# Claude Code Mods: What They Can Do and What They Can Reach

> Anthropic opened Claude Code to mods on Oct 1, 2026: TypeScript plugins that change its behavior and UI. What they can do, and the security fine print.

- Author: Nitish Garg, Founder & CEO, CellCog
- Published: 2026-10-02
- Canonical (HTML): https://cellcog.ai/blog/claude-code-mods/
- Section: Guides / Trust, permissions & security
- Publisher: CellCog (https://cellcog.ai), the AI employee platform. Blog index for agents: https://cellcog.ai/blog/llms.txt

## Key points

- On October 1, 2026, Anthropic opened Claude Code to mods: JavaScript or TypeScript handlers that run inside Claude Code and change how it behaves and what it draws.
- A mod can draw panes and bands, restyle parts of Claude Code's own interface, step into tool calls, answer them without running the tool, or send a request to a different model.
- Mods ship inside plugins, need Claude Code v2.1.287 or later, are on by default, and draw interface only in the terminal and the Desktop app's Code tab.
- A mod runs with your permissions and is not sandboxed: it can read your files and API keys, see every prompt, approve tool calls and spend your usage.
- Mods cannot change the permission prompt. Controls include claude plugin validate, --safe-mode, disableAllHooks and an administrator setting that limits which mods load.

## At a glance

- **What are Claude Code mods?** Plugins whose behavior lives in JavaScript or TypeScript handlers that Claude Code calls on events such as a tool call, a prompt or a redraw. They can change behavior, the interface and features.
- **Are mods safe to install?** Only from authors you trust. Anthropic's docs say a mod runs with your permissions, is not sandboxed and can approve tool calls; inspect it first with claude plugin validate.
- **What version do I need?** Claude Code v2.1.287 or later. Mods are on by default; --safe-mode or disableAllHooks turns them off.

**Anthropic has opened Claude Code to mods: plugins that change how the coding agent behaves and what it draws on screen.** On October 1, 2026, the company's developer account announced them in one line, "You can now mod Claude Code", and the docs went live the same day. A mod is a set of JavaScript or TypeScript handlers that run inside Claude Code itself, not beside it.

This page is read from [Anthropic's mods documentation](https://code.claude.com/docs/en/plugins/mods/overview), the [mods source folder on GitHub](https://github.com/anthropics/claude-code/blob/main/mods/README.md) and [the launch post on X](https://x.com/ClaudeDevs/status/2105721434807083061).

## What a mod can do

Claude Code already had settings hooks, skills, status lines and MCP servers. Those work from outside, by running a script or handing Claude text and tools. A mod is a function Claude Code calls when an event happens, such as a tool call, a submitted prompt or part of the interface being drawn, and the handler can watch, change or replace what happens next.

*Table: What mods add, per Anthropic's docs*

| Capability | Example from the docs |
|---|---|
| Draw your own interface | A pane beside the transcript, or a band above the prompt with tabs, buttons and text fields |
| Redraw Claude Code's interface | Restyle a tool call's row, the spinner, or the dialog Claude asks questions in |
| Step into a tool call or request | Hold a call while you ask the user, answer it without running the tool, or send one request to a different model |
| Run code on a command | A slash command that runs your function at once, with no Claude turn |
| Share data between hooks | Count tool calls in one hook and show the count beside the spinner in another |

The launch post sums up the authoring story: "Write one with a few lines of TypeScript, or have Claude build it for you." Mods ship inside plugins and install from a marketplace with the usual plugin command. Four already ship inside Claude Code, including `/diff` and a mod that loads `AGENTS.md` as project instructions.

## Where they run

Mods require Claude Code v2.1.287 or later and are on by default. Per the docs, "Mods work in the Claude Code CLI and in the Code tab of the Claude Desktop app." Mod handlers can also run in other surfaces such as the VS Code extension and headless runs, but the interface a mod draws appears only in the terminal and the Desktop Code tab.

## The security fine print

The docs are blunt about the risk, and this is the part teams should read before installing anything: "A mod is code that runs with your permissions." It can read and write files anywhere your account can, read environment variables and settings files including API keys, see every prompt and tool call, and spend your usage. Mods are not sandboxed; turning on sandboxing isolates the Bash commands Claude runs, not processes a mod starts.

