What
Before installing a plugin, Claude Code now runs a new check first. The check can refuse the install for one of three reasons:
blocked-by-policy: the plugin is not allowed by policy.marketplace-blocked-by-policy: the marketplace the plugin comes from is not allowed by policy.plugin-directory-unavailable: the plugin directory could not be reached.
Other changes to plugin installs:
- If no marketplaces are known, a plugin from an unrecognised source is refused rather than allowed.
- Dependencies that are installed automatically now go through the same policy check one by one. Any that cannot be found are returned in a
notFoundlist. - After an install, the message can now say "This plugin is disabled by default" or that it is disabled "in your settings", along with a hint on how to enable it.
- The two policy refusals are now turned into messages in one shared place. They map to the failure codes
plugin_policy_blockedandmarketplace_policy_blocked. The message text is the same as before.
Why
When an install is refused, you now get a clear reason, and a policy block also applies to the dependencies a plugin brings in. You are also told when a newly installed plugin starts out switched off, so you know to enable it.