Extension Surface Matrix¶
Claude Code’s extension model is compositional: instructions change context, hooks observe lifecycle, MCP adds remote/local capabilities, agents delegate work, and plugins package several of these together. The security review must follow the most privileged enabled component.
Surface matrix¶
| Surface | Contribution | Discovery / activation | Direct local execution? | Refresh / lifetime | Isolation controls | Basis and hosted sources |
|---|---|---|---|---|---|---|
CLAUDE.md / rules |
Prompt instructions and machine/project context | Automatic user/project/added-dir discovery unless suppressed | No; can influence model-selected tools | Startup and instruction/file change boundaries | Safe mode; bare disables automatic discovery | O CLI behavior: H:root; D assembly: R:startup |
| Automatic memory | Retrieved/persisted context | Settings-controlled store | No direct execution | Session/turn dependent; exact ranking unknown | Independent controls; project custom path ignored | D claims memory.independent-controls, memory.project-path-hardening in E:claims; R:memory |
| Skills / commands | Named procedures, prompts, assets | Skill roots and plugins; explicit /name invocation |
Indirect through tool requests or bundled assets | Can emit commands_changed mid-session |
Safe mode disables; bare still resolves named skills | D claim extensibility.skills-refresh; R:skills |
| Custom agents | Delegated prompt/model/tools/permissions/memory/isolation | Settings, --agents, plugins, built-ins |
Through the child’s granted tools | Child/background session lifetime | Tool restrictions, permission mode, worktree isolation | O flags: H:root; D contracts: R:agents |
| Hooks | Lifecycle command, prompt, agent, HTTP, or MCP handlers | Settings, plugins, skills, SDK | Yes for command/agent/HTTP/MCP handlers | Per matching lifecycle event | Safe/bare suppress; matcher/ordering remain partly unknown | D claim extensibility.hook-lifecycle; R:hooks |
| MCP servers | Tools, resources, prompts, elicitation | User/project/local/explicit/plugin sources | Stdio runs a child; remote transports execute elsewhere | Connection/session lifetime | Project approval, strict config, plugin MCP suppression | O CLI: H:MCP; D: R:MCP |
| Plugins | Composite component package | Installed scope, marketplace, directory, zip, URL | Depends on hooks/MCP/LSP/monitor components | Installed or session-only; update/restart boundaries | Safe mode; component inventory; strict validation; MCP suppression | O CLI: H:plugin, H:init; D: R:plugins |
| LSP / IDE / Chrome | Editor/browser/application capabilities | Auto-connect or explicit flags/plugins | Yes through child process or bridge | Integration connection lifetime | Safe/bare suppress LSP/customizations; IPC details unknown | O flags: H:root; D socket control: claim security.socket-directory-mode |
| Stream-JSON / SDK | Programmatic input, output, session and tool orchestration | --print, input/output format flags, entrypoint identity |
Through the same effective tools | Process/session lifetime | Explicit tools, settings, strict MCP, no-session-persistence | O protocol flags: H:root; D startup: R:startup |
| Remote control | Remote session messages and control | CLI flag or startup setting | Can lead to local tools under session policy | Remote channel/session lifetime | Peer-machine approval option; local socket mode | D claims remote.startup, remote.peer-isolation; R:remote |
Dynamically exercised extension paths¶
Observed dynamically Isolated
fixtures exercised three discovery surfaces: a selected inline agent narrowed
the advertised tool list, a user-home skill appeared in both skill and slash
command catalogs, and an explicit local plugin contributed a namespaced skill.
The same suite observed concurrent sibling PreToolUse dispatch and the MCP
stdio sequence initialize → initialized → tools/list → tools/call.
Extension runtime report · claims
dynamic.discovery.explicit-components, dynamic.hooks.concurrent-siblings,
and dynamic.mcp.stdio-flow in
E:claims.
Plugin composition map¶
flowchart TD
accTitle: Extension Surface Matrix - Plugin composition map
accDescr: Diagram showing plugin composition map in the Extension Surface Matrix section.
Package["[D:E1] Plugin package"] --> Manifest["[D:E2] Manifest + userConfig schema"]
Package --> Skills["[O:E3] Skills"]
Package --> Agents["[O:E4] Agents"]
Package --> Hooks["[O:E5] Hooks"]
Package --> MCP["[O:E6] MCP"]
Package --> LSP["[O:E7] LSP"]
Package --> Style["[O:E8] Output style"]
Package --> Channel["[O:E9] Channel"]
Hooks --> Exec["[D:E10] Local / remote execution authority"]
MCP --> Exec
LSP --> Exec
Skills --> Context["[D:E11] Model context / procedures"]
Agents --> Context
| IDs | Basis | Mapping | Hosted sources |
|---|---|---|---|
| E1–E2 | D | A plugin groups manifest metadata, configuration, and components into one source identity. | R:plugins, H:plugin-install |
| E3–E9 | O | plugin init --with advertises these seven component classes. |
H:plugin-init, claim extensibility.plugin-component-inventory |
| E10 | D | Hook monitors execute at hook trust; MCP/LSP can spawn or contact external capabilities. | Claims security.plugin-monitor-trust and extensibility.mcp-transports in E:claims, R:hooks |
| E11 | D | Skills and agents primarily specialize instructions and delegation, while authority remains mediated by effective tools/permissions. | R:skills, R:agents |
Lifecycle attachment points¶
| Phase | Relevant extension events or refresh | Basis | Sources |
|---|---|---|---|
| Startup | Setup, SessionStart, instructions/skills/plugins/MCP discovery |
D | Anchor hooks.lifecycle in E:anchors, R:startup |
| User input | UserPromptSubmit, UserPromptExpansion |
O event names; H payload/ordering | R:hooks, anchor hooks.lifecycle |
| Tool request | PreToolUse, PermissionRequest, PermissionDenied |
D control boundaries | R:tool-pipeline, R:permissions |
| Tool completion | PostToolUse, PostToolUseFailure, PostToolBatch |
O event names; D attachment | R:hooks, R:tool-pipeline |
| Context change | PreCompact, PostCompact, InstructionsLoaded, ConfigChange, FileChanged, CwdChanged |
O event names; H exact refresh scheduling | R:hooks, claim context.compaction-lifecycle |
| Delegation | SubagentStart, SubagentStop, TeammateIdle, task events |
D lifecycle observability | R:agents, claims agents.lifecycle-observability, agents.pending-turn-state |
| Shutdown | Stop, StopFailure, SessionEnd, WorktreeRemove |
O event names; H handler order | R:hooks |
Trust review order¶
- Identify origin, scope, immutable version/digest, and update channel.
- Inventory every component rather than trusting the package label.
- Review executable components first: command/agent/HTTP/MCP hooks, monitors, stdio MCP, LSP.
- Review model-influencing text: skills, agents, tool descriptions, MCP prompts/resources.
- Confirm safe/bare/strict-mode expectations and managed policy.
- Verify actual effective catalog and connections at runtime; presence in a package is not proof of activation.
The exact marketplace signature model, cross-event hook composition, and every
plugin shadowing rule remain outside the authenticated evidence. Sibling
PreToolUse command hooks are no longer wholly unknown: the exercised pair was
dispatched concurrently, so authors must not coordinate through declaration
order.