N&S Logo

Claude Code 2.1.281 の plugin validate: command も url も無いとエラー

更新: 9/28
読了: 約47分
字数: 18,796文字
Claude Code 2.1.281 の plugin validate: command も url も無いとエラー

Claude Code 2.1.281が 2026年9月24日 (日本時間) に公開され、claude plugin validateに MCP サーバーのチェックが加わりました。2026年9月26日に実行したところ、commandもurlも無い.mcp.jsonのエントリはエラーで終了コード 1 でした。"type": "http"を指定した非ループバックのhttp://の url は警告だけで、オプションなしでは終了コード 0、--strictでは 1 でした。urlはあるが"type"を書いていないエントリはエラーで、オプションなしでも--strictでも終了コード 1 でした。

検証結果の要約

Claude Code 2.1.281 のclaude plugin validateに 7 個の入力を渡して 14 回実行した結果です。終了コードの括弧はその実行に付けたオプションで、書いていない組み合わせは試していません。

入力結果終了コード (付けたオプション)
command と args を持つ有効なエントリ (対照)指摘なし0 (オプションなし・--json)
description だけで command も url も無いエントリエラー 1 件 (mcpServers.broken-server.command)1 (オプションなし・--json)
env で未宣言の${user_config.undeclared_token}を参照エラー 1 件 (mcpServers.uc-server.env.API_TOKEN)1 (オプションなし・--json)
url はあるが "type" を指定していないエントリエラー 1 件 (mcpServers.insecure-server.type)1 (オプションなし・--json・--strict)
"type": "http"と非ループバックのhttp://の url警告 1 件 (mcpServers.insecure-server.url)0 (オプションなし)、1 (--strict)
"type": "http"と localhost 向けのhttp://の url指摘なし0 (オプションなし・--json)
3 種類の問題を 1 つの.mcp.jsonに混在エラー 2 件 (mcpServers.broken-server.command、mcpServers.uc-server.env.API_TOKEN)、警告 1 件 (mcpServers.insecure-server.url)1 (オプションなし)

試した環境と準備

  • 検証日: 2026-09-26 (日本時間)
  • 検証対象: Claude Code 2.1.281
  • 検証環境: macOS 15.1 (Darwin 24.1.0 arm64) / Node.js v23.9.0
  • 作業ディレクトリ: コマンドは/path/to/lab/workで実行しました (../fixturesはその隣の/path/to/lab/fixturesです)。出力に含まれる絶対パスは、検証に使ったディレクトリを/path/to/labに置き換えて載せています。

検証した Claude Code 2.1.281 は、次のコマンドでインストールしました。

npm install --cache ./.npm-cache --prefix ./pkg --no-audit --no-fund @anthropic-ai/[email protected] 2>&1 | tail -30

plugin validate にはどんなオプションがありますか

Claude Code 2.1.281 のclaude plugin validate --helpに載っているオプションは-h, --help・--json・--strictで、--jsonは検証レポートを JSON で出力して終了コードは同じ、--strictは警告をエラーとして扱って CI を失敗させるためのものです。

次のコマンドは--versionとplugin validate --helpを続けて実行するもので、出力の 1 行目2.1.281 (Claude Code)がインストールしたバージョンです。

./pkg/node_modules/.bin/claude --version; ./pkg/node_modules/.bin/claude plugin validate --help 2>&1
2.1.281 (Claude Code)
Usage: claude plugin validate [options] <path>

Validate a plugin or marketplace manifest, or the skills, agents, and commands
in a directory

Options:
  -h, --help  Display help for command
  --json      Output the validation report as JSON (same exit codes)
  --strict    Treat warnings as errors (exit 1). Use in CI to fail on
              unrecognized fields, missing metadata, and other issues that the
              runtime tolerates.

