What
When you install a plugin from the plugin directory, Claude Code now checks it more strictly:
- the listing must name a repository, and the repository address must not be too long
- the listing is checked against
plugin-directory-bindings.jsonandinstalled_plugins.jsonin your plugins folder - a download that is not at the reviewed commit (the exact version that was checked) is rejected, and its temporary download folder is removed
- an install is refused if the listing now names a different repository than the one recorded
- an install is refused if
plugin-directory-bindings.jsoncannot be read
These refusals come with their own failure codes, such as directory_identity_changed, directory_listing_not_installable, directory_unavailable and directory_binding_unreadable.
Why
If a directory listing is pointed at a different repository, it can no longer quietly replace a plugin you already installed with code from somewhere else.
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubt
It is not clear what switches on installs from the plugin directory.