Skip to content

Security1 publisher2 min readPublished

Anthropic opens a public storefront for more than 2,000 Claude connectors and plugins

Anthropic's Claude Marketplace is live with more than 2,000 connectors and plugins, including ones published by Atlassian, Google, Microsoft and Salesforce. Each connector enabled from it adds a supplier that belongs in third-party and access reviews.

The Watch · Security desk

Illustration accompanying Anthropic opens a public storefront for more than 2,000 Claude connectors and plugins

What happened

  • Companies can also buy Claude-powered agents and products there from partners including CrowdStrike, Cursor, Harvey, Legora, Lovable and Snowflake.
  • Developers build connectors and plugins for the marketplace with Model Context Protocol and Agent Skills.
  • Consulting and systems integration firms, among them Accenture, Boston Consulting Group and Deloitte, are listed for companies that want help deploying Claude.
  • Anthropic says the aim is easier discovery for teams and a direct route for developers and partners to existing Claude customers.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure A blanket approval of the marketplace would cover developers nobody on the security team has assessed, because open publishing puts their connectors in the same store as the large vendors' connectors.
  • decision Security teams have to settle whether staff may add marketplace connectors on their own or only from a list reviewed publisher by publisher.
  • cost Every partner agent bought through the store adds another vendor besides Anthropic to the assessment queue and the contract review.
  • capability The direct route Anthropic offers developers to existing Claude customers is also the shortest route for a careless or hostile connector to reach them.

Claude could already connect to apps its users had, according to BleepingComputer, and the marketplace takes that past basic integrations [10]. The publication compares it to a Google Play Store for AI features [9]. The marketplace is already public [1]. For defenders, what is new is the supplier. A connector now comes from whoever published it to the store.

The report describes two routes onto the shelf. BleepingComputer reports that Anthropic is allowing anybody to publish. The publication says OpenAI's apps marketplace did not work out and that Anthropic wants to avoid that mistake [6]. Companies selling Claude-powered software take a different route. They apply to have their products listed [5].

Those two routes imply different levels of scrutiny. An application step suggests some gate for commercial listings. Open publishing suggests a lighter gate for everything else, or none. The report does not say which route the 2,000-plus connectors and plugins came through, or what review a listing passes before users can add it [1].

That gap decides how much of the vetting falls to the customer. A connector from one of the big-name publishers [2] maps to a vendor that a third-party risk program can already identify. A connector from an individual developer on the open route has no entry on the vendor register until someone creates one.

Nothing in the reporting describes a flaw or an attack. It describes a product launch that widens who can ship code into Claude deployments [6]. For access reviews, the unit to track is the individual connector and its publisher. The storefront is only where they were found.

What to watch

  • Anthropic publishing the review standard a listing must pass, and whether open-route connectors face the same checks as applied-for commercial listings.
  • Documentation of the access scopes a connector requests when added, and whether administrators can restrict installs to an approved list.
  • A first report of a malicious or data-leaking connector distributed through Claude Marketplace.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories