Note · Integration Best Practices

Your Claude Code plugins can change afteryou install them. Here's how to check

David He, FounderOctober 8, 20265 min read

A Claude Code plugin can change after you install it. Stripe's added scripts that ran on every message, six months later. Three checks I run now.

A plugin you said yes to once can be running different code today, because plugins from Anthropic's official marketplace update themselves by default. Stripe's added scripts that ran on every message I sent my coding agent, six months after I installed it, and checking it on install day would not have shown them.

How I found out

If you've ever installed a Claude Code plugin, it can change after you say yes. I installed Stripe's in March. In September, an automatic update added scripts that ran on every message I sent my coding agent.

I found out on a Wednesday night. I told my agent to stop a task, and it ended its reply by offering to send Stripe feedback about an error it hit while checking on a client's invoice.

The next morning I asked it, "Is this Stripe asking me for feedback or is this something else?"

I do client work with strict privacy rules, so my next question was whether everything I type goes to Stripe.

What the scripts actually did

It doesn't. My agent read all 627 lines of the plugin's scripts.

One runs on every message, and about 1 time in 100 it checks whether Stripe came up in my last exchange. If it did, it adds a note to my agent's input asking it to offer feedback and get my approval first. Every one of those notes told the agent to show me the feedback and ask before sending anything.

Another checks my Stripe login when a session starts. The rest ask for feedback when a Stripe tool fails, or tell Stripe which of its skills I used. In the version I had, the plugin hooked into five different moments in a session, including every message.

None of them sent Stripe what I typed. I still uninstalled the plugin, then sent the feedback. It was about a confusing error message: a restricted key without permission to read payments got "Missing required param: client_secret" instead of a permissions error.

Stripe's plugin was the exception on my machine. Of the 21 other plugins I have installed that ship skills, none runs a hook on every message.

Why checking it on install day wasn't enough

Claude Code's plugin documentation says installing a plugin adds its skills, agents, hooks and MCP servers to your machine. Skills are instructions your agent reads. Hooks are scripts that run on their own at set moments. MCP servers connect your agent to outside services.

The security page is blunt about what that means: "A Claude Code plugin you install can execute arbitrary code on your machine with your user privileges."

It also says that after an automatic update, "the files you reviewed can change on disk." Plugins from Anthropic's official marketplace update themselves by default.

That's what happened to me. I installed Stripe's plugin on March 7. Stripe added these scripts on September 9, six months after my install, and the update came in on its own. Checking the plugin in March wouldn't have shown them.

It keeps moving, too. On October 7 Stripe changed the startup checks again to opt out of its command-line tool's telemetry. The every-message hook is still in the plugin today.

Anthropic's own install warning says it "cannot verify that they will work as intended or that they won't change." The marketplace tells you who publishes a plugin. It doesn't tell you what the plugin runs next month.

What I check now

Step 1: Look at what's running today

Run claude plugin details followed by the plugin's name in your terminal. It lists the skills, hooks and servers in the installed copy, and the event each hook runs on. Typing /hooks inside Claude Code shows the same hooks, labeled with where each one came from.

Look for UserPromptSubmit. That's the event that fires on every message you send, before Claude reads it, and Stripe's plugin had a hook on it.

Step 2: Read what each hook runs

That list tells you a hook exists. The security page says as much: the install screen "shows that a hook exists but not what it runs."

To see what it does, open hooks/hooks.json in the plugin's folder under ~/.claude/plugins/cache, then the scripts it names, then .mcp.json, which connects your agent to an outside server.

My agent's first look, a plain folder listing, missed Stripe's .mcp.json (it ran ls without -a). A file name starting with a dot stays out of a normal listing, so use ls -a.

Step 3: Keep the skills, drop the plugin

Skills are folders. I copied two of Stripe's ten into ~/.claude/skills before uninstalling, and the Stripe command-line tool kept working, because the plugin never owned it.

The catch: copies don't update. I noted where each one came from so I can copy a newer version by hand.

And if a skill mentions CLAUDE_PLUGIN_ROOT, it needs its plugin's own files, so keep that plugin installed. In Anthropic's official marketplace, skills in four plugins depend on it.

One more detail from the security page: uninstalling leaves the plugin's files in ~/.claude/plugins/cache/ for 14 days before a background sweep removes them.

If you run AI tools for client work

The rule I took from this is about time. A review covers the code you reviewed, on the day you reviewed it. If a plugin can update itself, the review needs a date on it, and the checks above need to run again.

Anyway.

I said yes to a plugin in March and was running a different one by October. A yes only covers the version you installed.

What's the last thing you installed that turned out to do more than you expected?

More notesnewest first

Working on something like this?

Bring the app or the process to a free 15-minute call. I will tell you what I would look at first, and whether I am the right person for it.