ヘルプの読み方

  • Usageの行はclaude plugin validate [options] <path>で、検査する対象のパスを引数に取ります。説明には、プラグインまたはマーケットプレイスのマニフェストと、ディレクトリの中のスキル・エージェント・コマンドを検証すると書かれています。
  • MCP のチェックだけを選ぶオプションはヘルプに載っていません。
  • --strictの説明が対象として挙げているのは、未知のフィールドとメタデータの欠落、およびランタイムが許容するほかの問題です。

読み込み時に捨てられるエントリはどう報告されますか

Claude Code 2.1.281 のclaude plugin validateは、descriptionだけでcommandもurlも無い.mcp.jsonのエントリをmcpServers.broken-server.commandを名指しするエラー 1 件として報告し、オプションを付けない実行でも終了コード 1、最後の行は✘ Validation failedでした。

公式のトラブルシューティングのページには、.mcp.jsonのサーバーのエントリがスキーマに合わないとき、そのエントリは/pluginの Errors タブに出ず、claude --debugのログにInvalid MCP server config for <server> in <path>として記録されるだけだと書かれています。同じページには、2.1.281 より前のclaude plugin validateは.mcp.jsonを検査しなかったとも書かれています (Troubleshoot plugins)。

検査に使った.mcp.jsonでは、サーバーのエントリにdescriptionだけを置いています。

../fixtures/plugin-dropped/.mcp.json

{
  "mcpServers": {
    "broken-server": {
      "description": "no command and no url, does not match any known transport"
    }
  }
}
./pkg/node_modules/.bin/claude plugin validate ../fixtures/plugin-dropped/ 2>&1
Validating plugin manifest: /path/to/lab/fixtures/plugin-dropped/.claude-plugin/plugin.json

Validating mcp: /path/to/lab/fixtures/plugin-dropped/.mcp.json

✘ Found 1 error:

  ❯ mcpServers.broken-server.command: Invalid input. The plugin loader silently drops this server at load.

✘ Validation failed

出力の読み方

  • 出力の先頭には検査したファイルが並びます。Validating plugin manifest:の行が.claude-plugin/plugin.json、Validating mcp:の行が.mcp.jsonのパスです。
  • メッセージはInvalid input.に続けて、プラグインのローダーが読み込み時にこのサーバーを黙って捨てると述べています。
  • 名指しされたのはcommandですが、この入力のエントリにはcommandもurlもありません。手元のプロセスとして起動するサーバーならcommandを、リモートのサーバーならurlと"type"を与えることになります。urlだけを与えた場合は別のキーを名指しするメッセージになり、その形は後の節で扱います。
  • .claude-plugin/plugin.json側の指摘は出ていません。マニフェスト本体と.mcp.jsonは別のファイルとして報告されます。

未宣言の user_config 参照はどのように分かりますか

Claude Code 2.1.281 のclaude plugin validateは、plugin.jsonのuserConfigに宣言の無い${user_config.undeclared_token}を.mcp.jsonのenv.API_TOKENで参照した入力をmcpServers.uc-server.env.API_TOKENを名指しするエラー 1 件として報告し、オプションを付けない実行でも終了コード 1 でした。

Plugin manifest referenceには、claude plugin validateがプラグインが宣言する MCP サーバーのエントリを、.mcp.json、mcpServersが名前で指す.jsonファイル、plugin.jsonにインラインで書いた形のそれぞれについて検査すると書かれています。これらの MCP チェックには Claude Code v2.1.281 以降が必要で、エラーとして扱われるものにはマニフェストが宣言していない${user_config.KEY}参照が挙げられています。

検査に使った.mcp.jsonは、環境変数の値に${user_config.undeclared_token}を置いたものです。

../fixtures/plugin-userconfig/.mcp.json

{
  "mcpServers": {
    "uc-server": {
      "command": "node",
      "args": ["${CLAUDE_PLUGIN_ROOT}/server.js"],
      "env": { "API_TOKEN": "${user_config.undeclared_token}" }
    }
  }
}
./pkg/node_modules/.bin/claude plugin validate ../fixtures/plugin-userconfig/ 2>&1
Validating plugin manifest: /path/to/lab/fixtures/plugin-userconfig/.claude-plugin/plugin.json

Validating mcp: /path/to/lab/fixtures/plugin-userconfig/.mcp.json

✘ Found 1 error:

  ❯ mcpServers.uc-server.env.API_TOKEN: references ${user_config.undeclared_token}, which plugin.json does not declare under "userConfig" (or in this server's "channels" entry), so on a fresh install it cannot resolve: the loader drops the server or passes the literal text through. Declare the option or fix the key.

✘ Validation failed

エラーが名指しするキーと宣言の直し方

  • メッセージには参照先の${user_config.undeclared_token}がそのまま出るので、どのキーを宣言し忘れたかが 1 行で分かります。
  • メッセージは、新しくインストールした状態では参照が解決できず、ローダーがそのサーバーを捨てるか、文字どおりのテキストをそのまま渡すと述べ、オプションを宣言するかキーを直すよう促しています。
  • この入力の.claude-plugin/plugin.jsonにはuserConfigがありません。指摘が出なかった対照の入力 (../fixtures/plugin-good、全文は「検証に使ったファイル」にあります) では、plugin.jsonがuserConfigにapi_tokenを宣言し、.mcp.jsonのenv.API_TOKENが${user_config.api_token}を参照しています。ただしこの対照はmcpServersのキー名 (good-server) やplugin.jsonのname・descriptionも違うため、差は 1 つではありません。
  • メッセージは"userConfig"に加えて、そのサーバーの"channels"エントリでの宣言にも触れています。channelsで宣言する形はこの検証では試していません。
  • ${CLAUDE_PLUGIN_ROOT}はargsの中で使っていますが、この入力では指摘の対象になっていません。

url と type の書き方で結果はどう変わりますか

urlだけで"type"の無いエントリはmcpServers.insecure-server.typeのエラー 1 件で、オプションなしでも--strictでも終了コード 1 でした。"type": "http"と非ループバックのhttp://の url は警告 1 件で終了コード 0 (--strictでは 1)、同じ"type": "http"でループバックのhttp://localhost:8931/mcp/sseは指摘なしで終了コード 0 でした。

http://の url への指摘を見るつもりで用意した.mcp.jsonです。urlだけを置き、"type"は書いていません。

../fixtures/plugin-insecure/.mcp.json

{
  "mcpServers": {
    "insecure-server": {
      "url": "http://example.com/mcp/sse"
    }
  }
}
./pkg/node_modules/.bin/claude plugin validate ../fixtures/plugin-insecure/ 2>&1
Validating plugin manifest: /path/to/lab/fixtures/plugin-insecure/.claude-plugin/plugin.json

Validating mcp: /path/to/lab/fixtures/plugin-insecure/.mcp.json

✘ Found 1 error:

  ❯ mcpServers.insecure-server.type: server has a "url" but no "type". Remote servers must set "type" to "http" (or "sse" / "ws"); without it the entry is parsed as a stdio server, fails for lacking "command", and is silently dropped at load.

✘ Validation failed

type が無いエントリへの指摘

  • 名指しされたキーはurlではなくmcpServers.insecure-server.typeです。メッセージは、"url"があるのに"type"が無い状態では標準入出力のサーバーとして解析され、"command"が無いため読み込み時に黙って捨てられると述べています。
  • メッセージが挙げる直し方は、リモートのサーバーで"type"に"http"(または"sse"/"ws") を設定することです。
  • 予想と違った点として、この入力ではhttp://のホストに対する指摘は出ませんでした。安全でない URL のチェックだけを見るには"type": "http"を明示した入力が必要です。

この入力はオプションなしでエラーとして報告されるため、警告をエラーに格上げする--strictを付けてもメッセージは変わりませんでした。

./pkg/node_modules/.bin/claude plugin validate --strict ../fixtures/plugin-insecure/ 2>&1

type を明示した http:// の url

上の入力に"type": "http"を足した.mcp.jsonです。.mcp.jsonの差はtypeの 1 行だけです。

../fixtures/plugin-insecure2/.mcp.json

{
  "mcpServers": {
    "insecure-server": {
      "type": "http",
      "url": "http://example.com/mcp/sse"
    }
  }
}
./pkg/node_modules/.bin/claude plugin validate ../fixtures/plugin-insecure2/ 2>&1
Validating plugin manifest: /path/to/lab/fixtures/plugin-insecure2/.claude-plugin/plugin.json

Validating mcp: /path/to/lab/fixtures/plugin-insecure2/.mcp.json

⚠ Found 1 warning:

  ❯ mcpServers.insecure-server.url: url uses http:// to a non-loopback host — requests, headers and any credentials travel in cleartext. Use https://; plugin directories may reject insecure remote server urls.

