{"version":"2.1.287","anchor":"plugin-directory-installs-checked-against-reviewed-commit-an","canonical_anchor":"plugin-directory-installs-checked-against-reviewed-commit-an","heading":"Plugins from the plugin directory are checked against the reviewed version","tier":"notice","area":"Plugins","scope":null,"heads_up":null,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.287\/e\/plugin-directory-installs-checked-against-reviewed-commit-an","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.287","markdown":"### Plugins from the plugin directory are checked against the reviewed version\n\nDirectory plugin installs must now match the reviewed commit and recorded repository, or Claude Code refuses them\n\n**Unclear.** It is not clear what switches on installs from the plugin directory.\n\n**What**\n\nWhen you install a plugin from the plugin directory, Claude Code now checks it more strictly:\n\n- the listing must name a repository, and the repository address must not be too long\n\n- the listing is checked against `plugin-directory-bindings.json` and `installed_plugins.json` in your plugins folder\n\n- a download that is not at the reviewed commit (the exact version that was checked) is rejected, and its temporary download folder is removed\n\n- an install is refused if the listing now names a different repository than the one recorded\n\n- an install is refused if `plugin-directory-bindings.json` cannot be read\n\nThese refusals come with their own failure codes, such as `directory_identity_changed`, `directory_listing_not_installable`, `directory_unavailable` and `directory_binding_unreadable`.\n\n**Why**\n\nIf a directory listing is pointed at a different repository, it can no longer quietly replace a plugin you already installed with code from somewhere else.\n\n- Area: Plugins\n- Tier: You'll notice\n- Useful: 2\/5\n- Signal: 3\/5"}