Anthropic Launches Claude Code Mods, TypeScript Agent Hooks
TL;DR
- Mods run unsandboxed with full machine access, meaning a compromised extension can read, write, or exfiltrate without a permission boundary.
- Anthropic moved its own /diff feature into the mod system, making first-party built-ins replaceable by the same third-party mechanism.
- A native sec-default mod for business deployments ships at launch, but teams must still decide which mod sources are sanctioned before broad rollout.
Anthropic introduced "mods" on October 1, small TypeScript functions that hook into Claude Code's internal events and change what the agent does. In the launch post, the company writes that "a mod can rewrite a prompt, add new UI, replace a built-in feature, or add entirely new functionality."
The hook surface runs across the agent loop. Mods can rewrite a prompt before it reaches the model, block or retry a tool call, approve or deny a permission request, redact secrets from tool output, and edit or replace interface elements. "When several mods hook the same event, they run in the order they load," the post says; "the first mod to load sees the event first and the result last." Anthropic says the existing `/diff` feature now ships as a mod, which users can disable or replace the same way as any third-party extension.
Mods ride inside plugins and install via the `/plugin` command, with support in both the CLI and desktop app. They are not sandboxed. The post is blunt about what that means: "Mods run with the same access to your machine as Claude Code itself. They aren't sandboxed, and you should only install mods from sources you trust, the same way you'd install any code on your computer." Team and Enterprise plans load a built-in mod called `sec-default` first, intended to prevent risky actions like overriding permission denials.
It is the latest in a steady run of Claude Code and plugin releases moving through our coding-tools tracker, landing a day after a separate Anthropic enterprise pricing story. You can write a mod yourself, the company says, "or ask Claude Code to write one for you."
What others are reporting
-
Runtime Wire Read →
Reports Anthropic moved its own /diff feature into the mod system and details the sec-default mod for business deployments designed to block risky behavior.
Mods are not sandboxed and have the same access to a user's machine as Claude Code.
-
Crypto Briefing Read →
Leads with the trust model and machine-permission risk, positioning mod source vetting as the critical enterprise decision before any marketplace matures.
Mods are distributed inside plugins and installed using the /plugin command in the command-line interface or desktop application.
-
Aivy Read →
Connects mods to Australian Privacy Act 1988 and APRA CPS 234 compliance, framing marketplace governance as a strategic call for development teams, not just a technical one.
Mods run with the same access to your machine as Claude Code itself...should only be installed from sources you trust.
Originally reported by claude.com
Read the original article →Original headline: Anthropic Launches Claude Code Mods, TypeScript Functions That Rewrite Prompts, Tool Calls, and UI