,067~139Read-only tools plus Bash
15commit-commandscommit, commit-push-pr and clean_gone171,244~103git add, git commit, git push, gh pr create
16figma14 skills and Figma’s remote MCP167,556~2,133Figma account
17supabaseTwo skills and Supabase’s remote MCP118,617~634Supabase projects you authorize
18pr-review-toolkit/pr-review-toolkit:review-pr and six review subagents114,856~2,033Unrestricted Bash, read tools and subagents
19pyright-lspPython language server109,778~0Starts pyright-langserver from your PATH
20chrome-devtools-mcpSeven skills and the Chrome DevTools MCP server102,569~804A local Chrome; pins chrome-devtools-mcp@1.9.0

Two things the counts do not tell you. An install count measures reach, not fit: vercel and figma are only worth their context on a repository that deploys to Vercel or implements Figma designs. And superpowers is a community plugin by Jesse Vincent listed in the official marketplace, not an Anthropic-verified one; the official marketplace carries 6.4.1 while upstream is on 6.4.2.

Which of these plugins also run in Codex and Cursor?

Section titled “Which of these plugins also run in Codex and Cursor?”

Codex’s built-in openai-curated marketplace (65 entries, openai/plugins) and Cursor’s cursor-plugins marketplace (94 entries, cursor/plugins) were read from their manifests on 2026-09-26. Rows marked “vendor README” come from the plugin vendor’s own instructions and were not run in that agent.

PluginCodexCursor
superpowersIn openai-curated/add-plugin superpowers (vendor README)
githubIn openai-curatedIn cursor-plugins
playwrightNot a plugin; add the MCP serverIn cursor-plugins
ralph-loopNot listedCursor’s own ralph-loop in cursor-plugins
vercelIn openai-curatedSupported (vendor README)
figmaIn openai-curated/add-plugin figma (vendor README)
supabaseIn openai-curatedSupported (vendor README)
context7, chrome-devtools-mcpAdd the MCP server directlyAdd the MCP server directly
Anthropic’s own plugins (code-review, feature-dev, commit-commands, the LSP plugins and the rest)Not listedNot listed

Install the starter five and compare their cost

Section titled “Install the starter five and compare their cost”

The starter five cover the gaps most repositories hit first: current library docs, symbol navigation, security warnings on risky edits, commit hygiene and an up-to-date CLAUDE.md. This set assumes a TypeScript repository; swap typescript-lsp for pyright-lsp on Python.

Run these in a terminal. The official marketplace is already registered on your first interactive start; the marketplace add line matters only in scripts and CI.

Terminal window
npm install -g typescript-language-server typescript # the LSP plugin does not bundle the binary
claude plugin marketplace add anthropics/claude-plugins-official
claude plugin install context7@claude-plugins-official
claude plugin install typescript-lsp@claude-plugins-official
claude plugin install security-guidance@claude-plugins-official
claude plugin install commit-commands@claude-plugins-official
claude plugin install claude-md-management@claude-plugins-official
claude plugin details commit-commands

details prints the inventory, the always-on cost and the per-skill cost when invoked:

Component inventory
Skills (3) clean_gone, commit, commit-push-pr
Agents (0)
Hooks (0)
MCP servers (0)
LSP servers (0)
Projected token cost
Always-on: ~103 tok added to every session
Per-component (rounded)
component always-on on-invoke
clean_gone ~70 ~600
commit < 20 ~180
commit-push-pr ~20 ~210

Run /reload-plugins in an open session, or start a new one.

How much do the starter five cost next to the heavy bundles?

Section titled “How much do the starter five cost next to the heavy bundles?”

Measured with claude plugin details on Claude Code 2.1.283, 2026-09-26:

SetPluginsAlways-on tokens
Starter fivecontext7, typescript-lsp, security-guidance, commit-commands, claude-md-management~278 (plus Context7’s tool schemas)
Three popular bundlesvercel, figma, pr-review-toolkit~8,383

The heavy three are not bad plugins, but they cost about 30 times more in every session, including sessions that have nothing to do with Vercel, Figma or pull requests. Install them with --scope project in the repositories that need them, so the cost follows the work.

