Home / Security tooling

cc-plugin-lock

Lock file for Claude Code plugins: pins plugins and skills to content hashes and verifies them before load.

Python · MIT · latest v0.1.0

What it is

cc-plugin-lock pins Claude Code marketplace plugins and skills to content hashes and verifies them before load, so a plugin that changes upstream cannot silently change what runs on your machine.

pipx install git+https://github.com/basitalisandhu/cc-plugin-lock

Install

pipx install git+https://github.com/basitalisandhu/cc-plugin-lock

# 1. Lock what is installed now (review your plugins first; the lock records what you trust).
cc-plugin-lock lock -o ~/.claude/cc-plugins.lock.json --store

# 2. Any time later: has anything changed?
cc-plugin-lock verify --lock ~/.claude/cc-plugins.lock.json

# 3. Gate every session: print the hook block and merge it into ~/.claude/settings.json.
cc-plugin-lock hook --lock ~/.claude/cc-plugins.lock.json

From the README; see the full README for every option.

Releases

Topics: agent-security, ai-agents, ai-security, claude-code, claude-code-plugins, cli, devsecops, hacktoberfest, hooks, integrity, lockfile, mcp, plugins, python, sarif, security-tools, skills, supply-chain-security