GitHub repositories are the registry. There is no package server.
A registry is a JSON index committed to a repo. A hosted API would have needed its own accounts and something to keep running. Using repos means private distribution comes free from GitHub access controls. What I gave up: no download counts, no central moderation, no way to yank a bad package.
A package is a folder you can read in a pull request
Each package is registry/<name>/ holding meta.json and a Markdown entry file. Inlining into one large manifest would have been simpler to fetch and horrible to review. The file that lands in .claude/ is byte-identical to the one on GitHub.
Two clients, one contract
The terminal UI is Node and Ink. The Claude Code skill runs inside the conversation with no Node runtime at all. Both perform resolve, fetch, write, record in the same order, which is the only reason it is safe to have two of them.
Vaults resolve in a user-defined order, first match wins
An organisation registers its internal vault ahead of the public one, and its version of a package shadows the community version by the same name. Unqualified installs can silently resolve somewhere you did not expect.
The manifest is the source of truth, not the file tree
Scanning .claude/ and inferring what is installed falls apart the moment a package spans more than one file, and it cannot tell a Plug-managed file from one you wrote yourself. The trade-off is drift: hand-edit the folder and the manifest is quietly wrong.