How do you use each plugin? One worked example each

Section titled “How do you use each plugin? One worked example each”

Every plugin command is namespaced as /PLUGIN:COMMAND. Claude Code 2.1.283 lists only the prefixed form, so /hookify from an old README is /hookify:hookify today.

Plan and build: superpowers, feature-dev, frontend-design, ralph-loop

Section titled “Plan and build: superpowers, feature-dev, frontend-design, ralph-loop”
  • superpowers. Say “I want to add CSV export to the reports page”. The brainstorming skill asks clarifying questions, presents a design in sections, then writes a plan of small tasks and runs them through subagents with test-driven development. See the Superpowers framework page before you let it drive a multi-hour feature; it is heavy for one-line fixes.

  • feature-dev. Run /feature-dev:feature-dev Add per-team API rate limits configurable from the admin page. Code-explorer subagents map the repository, Claude asks questions before designing, proposes architectures, implements after you approve, and ends with a review.

  • frontend-design. Run /frontend-design:frontend-design Build the pricing page for a B2B observability product, dark theme, dense tables. Claude writes an aesthetic direction first, then the code.

  • ralph-loop. It loops until the completion promise appears, so cap it:

    /ralph-loop:ralph-loop "Make all tests in tests/unit pass. Output <promise>COMPLETE</promise> when the test suite is green." --completion-promise "COMPLETE" --max-iterations 20

    The default for --max-iterations is unlimited. Stop a run early with /ralph-loop:cancel-ralph. The autonomous loops page covers when a loop is safe.

Review and verify: code-review, pr-review-toolkit, code-simplifier, security-guidance

Section titled “Review and verify: code-review, pr-review-toolkit, code-simplifier, security-guidance”
  • code-review. On a pull request branch with gh signed in, run /code-review:code-review. It checks eligibility, launches five parallel reviewers (CLAUDE.md compliance, obvious bugs, git history, earlier PR comments, code comments), scores each finding from 0 to 100, drops everything below 80, and posts one PR comment. If nothing clears 80, it posts nothing.
  • pr-review-toolkit. Run /pr-review-toolkit:review-pr tests errors to run only the test-coverage and silent-failure reviewers on your changes. The aspects are comments, tests, errors, types, code, simplify and all.
  • code-simplifier. After a feature is finished, ask “use the code-simplifier agent on the files I changed in this branch”. It rewrites for readability and is meant to leave behaviour unchanged, so run the tests afterwards.
  • security-guidance. Ask Claude to “add an endpoint that fetches a user-supplied URL and returns the body”. When the turn ends, the stop-review hook flags the server-side request forgery risk and Claude fixes it before you commit. Put your organization’s rules in .claude/claude-security-guidance.md.

Context and docs: context7, typescript-lsp and pyright-lsp, claude-md-management, claude-code-setup

Section titled “Context and docs: context7, typescript-lsp and pyright-lsp, claude-md-management, claude-code-setup”
  • context7. Ask “How do I set up authentication in Next.js 15? use context7”. Claude calls resolve-library-id, then query-docs for that version, and answers from current docs instead of training data. Set CONTEXT7_API_KEY if you need higher rate limits. The Context7 page covers pinning a library ID.
  • typescript-lsp and pyright-lsp. Ask “find every caller of getAccessStatus and tell me which ones ignore the error branch”. Claude resolves references through the language server instead of grepping text, which matters when a name is overloaded or re-exported.
  • claude-md-management. At the end of a session, run /claude-md-management:revise-claude-md to write what Claude had to discover (commands, gotchas) into CLAUDE.md. For periodic upkeep, ask “audit my CLAUDE.md files” and review the proposed edits as a diff.
  • claude-code-setup. Ask “recommend automations for this project”. It scans the repository and recommends one or two hooks, skills, MCP servers and subagents, each with a reason, and changes no files.

