What
When you install a plugin from npm (the JavaScript package registry), Claude Code now checks the package before installing it. It refuses:
- a package name that is not a valid npm package name
- a tarball link (a direct link to a packed package file) that points at GitHub, GitLab, Bitbucket or SourceHut
- a tarball link that contains
#or whitespace - a tarball link using unencrypted
httpon a host other than your npm registry - a registry override that uses
httpand is not the default registry
npm also runs with git disabled during the install. If an install is refused, the error says why.
Why
These checks make it harder for a plugin install to fetch code from somewhere unexpected or over an insecure connection. They can also make an install that used to work fail, so read the error message if one stops working.