The plugins worth installing, with usage examples
The plugins most worth installing in September 2026 are the ones from Anthropic’s claude-plugins-official marketplace that add a capability Claude Code lacks without a heavy context bill: Context7, a language-server plugin, security-guidance, commit-commands and claude-md-management together cost about 278 always-on tokens plus Context7’s two MCP tool schemas. Heavier bundles such as Vercel (about 4,217 tokens) belong at project scope.
You open /plugin, see 314 entries in the official marketplace, and install a dozen popular ones, including Vercel, Figma and the PR review toolkit. A week later every session carries more than 8,000 extra tokens, /code-review does not run the plugin you installed, and nobody on the team can say which plugin posts comments on pull requests. This page is for developers choosing plugins for their own machine or one repository: what each popular plugin does, what it can touch, what it costs, and one command to prove it works.
What this plugin catalogue gives you
Section titled “What this plugin catalogue gives you”- The 20 most-installed plugins, ranked by Anthropic’s install counts, dated, with the always-on cost we measured for each
- What each plugin can touch: the tools its commands allow, its hooks, the servers it connects to and the secrets it reads
- Which of them also exist for Codex and Cursor, and how to install them there
- A “starter five” install with a cost comparison you can repeat on your own machine
- One example per plugin, one plugin-driven feature workflow, and a quarterly audit with
claude plugin list,detailsandprune
Which Claude Code plugins are most installed?
Section titled “Which Claude Code plugins are most installed?”Install counts come from each plugin’s page on Anthropic’s directory at claude.com/plugins, read on 2026-09-26. Always-on tokens are what claude plugin details NAME reported on Claude Code 2.1.283 the same day, for a fresh install from claude-plugins-official. “What it can touch” comes from the plugin’s own files: allowed-tools in its commands, hooks.json and .mcp.json.
| # | Plugin | What it adds | Installs | Always-on tokens | What it can touch |
|---|---|---|---|---|---|
| 1 | frontend-design | One skill that sets a design direction before UI code | 1,134,112 | ~78 | Nothing beyond the session’s own tools |
| 2 | superpowers | 15 workflow skills and a SessionStart hook | 1,009,371 | ~838 | A shell hook on every start, clear and compact |
| 3 | code-review | /code-review:code-review, a multi-agent PR review | 438,525 | ~20 | Read-only gh pr, gh issue and gh search commands, plus gh pr comment |
| 4 | context7 | Context7’s hosted MCP server for current library docs | 417,801 | ~0 (tool schemas not counted) | Sends queries to mcp.context7.com; reads optional CONTEXT7_API_KEY |
| 5 | code-simplifier | One subagent that refines recently changed code | 346,763 | ~64 | Session tools; runs on the opus model alias |
| 6 | playwright | Playwright MCP through npx @playwright/mcp@latest | 319,887 | ~0 | A local browser; fetches the latest package on each start |
| 7 | github | GitHub’s hosted MCP server | 319,381 | ~0 | GitHub API with GITHUB_PERSONAL_ACCESS_TOKEN |
| 8 | claude-md-management | Audit and revise CLAUDE.md files | 287,247 | ~175 | Reads the repo, edits CLAUDE.md |
| 9 | feature-dev | A seven-phase feature command and three subagents | 256,017 | ~238 | Read, search and web tools in its subagents |
| 10 | security-guidance | Five hooks: edit warnings, a review on stop, a commit reviewer | 241,800 | ~0 (hooks are harness-only) | Python hooks; builds a venv under ~/.claude/security/ on first start |
| 11 | vercel | 37 skills, hooks and Vercel’s remote MCP | 227,688 | ~4,217 | Node hooks on start; Vercel account through OAuth |
| 12 | typescript-lsp | TypeScript language server for definitions and references | 212,522 | ~0 | Starts typescript-language-server from your PATH |
| 13 | ralph-loop | A Stop hook that feeds the same prompt back until done | 196,527 | ~84 | Blocks session exit; writes .claude/ralph-loop.local.md |
| 14 | claude-code-setup | Recommends hooks, skills, MCP servers and subagents for a repo | 195,067 | ~139 | Read-only tools plus Bash |
| 15 | commit-commands | commit, commit-push-pr and clean_gone | 171,244 | ~103 | git add, git commit, git push, gh pr create |
| 16 | figma | 14 skills and Figma’s remote MCP | 167,556 | ~2,133 | Figma account |
| 17 | supabase | Two skills and Supabase’s remote MCP | 118,617 | ~634 | Supabase projects you authorize |
| 18 | pr-review-toolkit | /pr-review-toolkit:review-pr and six review subagents | 114,856 | ~2,033 | Unrestricted Bash, read tools and subagents |
| 19 | pyright-lsp | Python language server | 109,778 | ~0 | Starts pyright-langserver from your PATH |
| 20 | chrome-devtools-mcp | Seven skills and the Chrome DevTools MCP server | 102,569 | ~804 | A local Chrome; pins chrome-devtools-mcp@1.9.0 |
Two things the counts do not tell you. An install count measures reach, not fit: vercel and figma are only worth their context on a repository that deploys to Vercel or implements Figma designs. And superpowers is a community plugin by Jesse Vincent listed in the official marketplace, not an Anthropic-verified one; the official marketplace carries 6.4.1 while upstream is on 6.4.2.
Which of these plugins also run in Codex and Cursor?
Section titled “Which of these plugins also run in Codex and Cursor?”Codex’s built-in openai-curated marketplace (65 entries, openai/plugins) and Cursor’s cursor-plugins marketplace (94 entries, cursor/plugins) were read from their manifests on 2026-09-26. Rows marked “vendor README” come from the plugin vendor’s own instructions and were not run in that agent.
| Plugin | Codex | Cursor |
|---|---|---|
superpowers | In openai-curated | /add-plugin superpowers (vendor README) |
github | In openai-curated | In cursor-plugins |
playwright | Not a plugin; add the MCP server | In cursor-plugins |
ralph-loop | Not listed | Cursor’s own ralph-loop in cursor-plugins |
vercel | In openai-curated | Supported (vendor README) |
figma | In openai-curated | /add-plugin figma (vendor README) |
supabase | In openai-curated | Supported (vendor README) |
context7, chrome-devtools-mcp | Add the MCP server directly | Add the MCP server directly |
Anthropic’s own plugins (code-review, feature-dev, commit-commands, the LSP plugins and the rest) | Not listed | Not listed |
Install the starter five and compare their cost
Section titled “Install the starter five and compare their cost”The starter five cover the gaps most repositories hit first: current library docs, symbol navigation, security warnings on risky edits, commit hygiene and an up-to-date CLAUDE.md. This set assumes a TypeScript repository; swap typescript-lsp for pyright-lsp on Python.
Run these in a terminal. The official marketplace is already registered on your first interactive start; the marketplace add line matters only in scripts and CI.
npm install -g typescript-language-server typescript # the LSP plugin does not bundle the binaryclaude plugin marketplace add anthropics/claude-plugins-officialclaude plugin install context7@claude-plugins-officialclaude plugin install typescript-lsp@claude-plugins-officialclaude plugin install security-guidance@claude-plugins-officialclaude plugin install commit-commands@claude-plugins-officialclaude plugin install claude-md-management@claude-plugins-officialclaude plugin details commit-commandsdetails prints the inventory, the always-on cost and the per-skill cost when invoked:
Component inventory Skills (3) clean_gone, commit, commit-push-pr Agents (0) Hooks (0) MCP servers (0) LSP servers (0)
Projected token cost Always-on: ~103 tok added to every session
Per-component (rounded) component always-on on-invoke clean_gone ~70 ~600 commit < 20 ~180 commit-push-pr ~20 ~210Run /reload-plugins in an open session, or start a new one.
On 2026-09-26, openai-curated (openai/plugins) had no LSP, commit or CLAUDE.md plugins, so the Codex version of the starter set is two MCP servers plus the built-in reviewer:
codex mcp add context7 --url https://mcp.context7.com/mcpcodex mcp add playwright -- npx @playwright/mcp@latestcodex mcp listFor review, run codex review from the terminal or /review in the TUI (built in, checked on 0.157.1).
For GitHub, open the TUI, run /plugins, search for github and install it from openai-curated. The CLI form codex plugin add github@openai-curated was not verified on 2026-09-26 because the listing needs a signed-in account. Codex has no per-plugin cost report (checked on 0.157.1), so read what each plugin’s cache folder under ~/.codex/plugins/cache/ loads before you keep it.
