
Image: @ClaudeDevs (X) (video still)
Summary
- On October 1, Anthropic made mods generally available in Claude Code, letting developers hook functions into prompts, tool calls, permission requests and the interface Claude Code draws.
- Mods install as plugins, Claude can write one from a plain-language request, and built-in features such as /diff and AGENTS.md support now run as mods.
- Because mods run unsandboxed with the user's permissions, a built-in sec-default guard loads first on Team and Enterprise plans.
Anthropic on October 1 (US time) opened up mods for Claude Code. A mod is an extension written in a few lines of TypeScript or JavaScript that changes how Claude Code works and what it puts on screen. It can rewrite a prompt before it reaches the model, block, rewrite or retry a tool call, approve or deny a permission request, and redact secrets from tool output before Claude reads it. Mods ship inside plugins, so they are installed with the /plugin command in the CLI and the desktop app. They are on by default in Claude Code 2.1.287 and later.
According to Anthropic's official blog, Claude Code emits an event every time it calls a tool, asks for permission or draws part of the screen. A mod is a function that hooks into one of those events: it can run before the event, after it, or instead of it, and it can wrap the event to run code on both sides. The developer documentation sums up the options as observe, rewrite and answer. When several mods hook the same event, the one loaded first sees the event first and the result last. The existing hooks configured in settings files could only launch a shell command or HTTP request per event to allow or block it. METAL previously reported on how Claude Code hooks turn skipped rules into code that cannot be skipped; because mods run inside the Claude Code process, they also take on what those hooks could not do, such as drawing interface elements and adding new commands.
The 72-second demo video METAL reviewed walks through the three example mods from the official guide. Token Weather shows how full the context window is as a weather report above the prompt. After Claude reads one small file it reads Clear with 19,200 of 200,000 tokens (10%); after three days of logs and a month of readings it turns to Showers at 107,300 tokens (54%). Blast Radius catches Claude the moment it tries to run rm -rf build, lists the nine files (498KB) the command would delete, and offers Proceed and Cancel buttons. Replay Theater steps through the six edits Claude made across four files while renaming a single function. Token Weather was built in roughly 80 lines of code, according to reports.
Developers do not have to write the code themselves. Ask in a session for a mod that shows the current git branch above the prompt, and Claude writes it by following a built-in skill called plugin-authoring; once the user approves hot reloading, the mod loads as soon as the turn ends. Anthropic describes this as using Claude Code to mod Claude Code. A mod built this way runs only in that session, so using it elsewhere means moving its folder and loading it with --plugin-dir, or publishing it to a marketplace. The claude plugin validate command lists the events a mod hooks and the API calls it makes without running it, and claude plugin test runs automated tests with no session, sign-in or network.
Claude Code's own features have started moving into mods. The /diff view and AGENTS.md support are already mods, so users can switch them off in /plugin or swap in their own versions. The documentation lists six built-in mods, including telemetry and a security guard, and the source for four of them is public in the Claude Code repository. In its blog post, Anthropic said it plans to move more built-in features to mods so users can pare Claude Code down to a small core and add back only what they want.
The feature started as a public design. On September 3, Anthropic's Alice Poteat posted a function hooks proposal to the Claude Code GitHub repository to gather community feedback. Her design document, written in August, borrows the middleware structure of the Koa web framework: every hook takes the same three arguments, ($, e, next), and its behavior depends on whether and how it calls next. In a September 9 update Anthropic named the product Claude Mods and opened early access behind a single environment variable. "Claude Mods are landing now," Boris Cherny, head of Claude Code, wrote on X on September 14, adding, "Someone already built a Tetris-in-Claude mod." The post passed 600,000 views.
Mods are not sandboxed. Anthropic says they have the same access to the machine as Claude Code and advises installing mods only from trusted sources. According to the documentation, a mod can read and write any file the user's account can reach, start programs, read API keys held in environment variables and call models on the user's plan. It cannot change the permission prompt itself, but it can approve a tool call before that prompt ever appears. According to reports, a mod like Blast Radius that inspects command strings can be bypassed with aliases, wrapper scripts or $(...) substitution, so restrictions that must hold belong in permission rules or operating-system controls. "Our prerogative is not to restrict what plugins can do; that's your org admin's job," Poteat said in the GitHub discussion, explaining that the point of the design is to route everything through the $ object so administrators can audit, allow, deny and log it.
Controls for teams and companies sit on top of that $ object. On Team and Enterprise plans, and on any machine with managed settings, a built-in mod called sec-default loads first and stops user-installed mods from overriding an administrator's deny rules or touching managed hooks, the system prompt and managed MCP servers. According to the organization management documentation, administrators can block every user mod other than the organization's own with a single allowManagedModsOnly option, or put their own policy mod first to log or refuse other mods' file writes and process launches. Anthropic offered a CI/CD pane that shows build status, a confirmation step before any command touches production config, and an audit log of every mod's calls as examples for teams. METAL has previously reported on how Claude Code packages a team's setup into a single plugin; mods use that same plugin distribution path and the same management controls.

From an AI engineer's seat, the weight of this release is that the extension point has moved from outside to inside. Skills, MCP servers and settings hooks hand instructions or tools to Claude Code from the outside; mods put code in the middle of the agent's event stream. Claude Code now looks less like a finished app and more like an agent runtime assembled from plugins. That also means a team adopting a mod should read the calls line of the validate output the way it reads a code review. By pulling its own /diff out into a mod first, Anthropic is signaling that its features will pass through the same door, and the next test is which features stay in the core.
Sources
- Claude Devs (X) — You can now mod Claude Code →
- Claude Code Docs — Mods overview →
- Claude Code Docs — Create a mod →
- Claude Code Docs — Manage mods for your organization →
- AlphaSignal — Anthropic's Claude Code Mods Let Developers Rewrite the Agent From Inside →
- Anthropic — Customize Claude Code with mods in TypeScript →
- Boris Cherny (X) — Claude Mods are landing now →
- GitHub anthropics/claude-code — Mods - make Claude 10x more extensible · Issue #91870 →





Comments