Concepts
Publisher marketplaces
Modyard has no common marketplace. Each publisher is a Claude Code marketplace of its own, and that choice decides how you install, how you update and whom you trust.
4 min read
One marketplace per publisher
Claude Code installs plugins from marketplaces: a JSON file that lists plugins and says where to download each one. You add a marketplace once, then install any plugin it lists with plugin@marketplace.
On Modyard, every publisher is one of those marketplaces. A publisher is a person or a team account, created the first time someone signs in with Google. Its marketplace is served at a fixed address:
https://mods.gonzaloverdugo.com/publishers/<publisher>/marketplace.jsonand its name is the publisher's slug. So the marketplace of ana is called ana, and her mod bash-logger installs as bash-logger@ana:
/plugin marketplace add https://mods.gonzaloverdugo.com/publishers/ana/marketplace.jsonclaude plugin install bash-logger@ana --scope userThere is no modyard marketplace that lists everything. You browse everything on the mods page, but you install from the publisher.
Why not one big marketplace
A single marketplace with every mod would be one command shorter. It would also mean that adding it gives every publisher on the site a path to your machine, and that one compromised or careless account could ship updates to everyone who added it.
With one marketplace per publisher:
- You choose whom you trust, one by one. Adding
ana's marketplace means you accept code fromana, and from nobody else. - The name tells you the source.
bash-logger@anacannot quietly become someone else's plugin. The part after@is the publisher you added. - Removing trust is one action. Remove the marketplace and nothing more comes from that publisher.
- Reserved slugs stop impersonation. Slugs such as
anthropic,claude,officialandmodyardcannot be taken, so no publisher can look like an official source.
Mod names, on the other hand, are unique across all of Modyard, first come first served. Two publishers cannot both have a bash-logger, which keeps search and links unambiguous.
What the marketplace.json holds
The file is generated from the publisher's mods on every request, so it always lists the latest version of each listed mod. Trimmed to one mod, it looks like this:
{
"name": "ana",
"owner": { "name": "Ana" },
"metadata": { "description": "Claude Code mods published by Ana on Modyard" },
"plugins": [
{
"name": "bash-logger",
"version": "0.1.0",
"description": "Shows each Bash command in the status line",
"source": {
"source": "archive",
"url": "https://mods.gonzaloverdugo.com/api/v1/mods/bash-logger/versions/0.1.0/archive.zip",
"sha256": "<hex>"
}
}
]
}The interesting part is source. Modyard uses the archive source: instead of pointing at a git repository, each entry points at a zip of one exact version, together with that zip's sha256.
Archives and sha256
When a publisher uploads a mod, Modyard does not keep their zip as it arrived. It rebuilds a canonical archive: files sorted, timestamps fixed. The same files always give the same bytes, and so the same hash. That hash is computed once, at publishing, and written into the marketplace entry.
When you install or update, Claude Code downloads the archive from url and checks its sha256 against the one in the marketplace before it installs anything. If a single byte differs, the install fails. Together with immutable versions, that gives you a simple guarantee:
The files you read on the mod page for version 0.1.0 are the files Claude Code installs for version 0.1.0.
It is a guarantee about integrity, not about intent. The hash proves you got what the publisher published. It says nothing about whether what they published is safe. That part is on you, with the help of what a mod can touch.
Updating
Claude Code reads a marketplace when you add it and when you refresh it. To pick up new versions from a publisher, run this inside Claude Code:
/plugin marketplace update anaEach version on Modyard is immutable and each new one must be higher than the last, so an update only ever moves forward. A publisher who wants to fix 0.1.0 ships 0.1.1; they cannot change 0.1.0 under your feet. When an update arrives, the mod page shows each version's files, so you can compare what changed before you accept it.
Unlisted and deleted mods
A publisher can unlist a mod: it leaves search and their marketplace listing, but its direct link still works and it can still be installed by name. They can also delete it: its versions disappear and its name is freed for someone else. If you installed a mod that is later deleted, you keep the copy you have but get no more updates, and a new mod with the same name would come from whatever publisher you add for it. That is one more reason to install by name@publisher and to pay attention to the publisher part.
Trust, in practice
A few habits go a long way:
- Add a publisher's marketplace only when you mean to. Read their mod first, then add them.
- Install at the narrowest scope that works.
--scope projectkeeps a mod to one repository. - Read before updating a mod that touches
processes,networkorfiles. - Remove marketplaces you no longer use, from the
/pluginmenu in Claude Code.
Mods run with your permissions. Modyard tells you who published a mod and guarantees you get exactly what they published; deciding whether to run it is still your call.