In Agent chat, type /add-plugin github and /add-plugin playwright; both are in Cursor’s first-party cursor-plugins marketplace. Add Context7 as an MCP server, as the Context7 page shows. Cursor’s in-app cost and uninstall controls were not verified on 2026-09-26 because cursor.com was unreachable from the writing environment.
How much do the starter five cost next to the heavy bundles?
Section titled “How much do the starter five cost next to the heavy bundles?”Measured with claude plugin details on Claude Code 2.1.283, 2026-09-26:
| Set | Plugins | Always-on tokens |
|---|---|---|
| Starter five | context7, typescript-lsp, security-guidance, commit-commands, claude-md-management | ~278 (plus Context7’s tool schemas) |
| Three popular bundles | vercel, figma, pr-review-toolkit | ~8,383 |
The heavy three are not bad plugins, but they cost about 30 times more in every session, including sessions that have nothing to do with Vercel, Figma or pull requests. Install them with --scope project in the repositories that need them, so the cost follows the work.
How do you use each plugin? One worked example each
Section titled “How do you use each plugin? One worked example each”Every plugin command is namespaced as /PLUGIN:COMMAND. Claude Code 2.1.283 lists only the prefixed form, so /hookify from an old README is /hookify:hookify today.
Plan and build: superpowers, feature-dev, frontend-design, ralph-loop
Section titled “Plan and build: superpowers, feature-dev, frontend-design, ralph-loop”-
superpowers. Say “I want to add CSV export to the reports page”. The brainstorming skill asks clarifying questions, presents a design in sections, then writes a plan of small tasks and runs them through subagents with test-driven development. See the Superpowers framework page before you let it drive a multi-hour feature; it is heavy for one-line fixes. -
feature-dev. Run/feature-dev:feature-dev Add per-team API rate limits configurable from the admin page. Code-explorer subagents map the repository, Claude asks questions before designing, proposes architectures, implements after you approve, and ends with a review. -
frontend-design. Run/frontend-design:frontend-design Build the pricing page for a B2B observability product, dark theme, dense tables. Claude writes an aesthetic direction first, then the code. -
ralph-loop. It loops until the completion promise appears, so cap it:/ralph-loop:ralph-loop "Make all tests in tests/unit pass. Output <promise>COMPLETE</promise> when the test suite is green." --completion-promise "COMPLETE" --max-iterations 20The default for
--max-iterationsis unlimited. Stop a run early with/ralph-loop:cancel-ralph. The autonomous loops page covers when a loop is safe.
Review and verify: code-review, pr-review-toolkit, code-simplifier, security-guidance
Section titled “Review and verify: code-review, pr-review-toolkit, code-simplifier, security-guidance”code-review. On a pull request branch withghsigned in, run/code-review:code-review. It checks eligibility, launches five parallel reviewers (CLAUDE.mdcompliance, obvious bugs, git history, earlier PR comments, code comments), scores each finding from 0 to 100, drops everything below 80, and posts one PR comment. If nothing clears 80, it posts nothing.pr-review-toolkit. Run/pr-review-toolkit:review-pr tests errorsto run only the test-coverage and silent-failure reviewers on your changes. The aspects arecomments,tests,errors,types,code,simplifyandall.code-simplifier. After a feature is finished, ask “use the code-simplifier agent on the files I changed in this branch”. It rewrites for readability and is meant to leave behaviour unchanged, so run the tests afterwards.security-guidance. Ask Claude to “add an endpoint that fetches a user-supplied URL and returns the body”. When the turn ends, the stop-review hook flags the server-side request forgery risk and Claude fixes it before you commit. Put your organization’s rules in.claude/claude-security-guidance.md.