*Table: What a loaded mod can reach, per Anthropic's docs*

| Access | What it means |
|---|---|
| Your machine | Read and write files, start programs, make network requests, as you |
| Your secrets | Environment variables and settings files, including API keys |
| Your session | Every prompt and tool call; it can rewrite them or submit prompts |
| Your approvals | It can approve a tool call before you are asked |
| Your usage | It can call a model on your plan or API key |

One line holds firm: "A mod can restyle much of Claude Code's interface, but not the permission prompt." But a mod that approves tool calls can approve one an `ask` rule would have prompted for. Anthropic's controls: inspect a mod first with `claude plugin validate`, start a session with `--safe-mode`, turn every mod off with `disableAllHooks`, and, for organizations, an administrator setting that limits which mods load.

## What is verified and what is not

- **The feature and its limits** are read from Anthropic's docs on October 1, 2026.
- **No changelog entry yet.** The public Claude Code changelog we checked did not list mods or v2.1.287 at the time of writing.
- **No marketplace of community mods** has been announced; installs come from marketplaces you add.

## Why it matters

Coding agents are becoming platforms. Mods turn Claude Code from a tool you configure into one you program, in the same way browsers became platforms through extensions. The trade is the same too: power arrives with a new supply chain. A mod from an untrusted marketplace can see everything the agent sees and approve what it does. For teams, the first job is the admin setting that decides which mods may load. For how agent harnesses compare, see our [harness ranking](https://cellcog.ai/blog/best-ai-agent-harnesses/) and our post on [Claude Code auto mode](https://cellcog.ai/blog/claude-code-auto-mode/).

## What we are watching for

- A changelog entry and the first public mod marketplaces.
- Security research on malicious mods, and any default change to how approving mods are flagged.
- Whether Codex or Cursor answer with a comparable in-process extension model.

## Update log

- October 1, 2026: page opened, from Anthropic's docs, the mods source folder and the launch post.

## Sources

- Anthropic, [Mods overview](https://code.claude.com/docs/en/plugins/mods/overview), [Create a mod](https://code.claude.com/docs/en/plugins/mods/create) and [Mods API](https://code.claude.com/docs/en/plugins/mods/api).
- Anthropic, [mods source folder](https://github.com/anthropics/claude-code/blob/main/mods/README.md) in the Claude Code repository.
- Claude on X, [October 1, 2026](https://x.com/ClaudeDevs/status/2105721434807083061).

## FAQ

**How do I install a Claude Code mod?**

A mod installs as a plugin from a marketplace, with /plugin install name@marketplace in a session or claude plugin install in your shell. Run /reload-plugins to load it into an open session.

**Can a mod change the permission prompt?**

No. Anthropic's docs say mods can restyle much of the interface but not the permission prompt. A mod that approves tool calls can still approve a call before you are asked.

**How is a mod different from a Claude Code hook?**

Settings hooks run a shell command, HTTP request or prompt from outside Claude Code. A mod's handlers are functions that run inside Claude Code, so they can draw interface and share state.

**Can an organization block mods?**

Yes. Anthropic documents an administrator setting that stops user-installed mods from loading while leaving managed ones running, plus disableAllHooks for individuals.

**Where does CellCog fit?**

We build AI employees for any role, engineering included. Each works in its own secure workspace, and commands that reach your world pass an approval step you control.

## Related

- [Claude Code Auto Mode: What It Does, How to Turn It Off](https://cellcog.ai/blog/claude-code-auto-mode/index.md)
- [Best AI Agent Harnesses: October 2026 Rankings](https://cellcog.ai/blog/best-ai-agent-harnesses/index.md)
- [Jev Alternatives: Clef, Perplexity and Strands Decider](https://cellcog.ai/blog/jev-alternatives/index.md)
- [What Is an AI Employee? The 5-Part Test for a Standing AI Worker](https://cellcog.ai/blog/what-is-an-ai-employee/index.md)

## The AI employee for this read

[AI Software Engineer](https://cellcog.ai/ai-employees/ai-software-engineer): I built this page. For what it covers, hire an engineer: it works in your repo behind an approval gate, so nothing reaches your world unclassified.

---

Markdown alternate of https://cellcog.ai/blog/claude-code-mods/. Try CellCog free, no credit card needed: https://cellcog.ai/signup
