Plugin Clinic — Claude Code plugin review
Paste a Claude Code plugin — the .claude-plugin/plugin.json manifest, slash commands, subagents, skills, hooks.json and its scripts, MCP config — and get a senior plugin engineer's review: a load-readiness posture (install-ready / polish-recommended / load-breaking), the component inventory, prioritized findings with corrected JSON, YAML-frontmatter and bash fragments, and a conversion map for personal-setup patterns that do not travel. A free instant prescan flags a misplaced manifest, a hooks.json in the settings format, prompt hooks on unsupported events, hardcoded home paths where ${CLAUDE_PLUGIN_ROOT} belongs, agents with no example blocks, commands that address the user, skill descriptions in the wrong person and secrets in .mcp.json while you type. Derived from the @anthropics/claude-code skill and its first-party plugin-dev guidance.
Details
gpt-terra Every public app is built from a security-scanned skill and must pass a clean scan — skill and frontend — before it can be listed. Have a skill of your own? Turn it into an app — or read the step-by-step walkthrough.