Context and docs: context7, typescript-lsp and pyright-lsp, claude-md-management, claude-code-setup
Section titled “Context and docs: context7, typescript-lsp and pyright-lsp, claude-md-management, claude-code-setup”context7. Ask “How do I set up authentication in Next.js 15? use context7”. Claude callsresolve-library-id, thenquery-docsfor that version, and answers from current docs instead of training data. SetCONTEXT7_API_KEYif you need higher rate limits. The Context7 page covers pinning a library ID.typescript-lspandpyright-lsp. Ask “find every caller ofgetAccessStatusand tell me which ones ignore the error branch”. Claude resolves references through the language server instead of grepping text, which matters when a name is overloaded or re-exported.claude-md-management. At the end of a session, run/claude-md-management:revise-claude-mdto write what Claude had to discover (commands, gotchas) intoCLAUDE.md. For periodic upkeep, ask “audit my CLAUDE.md files” and review the proposed edits as a diff.claude-code-setup. Ask “recommend automations for this project”. It scans the repository and recommends one or two hooks, skills, MCP servers and subagents, each with a reason, and changes no files.
Git and external systems: commit-commands, github, playwright, chrome-devtools-mcp, figma, supabase, vercel
Section titled “Git and external systems: commit-commands, github, playwright, chrome-devtools-mcp, figma, supabase, vercel”commit-commands. Run/commit-commands:commit-push-pr. Claude stages, writes a message in the repository’s style based on the last 10 commits, pushes and opens a PR. After merges,/commit-commands:clean_gonedeletes local branches whose remote is gone, including their worktrees.github. ExportGITHUB_PERSONAL_ACCESS_TOKENfirst; the plugin reads that exact name, notGITHUB_TOKEN. Then ask “list open issues labelled bug created this week and draft a triage table”.playwright. Ask “open http://localhost:4321/pricing, click Start trial, fill the form with test data and screenshot the confirmation”. Claude drives a real browser and returns a screenshot.chrome-devtools-mcp. Run/chrome-devtools-mcp:debug-optimize-lcpagainsthttp://localhost:4321/. Claude records a trace and names the Largest Contentful Paint element and its blocker.figma. Paste a Figma frame URL and ask “implement this frame as a React component using our existing Button and Card”. Claude fetches the design context through Figma’s MCP server and maps it to your components.supabase. Ask “list tables without row-level security policies in my staging project and propose policies”. Point it at staging, never at production, until you have read what it proposes.vercel. Ask “check why my last preview deployment failed and show the build log”. Claude fetches the deployment and its logs through Vercel’s MCP server.
A feature from plan to merged PR with plugins
Section titled “A feature from plan to merged PR with plugins”Plugins earn their place when each owns a step and leaves evidence. Here is the loop for one feature in a TypeScript repository, with the starter five plus feature-dev and pr-review-toolkit at project scope.
- Plan. Run
/feature-dev:feature-devwith the feature and its acceptance criteria. Approve the architecture before any code is written; the written plan is the first artifact. - Build. Claude implements with
typescript-lspresolving symbols and Context7 answering library questions.security-guidancewarns on risky edits as they happen. - Verify. The test suite, type checker and linter are the gate, not the plugins.
security-guidancereviews the diff when the turn stops; fix its findings before you commit. - Review. Run
/pr-review-toolkit:review-pr tests errorslocally, with the prompt above so every finding becomes a test. - Ship. Run
/commit-commands:commit-push-pr, then/code-review:code-reviewon the open PR so a second reviewer comments before a human looks. - Learn. Run
/claude-md-management:revise-claude-mdso the next session starts with what this one discovered.
The human sign-off stays where it is in your process: the PR author owns the tests and acceptance criteria, and the reviewer approves on the evidence (green CI, the review comment and the finding-to-test table) rather than by reading every line. The agent PR review workflow covers what that reviewer checks.
How do you prove a plugin earns its place?
Section titled “How do you prove a plugin earns its place?”A plugin that feels helpful is not evidence. Three checks are:
- Cost.
claude plugin details NAMEfor skills and agents,/contextin a session for MCP servers. Anything above about 2,000 always-on tokens goes to project scope. - Outcome. When a plugin ships an
evals/folder,claude plugin eval NAME@MARKETPLACEruns its cases and adds a no-plugin baseline arm, so you see whether the plugin changes results. It runs the plugin on your machine as you, so run it only on plugins you already trust. - Blast radius. Read the “What it can touch” column above for the plugin’s current version.
pr-review-toolkitallows unrestricted Bash;code-reviewcan only runghcommands and post a comment. Trust follows from what a plugin is allowed to do, not from its install count. Skill supply-chain security covers the review.
Which plugins outside the official marketplace are worth a look?