✔ Validation passed with warnings

メッセージが名指ししているのはmcpServers.insecure-server.urlで、http://で非ループバックのホストに接続すると要求・ヘッダー・資格情報が平文で流れる点、https://を使う点、プラグインの配布先 (原文のplugin directories) が安全でないリモートサーバーの url を拒む場合がある点に触れています。見出しの記号も✘ではなく⚠です。

同じ入力に--strictを付けた実行では、⚠ Found 1 warning:の見出しと指摘の行は変わらず、最後の行が(--strict treats warnings as errors)を伴う形に変わりました。

./pkg/node_modules/.bin/claude plugin validate --strict ../fixtures/plugin-insecure2/ 2>&1

ループバックのホストの場合

"type": "http"とhttp://は変えず、url の宛先をループバックのホストにした.mcp.jsonも検査しました。.mcp.jsonで変えたのは url のホストとポートとサーバーのキー名です。

../fixtures/plugin-loopback2/.mcp.json

{
  "mcpServers": {
    "loopback-server": {
      "type": "http",
      "url": "http://localhost:8931/mcp/sse"
    }
  }
}
./pkg/node_modules/.bin/claude plugin validate ../fixtures/plugin-loopback2/ 2>&1
Validating plugin manifest: /path/to/lab/fixtures/plugin-loopback2/.claude-plugin/plugin.json

✔ Validation passed

警告のメッセージがnon-loopback hostと書いているとおり、http://という書き方そのものではなくホストが条件になっています。この出力にはValidating mcp:の行が現れません。指摘が無かった 2 個の入力ではこの行が出ず、--jsonでもcontentsは空の配列だったため、出力だけでは.mcp.jsonが検査されたかどうかは判断できません。

複数の問題と機械可読の出力はどう並びますか

Claude Code 2.1.281 のclaude plugin validateで 3 種類の問題 (commandもurlも無いエントリ、未宣言の${user_config.*}参照、"type": "http"と非ループバックのhttp://の url) を 1 つの.mcp.jsonにまとめた入力では、オプションを付けない実行でエラー 2 件と警告 1 件が報告され終了コード 1 になりました。--jsonを付けた 5 個のうち指摘が出た 3 個では、その指摘がcontents配列に並びました。

ここまでの 3 つの形を 1 つの.mcp.jsonにまとめた入力です。

../fixtures/plugin-combined/.mcp.json

{
  "mcpServers": {
    "broken-server": {
      "description": "no command and no url, does not match any known transport"
    },
    "uc-server": {
      "command": "node",
      "args": ["${CLAUDE_PLUGIN_ROOT}/server.js"],
      "env": { "API_TOKEN": "${user_config.undeclared_token}" }
    },
    "insecure-server": {
      "type": "http",
      "url": "http://example.com/mcp/sse"
    }
  }
}
./pkg/node_modules/.bin/claude plugin validate ../fixtures/plugin-combined/ 2>&1
Validating plugin manifest: /path/to/lab/fixtures/plugin-combined/.claude-plugin/plugin.json

Validating mcp: /path/to/lab/fixtures/plugin-combined/.mcp.json

✘ Found 2 errors:

  ❯ mcpServers.broken-server.command: Invalid input. The plugin loader silently drops this server at load.
  ❯ mcpServers.uc-server.env.API_TOKEN: references ${user_config.undeclared_token}, which plugin.json does not declare under "userConfig" (or in this server's "channels" entry), so on a fresh install it cannot resolve: the loader drops the server or passes the literal text through. Declare the option or fix the key.

