Honestly, I’ve always been pretty casual about installing Claude Code plugins. If something in the community marketplace looked decent, I’d press Y in the /plugin panel and be done with it, with roughly the same mindset as installing a Chrome extension.
Then I read through the official docs page on Plugin security and trust, and a chill ran down my spine. The very first line says it plainly: a plugin you install can execute arbitrary code on your machine with your user privileges.
I’m not trying to scare anyone. Today I’m going to lay out, once and for all, what to check before installing, how to check it, and how to remove a plugin cleanly when you don’t want it anymore. Everything uses the official built-in tools, with nothing extra to install.
First, the math: what can a plugin actually do?
Many people assume a plugin just adds a few slash commands. In reality, a plugin can bundle far more than that:



