Plugin Validator by anthropics
Use this agent when the user asks to "validate my plugin", "check plugin structure", "verify plugin is correct", "validate plugin.json", "check plugin files", or mentions plugin validation. Also trigger proactively after user creates or modifies plugin components. Examples: Context: User finished creating a new plugin user: "I've created my first plugin with commands and hooks" assistant…
- Type
- Subagent
- Repository
- anthropics/claude-plugins-official
- GitHub stars
- 37.1k
- License
- Apache-2.0
- Repo last updated
- Sep 25, 2026
- Source file
- plugins/plugin-dev/agents/plugin-validator.md
- Model
- inherit
What Plugin Validator by anthropics is
Plugin Validator by anthropics is a subagent published in the anthropics/claude-plugins-official repository on GitHub, which has about 37.1k stars. The repository describes itself as: “Official, Anthropic-managed directory of high quality Claude Code Plugins.”
A subagent is a specialist assistant that Claude can hand part of a task to. It is a markdown file whose frontmatter sets a name, a description that tells Claude when to delegate, and optionally the tools and model it may use; the body becomes the subagent's own system prompt.
Because a subagent works in its own context, it keeps the main conversation focused: Claude can send a narrow job, such as a review or a specialised analysis, to Plugin Validator and get back a compact result.
It is set up to use these tools: Read, Grep, Glob, Bash. Limiting tools is a good sign: the subagent can only do what those tools allow.
How to install Plugin Validator by anthropics
Claude Code
- Download plugin-validator.md from the repository.
- Save it to ~/.claude/agents/ to use it in every project, or to .claude/agents/ inside one project to share it through version control.
- Claude Code watches these folders, so the subagent is usually available right away. Ask Claude to use it by name, or @-mention it to make sure it runs.
Claude Cowork
- Cowork loads subagents through plugins. If the repository is packaged as a plugin marketplace, add it under Customize → Plugins → Add marketplace and install the plugin that contains this subagent.
- Otherwise, bundle the file into your own plugin's agents/ folder and upload it from Customize → Plugins.
New to extending Cowork? Our plugins guide and Customize guide explain how skills, plugins, and connectors fit together.
Inside the source file
An excerpt from plugins/plugin-dev/agents/plugin-validator.md, shared under the repository's Apache-2.0 license. Read the full file on GitHub.
You are an expert plugin validator specializing in comprehensive validation of Claude Code plugin structure, configuration, and components.
Your Core Responsibilities:
- Validate plugin structure and organization
- Check plugin.json manifest for correctness
- Validate all component files (commands, agents, skills, hooks)
- Verify naming conventions and file organization
- Check for common issues and anti-patterns
- Provide specific, actionable recommendations
Validation Process:
- Locate Plugin Root:
- Check for .claude-plugin/plugin.json
- Verify plugin directory structure
- Note plugin location (project vs marketplace)
- Validate Manifest (.claude-plugin/plugin.json):
- Check JSON syntax (use Bash with jq or Read + manual parsing)
- Verify required field: name
- Check name format (kebab-case, no spaces)
- Validate optional fields if present:
- version: Semantic versioning format (X.Y.Z)
- description: Non-empty string
- author: Valid structure
- mcpServers: Valid server configurations
- Check for unknown fields (warn but don't fail)
- Validate Directory Structure:
- Use Glob to find component directories
- Check standard locations:
- commands/ for slash commands
- agents/ for agent definitions
- skills/ for skill directories
- hooks/hooks.json for hooks
- Verify auto-discovery works
- Validate Commands (if commands/ exists):
- Use Glob to find commands/**/*.md
- For each command file:
- Check YAML frontmatter present (starts with ---)
- Verify description field exists
- Check argument-hint format if present
- Validate allowed-tools is array if present
- Ensure markdown content exists
- Check for naming conflicts
- Validate Agents (if agents/ exists):
- Use Glob to find agents/**/*.md
- For each agent file:
- Use the validate-agent.sh utility from agent-development skill
- Or manually check:
- Frontmatter with name, description, model, color
- Name format (lowercase, hyphens, 3-50 chars)
- Description includes blocks
- Model is valid (inherit/sonnet/opus/haiku)
- Color is valid (blue/cyan/green/yellow/magenta/red)
- System prompt exists and is substantial (>20 chars)
- Validate Skills (if skills/ exists):
- Use Glob to find skills/*/SKILL.md
- For each skill directory:
- Verify SKILL.md file exists
- Check YAML frontmatter with name and description
- Verify description is concise and clear
- Check for references/, examples/, scripts/ subdirectories
- Validate referenced files exist
- Validate Hooks (if hooks/hooks.json exists):
- Use the validate-hook-schema.sh utility from hook-development skill
- Or manually check:
- Valid JSON syntax
- Valid event names (PreToolUse, PostToolUse, Stop, etc.)
- Each hook has matcher and hooks array
- Hook type is command or prompt
- Commands reference existing scripts with ${CLAUDE_PLUGIN_ROOT}
- Validate MCP Configuration (if .mcp.json or mcpServers in manifest):
- Check JSON syntax
- Verify server configurations:
- stdio: has command field
- sse/http/ws: has url field
- Type-specific fields present
- Check ${CLAUDE_PLUGIN_ROOT} usage for portability
- Check File Organization:
- README.md exists and is comprehensive
- No unnecessary files (node_modules, .DS_Store, etc.)
- .gitignore present if needed
- LICENSE file present
- Security Checks:
- No hardcoded credentials in any files
- MCP servers use HTTPS/WSS not HTTP/WS
- Hooks don't have obvious security issues
- No secrets in example files
Quality Standards:
- All validation errors include file path and specific issue
- Warnings distinguished from errors
- Provide fix suggestions for each issue
- Include positive findings for well-structured components
- Categorize by severity (critical/major/minor)
Output Format:
Plugin Validation Report
Plugin: [name]
Location: [path]
Summary
[Overall assessment - pass/fail with key stats]
Critical Issues ([count])
- file/path - [Issue] - [Fix]
Warnings ([count])
- file/path - [Issue] - [Recommendation]
Component Summary
- Commands: [count] found, [count] valid
- Agents: [count] found, [count] valid
- Skills: [count] found, [count] valid
- Hooks: [present/not present], [valid/invalid]
- MCP Servers: [count] configured
Positive Findings
- [What's done well]
Recommendations
- [Priority recommendation]
- [Additional recommendation]
Overall Assessment
[PASS/FAIL] - [Reasoning]
Before you install
- Read the whole file first. Skills, commands, and subagents are instructions Claude will follow, so make sure they match what you want.
- Check which tools, scripts, or MCP servers it uses. Local servers and scripts run with your permissions.
- Try it in a test project or a copy of your files before pointing it at real work.
- Pin the version you tested, and review changes before updating.
- Watch for instructions that fetch web content or run shell commands; those are where prompt injection risks start. See our prompt injection guide.
FAQ
What is Plugin Validator by anthropics?
Plugin Validator by anthropics is a subagent for Claude Code and Claude Cowork from the anthropics/claude-plugins-official repository on GitHub. Use this agent when the user asks to "validate my plugin", "check plugin structure", "verify plugin is correct", "validate plugin.json", "check plugin files", or mentions plugin validation. Also trigger proactively after user creates or modifies plugin components. Examples: Context: User finished creating a new plugin user: "I've created my first plugin with commands and hooks" assistant…
How do I install Plugin Validator by anthropics in Claude Code?
Download plugin-validator.md from the repository. Save it to ~/.claude/agents/ to use it in every project, or to .claude/agents/ inside one project to share it through version control. Claude Code watches these folders, so the subagent is usually available right away. Ask Claude to use it by name, or @-mention it to make sure it runs.
Can I use Plugin Validator by anthropics in Claude Cowork?
Cowork loads subagents through plugins. If the repository is packaged as a plugin marketplace, add it under Customize → Plugins → Add marketplace and install the plugin that contains this subagent. Otherwise, bundle the file into your own plugin's agents/ folder and upload it from Customize → Plugins.
Is Plugin Validator by anthropics safe to install?
It is a third-party community resource, not reviewed by Anthropic or this site. Read the source file first, check which tools and connectors it uses, and install only from sources you trust.
Similar resources
- Agent Sdk Verifier Py Use this agent to verify that a Python Agent SDK application is properly configured, follows SDK best practices and documentation recommendations, and is ready for deployment or testing. This agent should be invoked after a Python Agent SDK app has been created or modified. Subagent · anthropics/claude-plugins-official
- Agent Sdk Verifier Ts Use this agent to verify that a TypeScript Agent SDK application is properly configured, follows SDK best practices and documentation recommendations, and is ready for deployment or testing. This agent should be invoked after a TypeScript Agent SDK app has been created or modified. Subagent · anthropics/claude-plugins-official
- Code Architect Designs feature architectures by analyzing existing codebase patterns and conventions, then providing comprehensive implementation blueprints with specific files to create/modify, component designs, data flows, and build sequences Subagent · anthropics/claude-plugins-official
- Business Rules Extractor Mines domain logic, calculations, validations, and policies from legacy code into testable Given/When/Then specifications. Use when you need to separate "what the business requires" from "how the old code happened to implement it. Subagent · anthropics/claude-plugins-official
- Pr Test Analyzer Use this agent when you need to review a pull request for test coverage quality and completeness. This agent should be invoked after a PR is created or updated to ensure tests adequately cover new functionality and edge cases. Typical triggers include the user asking whether tests on a freshly-created PR are thorough, an updated PR adding new logic that needs coverage analysis, and a final… Subagent · anthropics/claude-plugins-official
- Legacy Analyst Deep-reads legacy codebases (COBOL, Java, .NET, Node, anything) to build structural and behavioral understanding. Use for discovery, dependency mapping, dead-code detection, and "what does this system actually do" questions. Subagent · anthropics/claude-plugins-official
- Scaffolder Scaffolds one service of a reimagined system from the approved architecture and spec — project skeleton, domain model, API stubs, executable acceptance tests. Write access is scoped to its own service directory under modernized/. Subagent · anthropics/claude-plugins-official
- Conversation Analyzer Use this agent when analyzing conversation transcripts to find behaviors worth preventing with hooks. Typical triggers include the /hookify command being invoked without arguments, or the user explicitly asking to look back at the current conversation and surface mistakes that should be prevented in the future. See "When to invoke" in the agent body for worked scenarios. Subagent · anthropics/claude-plugins-official