Cc Plugin Lock — Development skill for Claude Code
Lock file for Claude Code plugins: pins marketplace plugins and skills to content hashes, verifies them before a session loads them, scores changes by component (hooks and MCP high, skills medium), di.
How to install Cc Plugin Lock
This entry records only its repository, not the path inside it, so there is no
exact command to give. Open basitalisandhu/cc-plugin-lock and copy the folder into
~/.claude/skills/, or the file into ~/.claude/agents/.
What Cc Plugin Lock does
Lock file for Claude Code plugins: pins marketplace plugins and skills to content hashes, verifies them before a session loads them, scores changes by component (hooks and MCP high, skills medium), diffs against the locked content, and scans plugin folders before install. SARIF output, SessionStart gate, Python stdlib only.
Alternatives in Development
- Codenotch — A macOS app that pins usage limits from Claude Code, Cursor, Codex, and Antigravity to a screen edge 1.3k ★
- Contributing To Claude Code Skills Marketplace — Thank you for your interest in contributing 653 ★
- Claude Code Instructions For Skills Marketplace Development — Repository: claude-skills-marketplace Purpose: Development guidelines for creating high-quality Claude Code sk 480 ★
README
cc-plugin-lock: Lock file for Claude Code plugins
**cc-plugin-lock pins Claude Code marketplace plugins and skills to content hashes and verifies them before load, so a plugin that changes upstream cannot silently change what runs on your machine.**
[](https://github.com/basitalisandhu/cc-plugin-lock/actions/workflows/ci.yml) [](LICENSE) [](pyproject.toml)
pipx install git+https://github.com/basitalisandhu/cc-plugin-lock
What it is, who it is for, and why
A Claude Code plugin can ship hooks that run shell commands on every tool call, MCP servers that start at session start, executables that land on the Bash tool's `PATH`, and skills that change what the model is told. Plugins come from marketplaces, which are git repositories. When a marketplace updates, Claude Code fetches the new version into `~/.claude/plugins/cache/` and loads it on the next launch. Auto-update is on by default for Anthropic's official marketplaces and can be turned on for any other ([plugin loading reference](https://code.claude.com/docs/en/plugins/loading#when-auto-update-runs)). Nothing in that path shows you what changed between the version you reviewed and the one that is about to run.
cc-plugin-lock is for developers and teams who install third-party Claude Code plugins and want the same guarantee a package lock file gives them for dependencies: the code that runs is the code you approved, and a change is visible, scored and stoppable before it runs.
lockhashes every file of every installed plugin (a sorted hash list per plugin and per component class) and records the marketplace source, version and git commit incc-plugins.lock.json.verifyrecomputes the hashes and reports each plugin as unchanged, changed, added or removed. A chang
Related Skills
All Recommendations
Launch a team of implementation agents to apply ALL recommended changes from the most recent review — every se
Bt MCP Tools
列出宝塔 MCP 协议的 98 个工具(按 19 类分组),给出风险等级(low/medium/high)和参数签名。当 Agent 已接入 baota-mcp 后需要选择合适工具时使用。
Verify Chain
Verify the full receipt chain offline — structure (single unbroken chain from GENESIS, content hashes) and eve
Content Hash Cache Pattern
Cache expensive file processing results via SHA-256 content hashes — path-independent, auto-invalidating, serv
Tech Debt
Multi-agent technical-debt assessment — fans out region-scoped + specialist hunters, verifies findings, scores
Superhunter
Job-search agent on the Claude Agent SDK. A deterministic TypeScript orchestrator runs 25 discovery agents aga
Related Agents
Config Conformance Reviewer
Reviews changes to Claude Code config surfaces (settings.json, agent/skill frontmatter, plugin.json, marketpla
Soia Meta
Skill ecosystem manager: searches the whole SOIA catalog by need and loads the right skill, syncs skills into
Effort Medium
Pins MEDIUM reasoning effort; pair with a per-call model param. For standard implementation, unit tests, and b