Cover: AI-generated editorial composition by TMRW, based on Anthropic’s Claude Code mods announcement.
On October 1, Anthropic gave developers a way to change Claude Code without waiting for Anthropic to ship the change. Mods are small TypeScript functions that hook events the coding agent already emits. A mod can rewrite a prompt before the model sees it, block or retry a tool call, approve or deny a permission, strip a secret out of a tool’s output, or replace part of the screen. They install as plugins, in the terminal and in the desktop app.
The sentence to read twice is in the launch post. Mods “run with the same access to your machine as Claude Code itself. They aren’t sandboxed.” Anthropic’s instruction is the ordinary one for software: install only what you trust. It is harder to follow here, because the mod sits inside a program that is already allowed to run commands on that machine.
A hook that can stand in for the event
Claude Code already had hooks that could watch and react. Mods can rewrite the event or take its place. They can run before it, after it, or around it. When several mods catch the same event, they run in the order they load. The first sees the event first and the result last, so an early mod can wrap whatever a later one tried to do. Anthropic also says you can ask Claude Code to write a mod, install it, and reload it inside the session you are in.
That last path is convenient, and it is circular. The agent a mod is supposed to constrain can be the thing that installs the constraint. A function that can approve a permission, written by the session it governs, is not a control. It is a shorter path around one.
The feature Anthropic expects you to replace
Some of Claude Code’s own pieces now ship as mods. The built-in diff view is one. You can turn it off, or put yours in its place. Anthropic says more of the product will move onto that base, so a team could keep a small core and put its own policy around it. That is the version of this launch worth having. The other version is a folder of clever plugins that are also able to approve their own tool calls.
On Team and Enterprise plans, and on any machine with managed settings, a built-in mod called sec-default loads first. Anthropic says it stops user-installed mods from risky moves, including overriding a permission denial. Administrators can load their own mods ahead of it. If they do, Anthropic tells them to keep sec-default on the list. Admins can allow or block plugin marketplaces. On API plans, managed settings are pushed to the machine.
What a serious mod looks like
The useful ones are dull, and they are code a security team can read. Require a confirmation before any command touches production configuration. Redact tokens before the model reads tool output. Put a build status beside the conversation. Log every call every other mod makes, from a mod that loads first.
The rule is short. Read the mod, or have someone who can, before it lands on a machine that holds production credentials. Prefer the mods an admin loads to the ones a session installs for itself. If sec-default is what stands between a plugin and a permission denial, do not remove it to make a demo work. Claude Code is already an agent with your files and your shell. A mod is that agent, plus someone else’s function, in the same process.