⚠ Found 1 warning:

  ❯ mcpServers.insecure-server.url: url uses http:// to a non-loopback host — requests, headers and any credentials travel in cleartext. Use https://; plugin directories may reject insecure remote server urls.

✘ Validation failed

エラーの見出しと警告の見出しが別に出て、指摘の行は単独で検査したときと同じ文です。

--json の形

指摘があるときの--jsonの出力は次のとおりです (commandもurlも無いエントリの入力)。

./pkg/node_modules/.bin/claude plugin validate --json ../fixtures/plugin-dropped/ 2>&1
{
  "success": false,
  "strict": false,
  "target": "/path/to/lab/fixtures/plugin-dropped/.claude-plugin/plugin.json",
  "manifest": {
    "file": "/path/to/lab/fixtures/plugin-dropped/.claude-plugin/plugin.json",
    "type": "plugin",
    "errors": [],
    "warnings": [],
    "notes": []
  },
  "contents": [
    {
      "file": "/path/to/lab/fixtures/plugin-dropped/.mcp.json",
      "type": "mcp",
      "errors": [
        {
          "path": "mcpServers.broken-server.command",
          "message": "Invalid input. The plugin loader silently drops this server at load.",
          "code": null
        }
      ],
      "warnings": [],
      "notes": []
    }
  ]
}

読み方は次のとおりです。

  • targetは渡したディレクトリから解決されたマニフェスト (.claude-plugin/plugin.json) のパス、manifestはそのマニフェスト自身の指摘です。この実行ではmanifestのerrors・warnings・notesはいずれも空でした。
  • .mcp.jsonの指摘はcontentsの要素に入り、要素にはfileと"type": "mcp"、errors・warnings・notesが付きます。指摘の要素はpath・message・codeを持ち、テキスト出力の❯の行の前半がpath、後半がmessageに対応します (codeはnull)。
  • strictはこの検証の--jsonの実行ではどれもfalseでした。
  • 未宣言の${user_config.*}参照の入力と、urlだけで"type"の無い入力に--jsonを付けた実行でも形は同じで、contentsの要素のpathとmessageがそれぞれの指摘の行と同じ内容になります。

確かめた範囲と試していないこと

Claude Code 2.1.281 のclaude plugin validateの MCP サーバーチェックについてのこの記事の結論は、7 個の入力に対する 14 回の実行 (オプションなし 7 回・--json5 回・--strict2 回) で確かめたもので、--jsonと--strictを同じ実行で一緒に付けた組み合わせや、メッセージが挙げる"sse"/"ws"は試していません。

実行した組み合わせ

  • 7 個すべての入力で実行したのはオプションなしで、--jsonを付けていないのは、"type": "http"と非ループバックのhttp://の url を持つ入力と、3 種類の問題を混在させた入力の 2 個です。

  • --strictを付けたのは、urlだけで"type"が無い入力と、"type": "http"と非ループバックのhttp://の url を持つ入力の 2 個で、対照・commandもurlも無い入力・未宣言の${user_config.*}参照の入力・ループバックの入力・混在させた入力には付けていません。

  • 結論ごとの根拠の数は次のとおりです。

    • commandもurlも無いエントリのエラー: 1 個の入力に対する 2 回の実行
    • 未宣言の${user_config.*}参照のエラー: 1 個の入力に対する 2 回の実行
    • urlがあって"type"が無いエントリのエラー: 1 個の入力に対する 3 回の実行 (オプションなし・--json・--strict)
    • "type": "http"と非ループバックのhttp://の url の警告と--strictでの扱い: 1 個の入力に対する 2 回の実行
    • ループバックのhttp://localhost:8931/mcp/sseで指摘が出ないこと: 1 個の入力に対する 2 回の実行
    • 3 種類を混在させた入力での同時報告: 1 個の入力に対する 1 回の実行

試していない値と設定

  • Plugin manifest referenceが MCP のチェックとして挙げているもののうち、絶対 URL として正しくないurlのエラー、ws://で非ループバックのホストに向かう url の警告、資格情報そのものに見えるヘッダー値の警告は、この検証では試していません。
  • Plugin manifest reference には、MCP のチェックがmcpServersが名前で指す.jsonファイルやplugin.jsonにインラインで書いたエントリにも働くと書かれていますが、この検証で渡したのは.mcp.jsonを置いたプラグインのディレクトリだけです。
  • ループバックのホストとして試したのはhttp://localhost:8931/mcp/sseの 1 個だけです。ほかのループバックの書き方は試していません。
  • 検査の対象として渡したのはプラグインのディレクトリだけで、マーケットプレイスのディレクトリ (.claude-plugin/marketplace.json) は渡していません。

同じリリースの関連する変更

  • Claude Code: v2.1.281ではclaude plugin validateについて、plugin.jsonのprivacyPolicyUrlやsupportUrlなどの一覧用のメタデータのキーを未知のフィールドとして報告していた問題の修正と、シェル形式のフックで${CLAUDE_PLUGIN_ROOT}が引用符の外に置かれているときの警告の追加も挙がっています。どちらもこの検証では試していません。
  • 検証日までにClaude Code 2.1.282(2026年9月25日 日本時間) とClaude Code 2.1.283(2026年9月26日 日本時間) が公開されています。この検証で動かしたのは 2.1.281 だけです。

CI に入れるならどのオプションを使いますか

Claude Code 2.1.281 のclaude plugin validateを CI に入れる場合、エラーだけで止めるならオプションを付けない実行にプラグインのディレクトリを渡し、警告でも止めるなら--strict、結果を機械で読むなら--jsonを使います。

Plugin manifest referenceには、claude plugin validateをシェルからプラグインのディレクトリに対して実行する形が示されています。渡すのは.claude-plugin/plugin.jsonを含むディレクトリです。

目的ごとの使い分け

  • エラーだけで止める: オプションを付けない実行。要約の表でエラーが出ている 4 行 (commandもurlも無いエントリ、未宣言の${user_config.*}参照、urlがあって"type"の無いエントリ、3 種類を混在させた入力) がこの使い方で止まる例です。プラグインを公開する前の最低限の関門として置けます。
  • 警告も止める:--strictを付けた実行。"type": "http"と非ループバックのhttp://の url を持つ入力の行が、オプションの有無で結果が分かれる行です (要約の表)。社内のプラグインで平文の通信を禁じたい場合は、こちらを使うことになります。
  • 結果を機械で読む:--jsonを付けた実行。要約の表の終了コードの括弧に--jsonと書かれている 5 行が対象です。contentsの各要素のfileと、そのerrors内の指摘が持つpath・messageを注釈やレビューのコメントに流せます。

組み立てるときの注意

  • --jsonと--strictの両方が必要なら、まず自分の環境でその組み合わせを確かめてから使ってください。
  • MCP の検査が働いていることは、わざと壊した.mcp.jsonを持つプラグインのディレクトリを 1 つ CI に置き、それが失敗することで確認してください。

CI に組み込むコマンド

導入のコマンドは検証で実行したものから--cache ./.npm-cache・2>&1・| tail -30を外したものです。検査のコマンドは検証で実行したものの入力のパスを<検査する対象のパス>に置き換え、一部の実行に付いていた2>&1を外したものです。導入する版は検証した 2.1.281 に固定しています (これより新しい版では試していません)。

npm install --prefix ./pkg --no-audit --no-fund @anthropic-ai/[email protected]
./pkg/node_modules/.bin/claude plugin validate <検査する対象のパス>
./pkg/node_modules/.bin/claude plugin validate --json <検査する対象のパス>
./pkg/node_modules/.bin/claude plugin validate --strict <検査する対象のパス>

検証環境は macOS 15.1 (Darwin 24.1.0 arm64) / Node.js v23.9.0 で、CI の実行環境では試していません。どのオプションで終了コードがいくつになったかは「検証結果の要約」の表のとおりです。

