Volume is not quality
Community directories now track thousands of skills and marketplaces. Skills remain the dominant component type; hooks and MCP are still the thinner integration edge. That volume is useful for discovery and terrible as a ranking signal.
A plugin with a loud star count can still ship unbounded tools, undocumented hooks, or standing context that burns tokens on every selection.
What high-adoption plugins tend to share
Multi-component bundles (skills plus commands, agents, hooks, or MCP) often move faster than single-file utilities — but only when each piece states when it applies and what it costs.
Maximalist “everything” plugins can win installs and still fail a team gate if permissions and context cost are opaque. Prefer clarity over component count.
A practical team allow-list
1. Named owner for each approved plugin. 2. Pre-install audit of published files (routing, context, tools, hosts, hooks). 3. Throwaway-repo hello-world. 4. Eval suite or fixed script before pinning. 5. Quarterly revisit after Claude Code releases.
Write the uninstall rule in one sentence. If nobody can say when the plugin leaves the list, it will never leave.
Measure peers, not folklore
When two SEO or workflow plugins claim the same job, compare them on the same scorecard and the same three tasks. AuditHQ Claude plugin projects plus peers make that comparison scheduled instead of anecdotal.