basitalisandhu

Cc Plugin Lock — Development skill for Claude Code

Development community

Lock file for Claude Code plugins: pins marketplace plugins and skills to content hashes, verifies them before a session loads them, scores changes by component (hooks and MCP high, skills medium), di.

How to install Cc Plugin Lock

This entry records only its repository, not the path inside it, so there is no exact command to give. Open basitalisandhu/cc-plugin-lock and copy the folder into ~/.claude/skills/, or the file into ~/.claude/agents/.

What Cc Plugin Lock does

Lock file for Claude Code plugins: pins marketplace plugins and skills to content hashes, verifies them before a session loads them, scores changes by component (hooks and MCP high, skills medium), diffs against the locked content, and scans plugin folders before install. SARIF output, SessionStart gate, Python stdlib only.

Alternatives in Development

README

cc-plugin-lock: Lock file for Claude Code plugins

**cc-plugin-lock pins Claude Code marketplace plugins and skills to content hashes and verifies them before load, so a plugin that changes upstream cannot silently change what runs on your machine.**

[![CI](https://github.com/basitalisandhu/cc-plugin-lock/actions/workflows/ci.yml/badge.svg)](https://github.com/basitalisandhu/cc-plugin-lock/actions/workflows/ci.yml) [![License: MIT](https://img.shields.io/badge/license-MIT-blue.svg)](LICENSE) [![Python 3.11+](https://img.shields.io/badge/python-3.11%2B-blue.svg)](pyproject.toml)

pipx install git+https://github.com/basitalisandhu/cc-plugin-lock

What it is, who it is for, and why

A Claude Code plugin can ship hooks that run shell commands on every tool call, MCP servers that start at session start, executables that land on the Bash tool's `PATH`, and skills that change what the model is told. Plugins come from marketplaces, which are git repositories. When a marketplace updates, Claude Code fetches the new version into `~/.claude/plugins/cache/` and loads it on the next launch. Auto-update is on by default for Anthropic's official marketplaces and can be turned on for any other ([plugin loading reference](https://code.claude.com/docs/en/plugins/loading#when-auto-update-runs)). Nothing in that path shows you what changed between the version you reviewed and the one that is about to run.

cc-plugin-lock is for developers and teams who install third-party Claude Code plugins and want the same guarantee a package lock file gives them for dependencies: the code that runs is the code you approved, and a change is visible, scored and stoppable before it runs.

  • lock hashes every file of every installed plugin (a sorted hash list per plugin and per component class) and records the marketplace source, version and git commit in cc-plugins.lock.json.
  • verify recomputes the hashes and reports each plugin as unchanged, changed, added or removed. A chang