検証の手順と結果

Claude Code 2.1.281 をローカルに導入し、MCP サーバーの設定を変えたプラグインのディレクトリ (plugin.jsonのname・descriptionは入力ごとに違い、対照だけがuserConfigを宣言しています) を用意して、入力ごとにオプションの有無を変えてclaude plugin validateを実行しました。

検証に使ったファイル

本文のコマンドが読んだファイルの全文です (パスはコマンドを実行した作業ディレクトリからの相対パスです)。

ファイル:../fixtures/plugin-good/.claude-plugin/plugin.json

{
  "name": "plugin-good",
  "version": "1.0.0",
  "description": "control plugin with a valid mcp.json",
  "author": { "name": "Test Author" },
  "userConfig": {
    "api_token": {
      "type": "string",
      "title": "API token",
      "description": "token for the api"
    }
  }
}

ファイル:../fixtures/plugin-good/.mcp.json

{
  "mcpServers": {
    "good-server": {
      "command": "node",
      "args": ["${CLAUDE_PLUGIN_ROOT}/server.js"],
      "env": { "API_TOKEN": "${user_config.api_token}" }
    }
  }
}

ファイル:../fixtures/plugin-dropped/.claude-plugin/plugin.json

{
  "name": "plugin-dropped",
  "version": "1.0.0",
  "description": "plugin with an mcp.json entry that would be silently dropped",
  "author": { "name": "Test Author" }
}

ファイル:../fixtures/plugin-userconfig/.claude-plugin/plugin.json

{
  "name": "plugin-userconfig",
  "version": "1.0.0",
  "description": "plugin referencing an undeclared user_config key",
  "author": { "name": "Test Author" }
}

ファイル:../fixtures/plugin-insecure/.claude-plugin/plugin.json

{
  "name": "plugin-insecure",
  "version": "1.0.0",
  "description": "plugin with an insecure non-loopback http url",
  "author": { "name": "Test Author" }
}

ファイル:../fixtures/plugin-insecure2/.claude-plugin/plugin.json

{
  "name": "plugin-insecure2",
  "version": "1.0.0",
  "description": "plugin with a well-formed http url to a non-loopback host",
  "author": { "name": "Test Author" }
}

ファイル:../fixtures/plugin-loopback2/.claude-plugin/plugin.json

{
  "name": "plugin-loopback2",
  "version": "1.0.0",
  "description": "plugin with a well-formed http url to a loopback host",
  "author": { "name": "Test Author" }
}

ファイル:../fixtures/plugin-combined/.claude-plugin/plugin.json

{
  "name": "plugin-combined",
  "version": "1.0.0",
  "description": "plugin whose mcp.json has all three problem patterns at once",
  "author": { "name": "Test Author" }
}

検証の範囲と制約

  • 検証の範囲: 記事中のコマンドと出力は、当社の検証環境で実際に実行した記録です。確かめたのは実行した入力とオプションの組み合わせだけで、それ以外の入力や組み合わせは試していません。

出典

この記事の作り方

この記事は、株式会社エヌアンドエスの自動化システム (CORTEX) が公式の一次情報と当社の検証ログをもとに生成 AI (Claude) で下書きしました。記事中の数値・日付・バージョンは、機械の検査で公式の一次情報と当社の検証ログに書かれているものだけにしています。リリースの公開日は、出典に日付を添えたリリースページのものです。記事の主張 152 件を出典と当社の検証ログと 1 文ずつ照合する自動の検査を通しています。2026-09-28 に原田賢治が内容を確認し、公開を承認しました。

📱 関連ショート動画

この記事の内容をショート動画で解説

横にスクロールできます

著者について

原田賢治

原田賢治

代表取締役

Mike King理論に基づくレリバンスエンジニアリング専門家。生成AI検索最適化、ChatGPT・Perplexity対応のGEO実装、企業向けAI研修を手がける。 15年以上のAI・システム開発経験を持ち、全国で企業のDX・AI活用、退職代行サービスを支援。