Anthropic introduced mods on October 1: small TypeScript functions that change how Claude Code works. They ship inside plugins, so you install and share them like anything else from the Claude directory. The code arrived in version 2.1.287, the same day, at 16:59 UTC.
Everything Claude Code does is an event
That’s the whole model. Claude Code emits an event for each thing it does — calling a tool, asking for permission, drawing part of the screen. A mod is a function that hooks into one of those: before it, after it, instead of it, or wrapped around it. With a single function, a mod can
- rewrite a prompt before it reaches the model,
- block, rewrite or retry a tool call,
- approve or deny a permission request itself,
- strip secrets out of tool output before Claude reads it.
Hooks couldn’t do that. They got a say, but they couldn’t rewrite an event, draw UI or replace a feature. That’s exactly what developers had been asking for, Anthropic writes: more control, without waiting on a shipped feature.
The interface is now in scope
A mod may edit or replace parts of what Claude Code draws — a tool result, a question from Claude. It can add buttons and inputs, and other mods can respond when you press them. A mod targets the terminal, the desktop app, or both.
When several mods hook the same event, they run in load order: the first one sees the event first and the result last. That lets you stack mods from different authors. And you can use Claude Code to mod Claude Code — ask, and Claude writes the TypeScript, installs it, and hot reloads it in your session.
Version 2.1.288 extended the mod surface a day later: $.ui.selection() returns the text you last selected in fullscreen mode, plus the transcript row if the selection sits inside one.
/diff stops being a special case
Some built-in Claude Code features now ship as mods themselves. The first is /diff: turn it off in /plugin, or swap in your own version. More are meant to follow over time, until you can pare Claude Code down to a small core and add back only what you actually need.
Mods run without a sandbox
The warning sits near the top of the announcement, and it belongs there: mods get the same access to your machine as Claude Code itself. No sandbox. Install mods only from sources you trust — the same care you’d apply to any other code you put on your computer.
Teams get a brake for that. On Team and Enterprise plans, and on any machine with managed settings, a built-in mod called sec-default loads first. It stops user-installed mods from doing risky things, such as overriding your permission deny rules, and its source code is readable. Admins may load their own mods first instead, in which case they have to put sec-default back in the list themselves or the restrictions are gone.
Anthropic names three team uses: your CI pipeline’s status in a pane beside the conversation, a confirmation before any command touches production config, and a first-loading mod that logs every call every other mod makes.
Anthropic is handing over the interface
Hooks were a concession: you may speak up, the decision happens elsewhere. Mods invert that. Render a tool result differently, grant a permission automatically, swap out /diff — none of it needs Anthropic’s agreement any more, only TypeScript.
The price is stated in the post itself: no sandbox, full machine access, and sec-default only where managed settings reach. On a personal machine without a team plan, a mod from the directory is worth exactly as much as your trust in its author. That Anthropic put the design on GitHub for feedback before shipping suggests they know it.
Sources: