MCP Apps (SEP-1865) is the first official MCP extension: a tool can now return an interactive HTML interface the host renders in a sandboxed iframe. The sandbox is real, but it does not stop your own code from leaking secrets or rendering tool output into an XSS sink. Here is the security surface the sandbox does not cover, and a free checker for it.
The internet decided the em dash means a robot wrote it, so people started deleting every one. That is the wrong lesson. No single feature proves text is AI-written, and a linter built on single features flags good writing and flattens voice. slop-check, our new plugin, judges by cluster and register instead, and it is a craft tool, not a detector-evader.
seo-optimizer 1.1.0 added an llms.txt and AI-discoverability audit. The honest test of a tool is running it on yourself, so we ran it against sigistry.com. Here is the before and after across the three things that decide whether ChatGPT, Claude, and Perplexity can read your site, plus the one robots.txt line that had quietly been breaking Google.
The verified catalog already spoke MCP, which is perfect for agents and invisible to everything else. Now the same data is a public REST API described by an OpenAPI 3.1 spec, so custom GPTs, code generators, CI jobs, and dashboards can read verified plugins, portable skills, and MCP scorecards without an agent in the loop. One dataset, three surfaces, no auth.
The scary part of going responsive is not finding the problems, it is fixing them without breaking the desktop layout that already works. responsive-design-kit audits your site's mobile responsiveness from source and scores every fix by its blast radius, so the safe changes apply automatically and the risky ones wait for your yes.
Classic SEO optimizes for crawlers that render HTML. AI answer engines read sites differently, and they look for a file most developers have never heard of. seo-optimizer 1.1.0 adds AI discoverability: llms.txt generation and validation, AI-crawler access checks, and answer-engine readiness for ChatGPT, Claude, and Perplexity.
Verifying a plugin means nothing if you install a different commit than the one we reviewed. Externally-hosted listings now pin a git-subdir source to a commit sha, so the code Claude Code installs is the exact code we verified. What ref and sha actually do, the gap they close, and why one hash now drives both the install and the audit.
A SKILL.md is text injected straight into your agent's context, and nobody was screening it. Methodology v1.1 adds a skill-safety check: command shadowing, greedy triggers, injection language, unsafe scripts. It failed 10 of our own 19 plugins on its first run, and that's the point.
Same catalog, same verification, same team, new name. Why we rebranded, what Sigistry means, the one command existing users need to run, and where the registry goes next.
The Claude Code skill ecosystem is exploding into the thousands across competing directories. In the same weeks, Anthropic hardened Claude Code against skills that shadow your commands. Here is why curation with evidence, not raw volume, is the number that matters.
The August 2026 Claude Code releases in one place, filtered for plugin authors and power users: GitLab marketplace support, cross-session messaging, fork mode by default, credential redaction, the /design preview, and what each one changes for how you build.
A practical walkthrough of earning the Verified by Sigistry badge: run the free browser checker against your repo, fix the common failures, pick a verification tier, and ship a badge that agents and users can actually trust.
Two releases for the agent era: verify_plugin, an MCP tool that teaches your Claude to run the registry's verification locally (your code never leaves your machine), and MCP Server Scorecards, public security grades against the 2026-07-28 spec, with our own server graded first.
search-visibility-kit is the first community plugin in the catalog, reviewed under the published methodology. What the security review looked at, the three verification tiers external authors can choose from, and how the badge stays honest after you earn it.
Claude Code plugins run hooks on your machine and give agents tools. Almost nobody checks them. We built a public, seven-check verification methodology, ran it on our own catalog, and it immediately failed 5 of 16 plugins. Here's what Verified by Sigistry means, and how to earn the badge.
A new plugin that treats your MCP server as both a protocol artifact and an attack surface: it scaffolds a spec-shaped server, scores an existing one against the stateless core and OAuth model, migrates it off HTTP+SSE, and catches confused-deputy and injection risks, all statically.
Claude Code's PostToolUse hooks can now replace what the model sees as a tool's output, for every tool, not just MCP. Here's how updatedToolOutput works, with copy-paste examples for redacting secrets, compressing noisy output, and normalizing results.
The biggest Model Context Protocol revision yet is rolling out across Claude. Here's what the stateless core, the OAuth 2.1 / OIDC alignment, and the new versioned extensions mean for anyone running an MCP server, and what breaks if you ignore them.
Three different technologies get called 'AI robots browsing your site' - and they point in opposite directions. Here's what chrome-devtools-mcp, Gemini's auto-browse, and Google's new WebMCP actually do, and the one move that's a real first-mover opportunity.
Meet Release Conductor, CI & Incident Medic, and SQL Safety Net - three new plugins that own the high-stakes chores around shipping: commits and semver, failing pipelines, and unsafe migrations.
AI now accounts for nearly half of committed code, but review capacity is flat. The bottleneck didn't disappear - it moved from writing code to trusting it. Here's what the review gap means and how to close it.
Modern Claude Code plugins are built from three layers - skills, subagents, and hooks. Here's what each is for, the decision rule that keeps them from overlapping, and how they fit together in a real plugin.
Claude Code's MCP Tool Search feature enables lazy loading for plugins and MCP servers, cutting context usage by up to 95%. Here's what it means for plugin-heavy workflows.
Claude Code Skills 2.0 unifies commands and skills, spawns isolated subagents, and enables parallel development across git worktrees. Here's what changed and how to use it.
The best Claude Code plugins for 2026, updated for August: top picks across code review, testing, docs, database, DevOps, API, accessibility, and LLM apps. Every recommendation passes an eight-check security verification.
A practical guide to Claude Code hooks with copy-paste examples for every event. Run your own commands automatically on PreToolUse, PostToolUse, SessionStart and more, to format code, run tests, block risky edits, or ping Slack.
The future of AI coding isn't one assistant that does everything -it's specialized agents that each do one thing brilliantly. Here's why plugins are leading this revolution.
Stop just getting answers -start actually learning. Code Tutor turns Claude Code into your personal programming instructor with interactive teaching, guided practice, and constructive feedback.
Skills let Claude load specialized expertise on-demand. No more generic outputs or bloated prompts -just laser-focused capabilities exactly when you need them.
Cloud-based parallel execution means you can assign multiple coding tasks to Claude simultaneously. Your terminal stays clean, your repos stay secure, and your backlog actually shrinks.
Learn how to install and use Claude Code plugins in under 5 minutes. Step-by-step tutorial covering marketplace setup, plugin installation, and slash commands.
A deep dive into Doc Generator, the plugin that makes documentation suck 30% less. Auto-generate docs, sync your README, and actually keep things up to date.