Git and external systems: commit-commands, github, playwright, chrome-devtools-mcp, figma, supabase, vercel

Section titled “Git and external systems: commit-commands, github, playwright, chrome-devtools-mcp, figma, supabase, vercel”
  • commit-commands. Run /commit-commands:commit-push-pr. Claude stages, writes a message in the repository’s style based on the last 10 commits, pushes and opens a PR. After merges, /commit-commands:clean_gone deletes local branches whose remote is gone, including their worktrees.
  • github. Export GITHUB_PERSONAL_ACCESS_TOKEN first; the plugin reads that exact name, not GITHUB_TOKEN. Then ask “list open issues labelled bug created this week and draft a triage table”.
  • playwright. Ask “open http://localhost:4321/pricing, click Start trial, fill the form with test data and screenshot the confirmation”. Claude drives a real browser and returns a screenshot.
  • chrome-devtools-mcp. Run /chrome-devtools-mcp:debug-optimize-lcp against http://localhost:4321/. Claude records a trace and names the Largest Contentful Paint element and its blocker.
  • figma. Paste a Figma frame URL and ask “implement this frame as a React component using our existing Button and Card”. Claude fetches the design context through Figma’s MCP server and maps it to your components.
  • supabase. Ask “list tables without row-level security policies in my staging project and propose policies”. Point it at staging, never at production, until you have read what it proposes.
  • vercel. Ask “check why my last preview deployment failed and show the build log”. Claude fetches the deployment and its logs through Vercel’s MCP server.

A feature from plan to merged PR with plugins

Section titled “A feature from plan to merged PR with plugins”

Plugins earn their place when each owns a step and leaves evidence. Here is the loop for one feature in a TypeScript repository, with the starter five plus feature-dev and pr-review-toolkit at project scope.

  1. Plan. Run /feature-dev:feature-dev with the feature and its acceptance criteria. Approve the architecture before any code is written; the written plan is the first artifact.
  2. Build. Claude implements with typescript-lsp resolving symbols and Context7 answering library questions. security-guidance warns on risky edits as they happen.
  3. Verify. The test suite, type checker and linter are the gate, not the plugins. security-guidance reviews the diff when the turn stops; fix its findings before you commit.
  4. Review. Run /pr-review-toolkit:review-pr tests errors locally, with the prompt above so every finding becomes a test.
  5. Ship. Run /commit-commands:commit-push-pr, then /code-review:code-review on the open PR so a second reviewer comments before a human looks.
  6. Learn. Run /claude-md-management:revise-claude-md so the next session starts with what this one discovered.

The human sign-off stays where it is in your process: the PR author owns the tests and acceptance criteria, and the reviewer approves on the evidence (green CI, the review comment and the finding-to-test table) rather than by reading every line. The agent PR review workflow covers what that reviewer checks.

How do you prove a plugin earns its place?

Section titled “How do you prove a plugin earns its place?”

A plugin that feels helpful is not evidence. Three checks are:

  • Cost. claude plugin details NAME for skills and agents, /context in a session for MCP servers. Anything above about 2,000 always-on tokens goes to project scope.
  • Outcome. When a plugin ships an evals/ folder, claude plugin eval NAME@MARKETPLACE runs its cases and adds a no-plugin baseline arm, so you see whether the plugin changes results. It runs the plugin on your machine as you, so run it only on plugins you already trust.
  • Blast radius. Read the “What it can touch” column above for the plugin’s current version. pr-review-toolkit allows unrestricted Bash; code-review can only run gh commands and post a comment. Trust follows from what a plugin is allowed to do, not from its install count. Skill supply-chain security covers the review.

Which plugins outside the official marketplace are worth a look?

Section titled “Which plugins outside the official marketplace are worth a look?”

These were verified on 2026-09-26 but are not in claude-plugins-official, so they have no install count; the popularity figure is GitHub stars. Third-party marketplaces are not reviewed by Anthropic, and their auto-update is off by default.

