{"version":"2.1.281","anchor":"plugin-validation-now-checks-a-plugins-mcp-server-files","canonical_anchor":"plugin-validation-now-checks-a-plugins-mcp-server-files","heading":"Plugin validation now checks a plugin's MCP server files","tier":null,"area":null,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.281\/e\/plugin-validation-now-checks-a-plugins-mcp-server-files","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.281","markdown":"### Plugin validation now checks a plugin's MCP server files\n\nPlugin validation now checks a plugin's MCP server files for bad settings, insecure addresses and credentials left in plain text\n\n**What**\n\nA plugin is an add-on package for Claude Code. Some plugins bring MCP servers, which are external tools Claude can connect to. Plugin validation now also reads the plugin's MCP server files: `.mcp.json`, plus any `.\/*.json` files that `plugin.json` lists under `mcpServers`. It does not follow symlinks (shortcut files that point somewhere else), and it refuses files above a size limit.\n\nIt reports these as errors:\n\n- `headersHelper` referring to `${user_config.*}`\n\n- userConfig keys the plugin never declared\n\n- invalid URLs\n\n- an unknown server `type`\n\n- a `url` given with no `type`\n\nIt warns about these:\n\n- `http:\/\/` or `ws:\/\/` addresses to any host other than the local machine\n\n- header values that look like real credentials, matched against known token patterns or by how random the value looks on auth-style headers\n\n- lists used where settings objects are expected\n\n- a byte-order mark (BOM, an invisible marker at the start of a file)\n\n- too many server files\n\n**Why**\n\nThe credential warning says why it matters: everything shipped in a plugin can be read by everyone who installs it. Plugin authors now hear about leaked secrets, unencrypted connections and broken server entries before they publish."}