Anthropic Adds Mods to Claude Code, TypeScript Functions That Rewrite Prompts, Gate Tool Calls and Run Unsandboxed
Claude Code mods, announced October 1, are plugin-delivered TypeScript functions that can rewrite prompts and block tool calls, and Anthropic says they are not sandboxed.
Editor's Note ·
- Clarification:
- The article says the sec-default mod loads "on Team and Enterprise plans with managed settings". Anthropic's announcement says it loads "On Team and Enterprise plans, and on any machine with managed settings", so either condition applies. Preventing overrides of permission deny rules is given by Anthropic as one example of the risky actions it stops, not as its sole purpose.
- Clarification:
- The article says plugin-based mods can be installed "from the Claude directory with the /plugin command". Anthropic's announcement describes two routes: from the Claude directory, or by running /plugin in the CLI.
Overview
Anthropic has introduced “mods” for Claude Code, small TypeScript functions that change how the coding agent behaves and looks, according to Anthropic’s announcement dated October 1, 2026. Mods can rewrite prompts, add UI, replace built-in features or add new functionality, and users can write them by hand or ask Claude Code to write them. The Claude Code changelog lists “Added Claude Mods: plugins may now modify deeper behavior” under version 2.1.287, released October 1, 2026.
What We Know
- Delivery. Mods are distributed through plugins and work in both the Claude Code CLI and the desktop app, and plugin-based mods can be installed from the Claude directory with the
/plugincommand, per Anthropic. - How they work. A mod hooks events that Claude Code emits while it runs. According to Anthropic, a single mod function can rewrite prompts before the model processes them, block, rewrite or retry tool calls, approve or deny permission requests, and redact secrets from tool output. When several mods hook the same event, they run sequentially, with the earliest-loaded mod seeing the event first and the result last.
- Anthropic’s own mods. The claude-code repository’s mods README says four mods ship inside Claude Code:
sec-default,diff,telemetryandagents-md. Thediffmod provides/diff, which shows the session’s uncommitted changes in a pane beside the transcript, andagents-mdloadsAGENTS.mdas project instructions. The same README says a mod’s tests run withclaude plugin test mods/diff. - Further additions. The changelog says version 2.1.287 also added “You should know,” a built-in mod where a side agent flags things the user or Claude might miss, enabled with
/plugin enable cc-plugin-you-should-know@builtinfor first-party sessions with telemetry on. Version 2.1.288, dated October 2, 2026, added$.ui.selection()for mods, which returns the text last selected in fullscreen mode, per the changelog.
Security Model
Anthropic is explicit that mods are not isolated from the machine. Its announcement states: “Mods run with the same access to your machine as Claude Code itself. They aren’t sandboxed, and you should only install mods from sources you trust, the same way you’d install any code on your computer.” Anthropic says that on Team and Enterprise plans with managed settings, a built-in mod called sec-default loads first to prevent user-installed mods from overriding permission denial rules. The mods README describes sec-default as adding “no policy of its own” in the sense that it keeps an organization’s hooks, managed settings, tool policy and deny rules out of reach of installed plugins, per the README.
The announcement also lists uses teams could build for themselves: CI/CD pipeline status displays, production safeguards that require confirmation, and audit logging of mod function calls, according to Anthropic.
What We Don’t Know
- Stability of the API. The README states: “Early access: hooks modules load only where function hooks are enabled, and the API these mods are written against may change between releases without notice.” Authors of mods should expect interface changes, per the README.
- Third-party vetting. The sources reviewed do not describe how mods submitted to the Claude directory are reviewed for safety, so the extent of that vetting is unclear.
Analysis
Mods move parts of Claude Code that were fixed product features into the same extension layer available to outside developers: the README says the diff, telemetry and agents-md features are mods whose source is published as it is built into the binary. The combination of permission-request handling, tool-call gating and unsandboxed execution means a mod is both a possible policy-enforcement point and a possible risk. For managed organizations, Anthropic’s announcement describes sec-default as the layer that keeps installed mods from overriding permission denial rules.