PluginWhy you would install itInstall (Claude Code)Stars, 2026-09-26
codex@openai-codexOpenAI’s plugin runs Codex reviews from inside Claude Code: /codex:review, /codex:adversarial-reviewclaude plugin marketplace add openai/codex-plugin-cc, then claude plugin install codex@openai-codex33,594
compound-engineeringEvery’s plan, work, review and compound loop, about 2,989 always-on tokensclaude plugin marketplace add EveryInc/compound-engineering-plugin, then claude plugin install compound-engineering@compound-engineering-plugin25,271
ponytailHooks that push the agent toward the smallest change and the standard library, about 983 always-on tokensclaude plugin marketplace add DietrichGebert/ponytail, then claude plugin install ponytail@ponytail146,068
differential-review (Trail of Bits)Security-focused diff review from a 44-plugin security marketplace that Codex also readsclaude plugin marketplace add trailofbits/skills, then claude plugin install differential-review@trailofbits7,251 (marketplace repo)

compound-engineering and ponytail also installed in Codex 0.157.1 with codex plugin marketplace add and codex plugin add. For memory plugins such as claude-mem, which by default offers a hosted service sign-in, read memory plugins before installing on company code. The Compound Engineering page covers that loop in depth.

Plugins accumulate. A quarterly audit keeps the set small, current and justified. Allow about 30 minutes per repository.

  1. Inventory. List what is installed, where, and at which version:

    Terminal window
    claude plugin list --json > plugins-$(date +%F).json

    Each entry records the plugin id, version, scope and whether it is enabled.

  2. Measure. Run claude plugin details NAME for each enabled plugin and record the always-on figure next to last quarter’s. A jump usually means a new version added skills.

  3. Decide. Keep a plugin only if someone used it this quarter for work that needed it. Move anything over about 2,000 always-on tokens from user scope to project scope. Disable what you are unsure about, and remove what nobody used:

    Terminal window
    claude plugin disable vercel@claude-plugins-official
    claude plugin uninstall figma@claude-plugins-official
    claude plugin prune --dry-run

    prune removes plugins that were installed automatically as dependencies of others and are no longer needed. It does not remove plugins you installed yourself. Run it with --dry-run first, and add -y only in non-interactive scripts.

  4. Refresh. Pull new catalogue versions and update what you kept, then restart:

    Terminal window
    claude plugin marketplace update
    claude plugin update commit-commands@claude-plugins-official
  5. Record. Commit the project-scope changes in .claude/settings.json through a pull request, so the tech lead who owns the allowlist signs off. The plugins overview covers the team allowlist.

In Codex, codex plugin list shows each plugin as installed, enabled or installed, disabled with its version, codex plugin remove NAME@MARKETPLACE uninstalls, and codex plugin marketplace upgrade refreshes catalogues. Codex has no details or prune equivalent in 0.157.1.

Section titled “What goes wrong after you install popular plugins”
  • Sessions feel slower and compact sooner. Run claude plugin details on each enabled plugin and /context in a session. Disable the largest bundle, start a new session and compare. Reinstall it at --scope project only where it is used.
  • A plugin command “does not exist”. Type / and the plugin name to see its real commands. README examples often predate namespacing.
  • The LSP plugin does nothing. Check that typescript-language-server or pyright-langserver runs from the same shell that starts Claude Code. Install it globally, then restart.
  • The first session after installing security-guidance stalls. Its SessionStart hook builds a Python virtual environment under ~/.claude/security/ and installs the Claude Agent SDK there once, with a 180-second timeout. Let it finish. In shared-worktree multi-agent setups, set ENABLE_STOP_REVIEW=0 so parallel agents do not each review the same diff.
  • ralph-loop will not stop after the session is gone. Delete .claude/ralph-loop.local.md.
  • code-review posted nothing. That is the designed result when no finding scores 80 or more, or when the PR is closed, a draft or already reviewed. Check gh auth status if you expected a comment.