Section titled “Which plugins outside the official marketplace are worth a look?”These were verified on 2026-09-26 but are not in claude-plugins-official, so they have no install count; the popularity figure is GitHub stars. Third-party marketplaces are not reviewed by Anthropic, and their auto-update is off by default.
| Plugin | Why you would install it | Install (Claude Code) | Stars, 2026-09-26 |
|---|---|---|---|
codex@openai-codex | OpenAI’s plugin runs Codex reviews from inside Claude Code: /codex:review, /codex:adversarial-review | claude plugin marketplace add openai/codex-plugin-cc, then claude plugin install codex@openai-codex | 33,594 |
compound-engineering | Every’s plan, work, review and compound loop, about 2,989 always-on tokens | claude plugin marketplace add EveryInc/compound-engineering-plugin, then claude plugin install compound-engineering@compound-engineering-plugin | 25,271 |
ponytail | Hooks that push the agent toward the smallest change and the standard library, about 983 always-on tokens | claude plugin marketplace add DietrichGebert/ponytail, then claude plugin install ponytail@ponytail | 146,068 |
differential-review (Trail of Bits) | Security-focused diff review from a 44-plugin security marketplace that Codex also reads | claude plugin marketplace add trailofbits/skills, then claude plugin install differential-review@trailofbits | 7,251 (marketplace repo) |
compound-engineering and ponytail also installed in Codex 0.157.1 with codex plugin marketplace add and codex plugin add. For memory plugins such as claude-mem, which by default offers a hosted service sign-in, read memory plugins before installing on company code. The Compound Engineering page covers that loop in depth.
Run a quarterly plugin audit
Section titled “Run a quarterly plugin audit”Plugins accumulate. A quarterly audit keeps the set small, current and justified. Allow about 30 minutes per repository.
-
Inventory. List what is installed, where, and at which version:
Terminal window claude plugin list --json > plugins-$(date +%F).jsonEach entry records the plugin id, version, scope and whether it is enabled.
-
Measure. Run
claude plugin details NAMEfor each enabled plugin and record the always-on figure next to last quarter’s. A jump usually means a new version added skills. -
Decide. Keep a plugin only if someone used it this quarter for work that needed it. Move anything over about 2,000 always-on tokens from user scope to project scope. Disable what you are unsure about, and remove what nobody used:
Terminal window claude plugin disable vercel@claude-plugins-officialclaude plugin uninstall figma@claude-plugins-officialclaude plugin prune --dry-runpruneremoves plugins that were installed automatically as dependencies of others and are no longer needed. It does not remove plugins you installed yourself. Run it with--dry-runfirst, and add-yonly in non-interactive scripts. -
Refresh. Pull new catalogue versions and update what you kept, then restart:
Terminal window claude plugin marketplace updateclaude plugin update commit-commands@claude-plugins-official -
Record. Commit the project-scope changes in
.claude/settings.jsonthrough a pull request, so the tech lead who owns the allowlist signs off. The plugins overview covers the team allowlist.
In Codex, codex plugin list shows each plugin as installed, enabled or installed, disabled with its version, codex plugin remove NAME@MARKETPLACE uninstalls, and codex plugin marketplace upgrade refreshes catalogues. Codex has no details or prune equivalent in 0.157.1.
What goes wrong after you install popular plugins
Section titled “What goes wrong after you install popular plugins”- Sessions feel slower and compact sooner. Run
claude plugin detailson each enabled plugin and/contextin a session. Disable the largest bundle, start a new session and compare. Reinstall it at--scope projectonly where it is used. - A plugin command “does not exist”. Type
/and the plugin name to see its real commands. README examples often predate namespacing. - The LSP plugin does nothing. Check that
typescript-language-serverorpyright-langserverruns from the same shell that starts Claude Code. Install it globally, then restart. - The first session after installing
security-guidancestalls. ItsSessionStarthook builds a Python virtual environment under~/.claude/security/and installs the Claude Agent SDK there once, with a 180-second timeout. Let it finish. In shared-worktree multi-agent setups, setENABLE_STOP_REVIEW=0so parallel agents do not each review the same diff. ralph-loopwill not stop after the session is gone. Delete.claude/ralph-loop.local.md.code-reviewposted nothing. That is the designed result when no finding scores 80 or more, or when the PR is closed, a draft or already reviewed. Checkgh auth statusif you expected a comment.