cc-plugin-lock
Lock file for Claude Code plugins: pins plugins and skills to content hashes and verifies them before load.
What it is
cc-plugin-lock pins Claude Code marketplace plugins and skills to content hashes and verifies them before load, so a plugin that changes upstream cannot silently change what runs on your machine.
pipx install git+https://github.com/basitalisandhu/cc-plugin-lock
Install
pipx install git+https://github.com/basitalisandhu/cc-plugin-lock
# 1. Lock what is installed now (review your plugins first; the lock records what you trust).
cc-plugin-lock lock -o ~/.claude/cc-plugins.lock.json --store
# 2. Any time later: has anything changed?
cc-plugin-lock verify --lock ~/.claude/cc-plugins.lock.json
# 3. Gate every session: print the hook block and merge it into ~/.claude/settings.json.
cc-plugin-lock hook --lock ~/.claude/cc-plugins.lock.json
From the README; see the full README for every option.
Links
Releases
Topics: agent-security, ai-agents, ai-security, claude-code, claude-code-plugins, cli, devsecops, hacktoberfest, hooks, integrity, lockfile, mcp, plugins, python, sarif, security-tools, skills, supply-chain-security